SAML 2.0 IdP metaandmed
Need on SimpleSAMLphp poolt sulle genereeritud metaandmed. Võid saata need metaandmed usaldatavatele partneritele usaldatava föderatsiooni loomiseks.
Metaandmete XML-i on võimalik saada spetsiaalselt aadressilt:
https://idp.olvaso.konyvtar.mta.hu/simplesaml/saml2/idp/metadata.php
Metaandmed
SAML 2.0 metaandmete XML-vormingus:
<?xml version="1.0"?> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://idp.olvaso.konyvtar.mta.hu/simplesaml/saml2/idp/metadata.php"> <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIFZzCCBE+gAwIBAgIQCUuLur7jSh+R7hCWUxYcvDANBgkqhkiG9w0BAQsFADBkMQswCQYDVQQGEwJOTDEWMBQGA1UECBMNTm9vcmQtSG9sbGFuZDESMBAGA1UEBxMJQW1zdGVyZGFtMQ8wDQYDVQQKEwZURVJFTkExGDAWBgNVBAMTD1RFUkVOQSBTU0wgQ0EgMzAeFw0xNzEwMzAwMDAwMDBaFw0yMDExMDMxMjAwMDBaMIGjMQswCQYDVQQGEwJIVTERMA8GA1UEBxMIQnVkYXBlc3QxMjAwBgNVBAoMKU1UQSBLw7ZueXZ0w6FyIMOpcyBJbmZvcm3DoWNpw7NzIEvDtnpwb250MSgwJgYDVQQLEx9Lb255dnRhciBlcyBJbmZvcm1hY2lvcyBLb3pwb250MSMwIQYDVQQDExppZHAub2x2YXNvLmtvbnl2dGFyLm10YS5odTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMiCxQWpb4JTrPuj24rREOCY8Jm8zffzmn/wahWGij1nvQ1yOMzN8sUkllIeub7PBaXdp2sX/tNSfyZWdkZmNPg0ypAy3aorG9VtxQfXcyKEgzPrRTTFT10m882QNMNBJRAlDT4LacAsJ10Dn/oMhGh9VMm0eE3hWJIR2qMNAxyeqPf6j/oG5RCwZCRPd9oKSN1ihfPLTmP/TPB3O9ZyUZYgqlRu8iEr1xjGpSwvDZvXp3qu9H3xeAAEgJ1Cx2lXCLGCbJseJ6mv6X+dPgfdn8r3tW0UMsDvr5sicgVVJf9ImQdqETG1taTnxcn6FRQzE9HS27/LXdoq6YHKhs8EUUsCAwEAAaOCAdMwggHPMB8GA1UdIwQYMBaAFGf9iCAUJ5jHCdIlGbvpURFjdVBiMB0GA1UdDgQWBBRtc2G81lvFmbXtL1wTZRSs01p1lTAlBgNVHREEHjAcghppZHAub2x2YXNvLmtvbnl2dGFyLm10YS5odTAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMGsGA1UdHwRkMGIwL6AtoCuGKWh0dHA6Ly9jcmwzLmRpZ2ljZXJ0LmNvbS9URVJFTkFTU0xDQTMuY3JsMC+gLaArhilodHRwOi8vY3JsNC5kaWdpY2VydC5jb20vVEVSRU5BU1NMQ0EzLmNybDBMBgNVHSAERTBDMDcGCWCGSAGG/WwBATAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BTMAgGBmeBDAECAjBuBggrBgEFBQcBAQRiMGAwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmRpZ2ljZXJ0LmNvbTA4BggrBgEFBQcwAoYsaHR0cDovL2NhY2VydHMuZGlnaWNlcnQuY29tL1RFUkVOQVNTTENBMy5jcnQwDAYDVR0TAQH/BAIwADANBgkqhkiG9w0BAQsFAAOCAQEARiYOv4/2B1sxUE6mVIBGESg4BcaFCohlxrvYZZ4N5OAohq62RT/aUxVHgZN7PE2q6APBhlIjiGO1Aa8ez60