SAML 2.0 identitetsudbyders metadata
Her er det metadata, som SimpleSAMLphp har genereret. Du kan sende det til dem du stoler i forbindelse med oprettelsen af en føderation.
Du kan få metadata-xml her:
https://fmu-staff.idp-proxy.finki.ukim.mk/saml2/idp/metadata.php
Metadata
I SAML 2.0 metadata xml-format:
<?xml version="1.0"?> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://fmu-staff.idp-proxy.finki.ukim.mk/saml2/idp/metadata.php"> <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIDvTCCAqWgAwIBAgIUd0Kx7BTmdhx+gRLJTw4cjVSPAZEwDQYJKoZIhvcNAQELBQAwbjELMAkGA1UEBhMCTUsxEzARBgNVBAgMClNvbWUtU3RhdGUxDzANBgNVBAcMBlNrb3BqZTENMAsGA1UECgwEVUtJTTEqMCgGA1UEAwwhZm11LXN0YWZmLmlkcC1wcm94eS5maW5raS51a2ltLm1rMB4XDTIwMDUzMDE4MDEwM1oXDTMwMDUyODE4MDEwM1owbjELMAkGA1UEBhMCTUsxEzARBgNVBAgMClNvbWUtU3RhdGUxDzANBgNVBAcMBlNrb3BqZTENMAsGA1UECgwEVUtJTTEqMCgGA1UEAwwhZm11LXN0YWZmLmlkcC1wcm94eS5maW5raS51a2ltLm1rMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqMguajYVKXCZEKPzqCvWeOk+zUzYGdxFgbc/t3JxiLH5CzeTCrm8qL2IK+oiAm6SWou4l1K+l40K2PEsX6ghw67B3smxaD9Ul/YuXQbeRcGHncH3+89GtmuxEJmZ5h2/IMmiDxrsq7wraOcUJ+1KjHToodBPQmLz6JmUJS8AeQnIfzjIvRwLCwMmdZqj1w3g4aR2JMsauxoVA/ZuME9wq49zEC7t9zSlFARHIxqpOGmAmOiyy7Ufbps8P3yVEFdhcrkaoRHUr7NKsBbxoixcXaZvGvDA4caIvDWl1TJ8uE7aXBDaJDShqSj4RupXjOV4wHUdxZHGH6bbfaVTOrhQtwIDAQABo1MwUTAdBgNVHQ4EFgQU0s69LrUcFPYk4tUWjJmximhvcOMwHwYDVR0jBBgwFoAU0s69LrUcFPYk4tUWjJmximhvcOMwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEADjad7KaBT4Wz6mDwiWVV/8gG+6LEm8kGZpsqh3f7vPNP5p+dZTnb7lL2jgZz/mPAxI2JoTU5rKIuTjtanY5tFinq5riBEAbafZ04OvHOp3R6BQ80rFnTwNsY24SG27Gki/YLAIgfjuSzWNmJLUuBXQymYxTTyAS+56VonMd2LNk6INhUgM1ztked/3Ck4KfpOKhl4Qt552WHlcdPCyKlnJvl7cwBnZx+ruNzFUXBfoc2fP8WfnKHJKMfF9ZMsc5Nj8s0eRXzgrWLOAsRKPaKmTfVzX+sczsx5+/yMdrRrpyk0YgDoADWJEFca/SO2GOYv6NkzQUUGQDlU/O/NGokLQ==</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIDvTCCAqWgAwIBAgIUd0Kx7BTmdhx+gRLJTw4cjVSPAZEwDQYJKoZIhvcNAQELBQAwbjELMAkGA1UEBhMCTUsxEzARBgNVBAgMClNvbWUtU3RhdGUxDzANBgNVBAcMBlNrb3BqZTENMAsGA1UECgwEVUtJTTEqMCgGA1UEAwwhZm11LXN0YWZmLmlkcC1wcm94eS5maW5raS51a2ltLm1rMB4XDTIwMDUzMDE4MDEwM1oXDTMwMDUyODE4MDEwM1owbjELMAkGA1UEBhMCTUsxEzARBgNVBAgMClNvbWUtU3RhdGUxDzANBgNVBAcMBlNrb3BqZTENMAsGA1UECgwEVUtJTTEqMCgGA1UEAwwhZm11LXN0YWZmLmlkcC1wcm94eS5maW5raS51a2ltLm1rMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqMguajYVKXCZEKPzqCvWeOk+zUzYGdxFgbc/t3JxiLH5CzeTCrm8qL2IK+oiAm6SWou4l1K+l40K2PEsX6ghw67B3smxaD9Ul/YuXQbeRcGHncH3+89GtmuxEJmZ5h2/IMmiDxrsq7wraOcUJ+1KjHToodBPQmLz6JmUJS8AeQnIfzjIvRwLCwMmdZqj1w3g4aR2JMsauxoVA/ZuME9wq49zEC7t9zSlFARHIxqpOGmAmOiyy7Ufbps8P3yVEFdhcrkaoRHUr7NKsBbxoixcXaZvGvDA4caIvDWl1TJ8uE7aXBDaJDShqSj4RupXjOV4wHUdxZHGH6bbfaVTOrhQtwIDAQABo1MwUTAdBgNVHQ4EFgQU0s69LrUcFPYk4tUWjJmximhvcOMwHwYDVR0jBBgwFoAU0s69LrUcFPYk4tUWjJmximhvcOMwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEADjad7KaBT4Wz6mDwiWVV/8gG+6LEm8kGZpsqh3f7vPNP5p+dZTnb7lL2jgZz/mPAxI2JoTU5rKIuTjtanY5tFinq5riBEAbafZ04OvHOp3R6BQ80rFnTwNsY24SG27Gki/YLAIgfjuSzWNmJLUuBXQymYxTTyAS+56VonMd2LNk6INhUgM1ztked/3Ck4KfpOKhl4Qt552WHlcdPCyKlnJvl7cwBnZx+ruNzFUXBfoc2fP8WfnKHJKMfF9ZMsc5Nj8s0eRXzgrWLOAsRKPaKmTfVzX+sczsx5+/yMdrRrpyk0YgDoADWJEFca/SO2GOYv6NkzQUUGQDlU/O/NGokLQ==</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://fmu-staff.idp-proxy.finki.ukim.mk/saml2/idp/SingleLogoutService.php"/> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://fmu-staff.idp-proxy.finki.ukim.mk/saml2/idp/SSOService.php"/> </md:IDPSSODescriptor> <md:ContactPerson contactType="technical"> <md:GivenName>FINKI</md:GivenName> <md:SurName>FCC</md:SurName> <md:EmailAddress>fcc@finki.ukim.mk</md:EmailAddress> </md:ContactPerson> </md:EntityDescriptor>
I SimpleSAMLphp flat-file format - brug dette hvis du også bruger SimpleSAMLphp i den anden ende;
$metadata['https://fmu-staff.idp-proxy.finki.ukim.mk/saml2/idp/metadata.php'] = array ( 'metadata-set' => 'saml20-idp-remote', 'entityid' => 'https://fmu-staff.idp-proxy.finki.ukim.mk/saml2/idp/metadata.php', 'SingleSignOnService' => array ( 0 => array ( 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://fmu-staff.idp-proxy.finki.ukim.mk/saml2/idp/SSOService.php', ), ), 'SingleLogoutService' => array ( 0 => array ( 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://fmu-staff.idp-proxy.finki.ukim.mk/saml2/idp/SingleLogoutService.php', ), ), 'certData' => 'MIIDvTCCAqWgAwIBAgIUd0Kx7BTmdhx+gRLJTw4cjVSPAZEwDQYJKoZIhvcNAQELBQAwbjELMAkGA1UEBhMCTUsxEzARBgNVBAgMClNvbWUtU3RhdGUxDzANBgNVBAcMBlNrb3BqZTENMAsGA1UECgwEVUtJTTEqMCgGA1UEAwwhZm11LXN0YWZmLmlkcC1wcm94eS5maW5raS51a2ltLm1rMB4XDTIwMDUzMDE4MDEwM1oXDTMwMDUyODE4MDEwM1owbjELMAkGA1UEBhMCTUsxEzARBgNVBAgMClNvbWUtU3RhdGUxDzANBgNVBAcMBlNrb3BqZTENMAsGA1UECgwEVUtJTTEqMCgGA1UEAwwhZm11LXN0YWZmLmlkcC1wcm94eS5maW5raS51a2ltLm1rMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqMguajYVKXCZEKPzqCvWeOk+zUzYGdxFgbc/t3JxiLH5CzeTCrm8qL2IK+oiAm6SWou4l1K+l40K2PEsX6ghw67B3smxaD9Ul/YuXQbeRcGHncH3+89GtmuxEJmZ5h2/IMmiDxrsq7wraOcUJ+1KjHToodBPQmLz6JmUJS8AeQnIfzjIvRwLCwMmdZqj1w3g4aR2JMsauxoVA/ZuME9wq49zEC7t9zSlFARHIxqpOGmAmOiyy7Ufbps8P3yVEFdhcrkaoRHUr7NKsBbxoixcXaZvGvDA4caIvDWl1TJ8uE7aXBDaJDShqSj4RupXjOV4wHUdxZHGH6bbfaVTOrhQtwIDAQABo1MwUTAdBgNVHQ4EFgQU0s69LrUcFPYk4tUWjJmximhvcOMwHwYDVR0jBBgwFoAU0s69LrUcFPYk4tUWjJmximhvcOMwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEADjad7KaBT4Wz6mDwiWVV/8gG+6LEm8kGZpsqh3f7vPNP5p+dZTnb7lL2jgZz/mPAxI2JoTU5rKIuTjtanY5tFinq5riBEAbafZ04OvHOp3R6BQ80rFnTwNsY24SG27Gki/YLAIgfjuSzWNmJLUuBXQymYxTTyAS+56VonMd2LNk6INhUgM1ztked/3Ck4KfpOKhl4Qt552WHlcdPCyKlnJvl7cwBnZx+ruNzFUXBfoc2fP8WfnKHJKMfF9ZMsc5Nj8s0eRXzgrWLOAsRKPaKmTfVzX+sczsx5+/yMdrRrpyk0YgDoADWJEFca/SO2GOYv6NkzQUUGQDlU/O/NGokLQ==', 'NameIDFormat' => array ( 0 => 'urn:oasis:names:tc:SAML:2.0:nameid-format:persistent', ), 'contacts' => array ( 0 => array ( 'emailAddress' => 'fcc@finki.ukim.mk', 'contactType' => 'technical', 'givenName' => 'FINKI', 'surName' => 'FCC', ), ), );
Certifikater
Download X509 certifikaterne som PEM-indkodet filer.