Metadati SAML 2.0 IdP
Questi sono i metadati che SimpleSAMLphp ha generato e che possono essere inviati ai partner fidati per creare una federazione tra siti.
Si possono ottenere i metadati in XML dall'URL dedicata:
https://rv-tool-sso.testing.ingress-team-elster.n4group.eu/saml2/idp/metadata.php
Metadati
Metadati SAML 2.0 in formato XML:
<?xml version="1.0"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://rv-tool-sso.testing.ingress-team-elster.n4group.eu/saml2/idp/metadata.php">
<md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<md:KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>MIIDaTCCAlGgAwIBAgIQWBv42GF/1j0auStgQNGlszANBgkqhkiG9w0BAQsFADAkMSIwIAYDVQQDDBlSVi1Ub29sIFRlc3QgSW50ZXJtZWRpYXRlMB4XDTI2MDQyMjEzNTM0NloXDTI2MDgyMDEzNTM0NlowFzEVMBMGA1UEAwwMcnYtdG9vbC1zYW1sMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApsrkO6Q5iLwOO1ggGewpTFDq529tieln5gxv9CK8ljbnBpGfYKPTiV7uAK3yfpYmTNYUIOcSv39cMJGGfXgxeepDzfZg7lUbnmRH+8+NJzVdGCNPC5vGUXrOIMpwAj8eKEwOQlOJ1U2J25PrQ1PStnB6Aw7thsj7WidbURCEX0ul8DnW+EtjijvnvKEGgKdhDk76XL2GzqUYcjHl96jzsqrjQde7O+lR4DFs6fcWbC167a+JgiCzK2rLLVAqGDg1SwUrQoiNNK82TvRB5cIz05M+G65EYe3cbgnWHl/TCwSc5zw5h+qac8LthP0eP79e9i5uZDJxI5MjOfYTgrzdUwIDAQABo4GjMIGgMAkGA1UdEwQCMAAwHQYDVR0OBBYEFBTF2scOpTlp4ga8s/85FPbwJnIhMFIGA1UdIwRLMEmAFNYHDDPI8cPUV668kwkrNz0r6twOoR6kHDAaMRgwFgYDVQQDDA9SVi1Ub29sIFRlc3QgQ0GCEQCEb2P7mXDUCY90LOVPmBhGMBMGA1UdJQQMMAoGCCsGAQUFBwMBMAsGA1UdDwQEAwIFoDANBgkqhkiG9w0BAQsFAAOCAQEArgLbIMjlBQkkvHoItQ4nK74FNy/qFxOb25+sGMq0oPJ70QBn3uLwFwjQPwJkPBXFzbZ+X3ju7f6CeYBZWKGyY10+0UDf07f9qk4CaNGPPlT5MNTcsiJBe/VVEyi3/z6Gc/rUPYHDPMVj/92wvO1OY1651uoXumgPVGUpmXWRB+ZSXm1mDfvvVvviyLk5jem8xCi5+Bh4IwmoYVag6l+NMwSdF8sUW90SM2iy2+i7QIlJFlNRP936SxLkyVlpBD0Pujtz+4+GC75CSHUftXaoDzTd8d8oY9bNlOfCGqZ3d5lKjetyFuqEMTeL3kucgrSMxr1F57uSHER7ihC+6gulqg==</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:KeyDescriptor use="encryption">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>MIIDaTCCAlGgAwIBAgIQWBv42GF/1j0auStgQNGlszANBgkqhkiG9w0BAQsFADAkMSIwIAYDVQQDDBlSVi1Ub29sIFRlc3QgSW50ZXJtZWRpYXRlMB4XDTI2MDQyMjEzNTM0NloXDTI2MDgyMDEzNTM0NlowFzEVMBMGA1UEAwwMcnYtdG9vbC1zYW1sMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApsrkO6Q5iLwOO1ggGewpTFDq529tieln5gxv9CK8ljbnBpGfYKPTiV7uAK3yfpYmTNYUIOcSv39cMJGGfXgxeepDzfZg7lUbnmRH+8+NJzVdGCNPC5vGUXrOIMpwAj8eKEwOQlOJ1U2J25PrQ1PStnB6Aw7thsj7WidbURCEX0ul8DnW+EtjijvnvKEGgKdhDk76XL2GzqUYcjHl96jzsqrjQde7O+lR4DFs6fcWbC167a+JgiCzK2rLLVAqGDg1SwUrQoiNNK82TvRB5cIz05M+G65EYe3cbgnWHl/TCwSc5zw5h+qac8LthP0eP79e9i5uZDJxI5MjOfYTgrzdUwIDAQABo4GjMIGgMAkGA1UdEwQCMAAwHQYDVR0OBBYEFBTF2scOpTlp4ga8s/85FPbwJnIhMFIGA1UdIwRLMEmAFNYHDDPI8cPUV668kwkrNz0r6twOoR6kHDAaMRgwFgYDVQQDDA9SVi1Ub29sIFRlc3QgQ0GCEQCEb2P7mXDUCY90LOVPmBhGMBMGA1UdJQQMMAoGCCsGAQUFBwMBMAsGA1UdDwQEAwIFoDANBgkqhkiG9w0BAQsFAAOCAQEArgLbIMjlBQkkvHoItQ4nK74FNy/qFxOb25+sGMq0oPJ70QBn3uLwFwjQPwJkPBXFzbZ+X3ju7f6CeYBZWKGyY10+0UDf07f9qk4CaNGPPlT5MNTcsiJBe/VVEyi3/z6Gc/rUPYHDPMVj/92wvO1OY1651uoXumgPVGUpmXWRB+ZSXm1mDfvvVvviyLk5jem8xCi5+Bh4IwmoYVag6l+NMwSdF8sUW90SM2iy2+i7QIlJFlNRP936SxLkyVlpBD0Pujtz+4+GC75CSHUftXaoDzTd8d8oY9bNlOfCGqZ3d5lKjetyFuqEMTeL3kucgrSMxr1F57uSHER7ihC+6gulqg==</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://rv-tool-sso.testing.ingress-team-elster.n4group.eu/saml2/idp/SingleLogoutService.php"/>