ZvM1jAhfagYVnMGyD6xDdlFkOChscLUHdaWKCRqEFtJ9f/HwT+1LZGx0YQBQEO3qghAuJJ+ITMcJGFaeCPJrz/LpvVs7rvfteHpRebOUgjP25nzJ6KvIZbu2qBXGtJ9cgXHr5TfknyOclL2GmLXEFaePFNYMjBi/QgPSwdVyDIEnch1xtNBROO6TsOPSvbKmCJj0xmtFIajeaOl7A10YYAFxMKNFjSFbFW2C0dvIQXTPTuZXkQd+14TkxpLY+ixIB9g==</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIFZzCCBE+gAwIBAgIQCUuLur7jSh+R7hCWUxYcvDANBgkqhkiG9w0BAQsFADBkMQswCQYDVQQGEwJOTDEWMBQGA1UECBMNTm9vcmQtSG9sbGFuZDESMBAGA1UEBxMJQW1zdGVyZGFtMQ8wDQYDVQQKEwZURVJFTkExGDAWBgNVBAMTD1RFUkVOQSBTU0wgQ0EgMzAeFw0xNzEwMzAwMDAwMDBaFw0yMDExMDMxMjAwMDBaMIGjMQswCQYDVQQGEwJIVTERMA8GA1UEBxMIQnVkYXBlc3QxMjAwBgNVBAoMKU1UQSBLw7ZueXZ0w6FyIMOpcyBJbmZvcm3DoWNpw7NzIEvDtnpwb250MSgwJgYDVQQLEx9Lb255dnRhciBlcyBJbmZvcm1hY2lvcyBLb3pwb250MSMwIQYDVQQDExppZHAub2x2YXNvLmtvbnl2dGFyLm10YS5odTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMiCxQWpb4JTrPuj24rREOCY8Jm8zffzmn/wahWGij1nvQ1yOMzN8sUkllIeub7PBaXdp2sX/tNSfyZWdkZmNPg0ypAy3aorG9VtxQfXcyKEgzPrRTTFT10m882QNMNBJRAlDT4LacAsJ10Dn/oMhGh9VMm0eE3hWJIR2qMNAxyeqPf6j/oG5RCwZCRPd9oKSN1ihfPLTmP/TPB3O9ZyUZYgqlRu8iEr1xjGpSwvDZvXp3qu9H3xeAAEgJ1Cx2lXCLGCbJseJ6mv6X+dPgfdn8r3tW0UMsDvr5sicgVVJf9ImQdqETG1taTnxcn6FRQzE9HS27/LXdoq6YHKhs8EUUsCAwEAAaOCAdMwggHPMB8GA1UdIwQYMBaAFGf9iCAUJ5jHCdIlGbvpURFjdVBiMB0GA1UdDgQWBBRtc2G81lvFmbXtL1wTZRSs01p1lTAlBgNVHREEHjAcghppZHAub2x2YXNvLmtvbnl2dGFyLm10YS5odTAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMGsGA1UdHwRkMGIwL6AtoCuGKWh0dHA6Ly9jcmwzLmRpZ2ljZXJ0LmNvbS9URVJFTkFTU0xDQTMuY3JsMC+gLaArhilodHRwOi8vY3JsNC5kaWdpY2VydC5jb20vVEVSRU5BU1NMQ0EzLmNybDBMBgNVHSAERTBDMDcGCWCGSAGG/WwBATAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BTMAgGBmeBDAECAjBuBggrBgEFBQcBAQRiMGAwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmRpZ2ljZXJ0LmNvbTA4BggrBgEFBQcwAoYsaHR0cDovL2NhY2VydHMuZGlnaWNlcnQuY29tL1RFUkVOQVNTTENBMy5jcnQwDAYDVR0TAQH/BAIwADANBgkqhkiG9w0BAQsFAAOCAQEARiYOv4/2B1sxUE6mVIBGESg4BcaFCohlxrvYZZ4N5OAohq62RT/aUxVHgZN7PE2q6APBhlIjiGO1Aa8ez60ZvM1jAhfagYVnMGyD6xDdlFkOChscLUHdaWKCRqEFtJ9f/HwT+1LZGx0YQBQEO3qghAuJJ+ITMcJGFaeCPJrz/LpvVs7rvfteHpRebOUgjP25nzJ6KvIZbu2qBXGtJ9cgXHr5TfknyOclL2GmLXEFaePFNYMjBi/QgPSwdVyDIEnch1xtNBROO6TsOPSvbKmCJj0xmtFIajeaOl7A10YYAFxMKNFjSFbFW2C0dvIQXTPTuZXkQd+14TkxpLY+ixIB9g==</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.olvaso.konyvtar.mta.hu/simplesaml/saml2/idp/SingleLogoutService.php"/> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.olvaso.konyvtar.mta.hu/simplesaml/saml2/idp/SSOService.php"/> </md:IDPSSODescriptor> <md:ContactPerson