<md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://rv-tool-sso.testing.ingress-team-elster.n4group.eu/saml2/idp/SSOService.php"/>
</md:IDPSSODescriptor>
<md:ContactPerson contactType="technical">
<md:GivenName>Jan</md:GivenName>
<md:SurName>Kohnert</md:SurName>
<md:EmailAddress>mailto:jan.kohnert@n4.de</md:EmailAddress>
</md:ContactPerson>
</md:EntityDescriptor>
In formato flat per SimpleSAMLphp - da utilizzare se dall'altra parte c'è un'entità che utilizza SimpleSAMLphp
$metadata['https://rv-tool-sso.testing.ingress-team-elster.n4group.eu/saml2/idp/metadata.php'] = [
'metadata-set' => 'saml20-idp-remote',
'entityid' => 'https://rv-tool-sso.testing.ingress-team-elster.n4group.eu/saml2/idp/metadata.php',
'SingleSignOnService' => [
[
'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
'Location' => 'https://rv-tool-sso.testing.ingress-team-elster.n4group.eu/saml2/idp/SSOService.php',
],
],
'SingleLogoutService' => [
[
'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
'Location' => 'https://rv-tool-sso.testing.ingress-team-elster.n4group.eu/saml2/idp/SingleLogoutService.php',
],
],
'certData' => 'MIIDaTCCAlGgAwIBAgIQWBv42GF/1j0auStgQNGlszANBgkqhkiG9w0BAQsFADAkMSIwIAYDVQQDDBlSVi1Ub29sIFRlc3QgSW50ZXJtZWRpYXRlMB4XDTI2MDQyMjEzNTM0NloXDTI2MDgyMDEzNTM0NlowFzEVMBMGA1UEAwwMcnYtdG9vbC1zYW1sMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApsrkO6Q5iLwOO1ggGewpTFDq529tieln5gxv9CK8ljbnBpGfYKPTiV7uAK3yfpYmTNYUIOcSv39cMJGGfXgxeepDzfZg7lUbnmRH+8+NJzVdGCNPC5vGUXrOIMpwAj8eKEwOQlOJ1U2J25PrQ1PStnB6Aw7thsj7WidbURCEX0ul8DnW+EtjijvnvKEGgKdhDk76XL2GzqUYcjHl96jzsqrjQde7O+lR4DFs6fcWbC167a+JgiCzK2rLLVAqGDg1SwUrQoiNNK82TvRB5cIz05M+G65EYe3cbgnWHl/TCwSc5zw5h+qac8LthP0eP79e9i5uZDJxI5MjOfYTgrzdUwIDAQABo4GjMIGgMAkGA1UdEwQCMAAwHQYDVR0OBBYEFBTF2scOpTlp4ga8s/85FPbwJnIhMFIGA1UdIwRLMEmAFNYHDDPI8cPUV668kwkrNz0r6twOoR6kHDAaMRgwFgYDVQQDDA9SVi1Ub29sIFRlc3QgQ0GCEQCEb2P7mXDUCY90LOVPmBhGMBMGA1UdJQQMMAoGCCsGAQUFBwMBMAsGA1UdDwQEAwIFoDANBgkqhkiG9w0BAQsFAAOCAQEArgLbIMjlBQkkvHoItQ4nK74FNy/qFxOb25+sGMq0oPJ70QBn3uLwFwjQPwJkPBXFzbZ+X3ju7f6CeYBZWKGyY10+0UDf07f9qk4CaNGPPlT5MNTcsiJBe/VVEyi3/z6Gc/rUPYHDPMVj/92wvO1OY1651uoXumgPVGUpmXWRB+ZSXm1mDfvvVvviyLk5jem8xCi5+Bh4IwmoYVag6l+NMwSdF8sUW90SM2iy2+i7QIlJFlNRP936SxLkyVlpBD0Pujtz+4+GC75CSHUftXaoDzTd8d8oY9bNlOfCGqZ3d5lKjetyFuqEMTeL3kucgrSMxr1F57uSHER7ihC+6gulqg==',
'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient',
'contacts' => [
[
'emailAddress' => 'jan.kohnert@n4.de',
'contactType' => 'technical',
'givenName' => 'Jan',
'surName' => 'Kohnert',
],
],
];
Certificati
Scarica i certificati X509 come file PEM-encoded