contactType="technical"> <md:GivenName>MTA_KIK_admin</md:GivenName> <md:EmailAddress>admin@konyvtar.mta.hu</md:EmailAddress> </md:ContactPerson> </md:EntityDescriptor>
SimpleSAMLphp formaadis: kasuta seda siis, kui ka teine pool kasutab SimpleSAMLphp-d:
$metadata['https://idp.olvaso.konyvtar.mta.hu/simplesaml/saml2/idp/metadata.php'] = array ( 'metadata-set' => 'saml20-idp-remote', 'entityid' => 'https://idp.olvaso.konyvtar.mta.hu/simplesaml/saml2/idp/metadata.php', 'SingleSignOnService' => array ( 0 => array ( 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://idp.olvaso.konyvtar.mta.hu/simplesaml/saml2/idp/SSOService.php', ), ), 'SingleLogoutService' => array ( 0 => array ( 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://idp.olvaso.konyvtar.mta.hu/simplesaml/saml2/idp/SingleLogoutService.php', ), ), 'certData' => 'MIIFZzCCBE+gAwIBAgIQCUuLur7jSh+R7hCWUxYcvDANBgkqhkiG9w0BAQsFADBkMQswCQYDVQQGEwJOTDEWMBQGA1UECBMNTm9vcmQtSG9sbGFuZDESMBAGA1UEBxMJQW1zdGVyZGFtMQ8wDQYDVQQKEwZURVJFTkExGDAWBgNVBAMTD1RFUkVOQSBTU0wgQ0EgMzAeFw0xNzEwMzAwMDAwMDBaFw0yMDExMDMxMjAwMDBaMIGjMQswCQYDVQQGEwJIVTERMA8GA1UEBxMIQnVkYXBlc3QxMjAwBgNVBAoMKU1UQSBLw7ZueXZ0w6FyIMOpcyBJbmZvcm3DoWNpw7NzIEvDtnpwb250MSgwJgYDVQQLEx9Lb255dnRhciBlcyBJbmZvcm1hY2lvcyBLb3pwb250MSMwIQYDVQQDExppZHAub2x2YXNvLmtvbnl2dGFyLm10YS5odTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMiCxQWpb4JTrPuj24rREOCY8Jm8zffzmn/wahWGij1nvQ1yOMzN8sUkllIeub7PBaXdp2sX/tNSfyZWdkZmNPg0ypAy3aorG9VtxQfXcyKEgzPrRTTFT10m882QNMNBJRAlDT4LacAsJ10Dn/oMhGh9VMm0eE3hWJIR2qMNAxyeqPf6j/oG5RCwZCRPd9oKSN1ihfPLTmP/TPB3O9ZyUZYgqlRu8iEr1xjGpSwvDZvXp3qu9H3xeAAEgJ1Cx2lXCLGCbJseJ6mv6X+dPgfdn8r3tW0UMsDvr5sicgVVJf9ImQdqETG1taTnxcn6FRQzE9HS27/LXdoq6YHKhs8EUUsCAwEAAaOCAdMwggHPMB8GA1UdIwQYMBaAFGf9iCAUJ5jHCdIlGbvpURFjdVBiMB0GA1UdDgQWBBRtc2G81lvFmbXtL1wTZRSs01p1lTAlBgNVHREEHjAcghppZHAub2x2YXNvLmtvbnl2dGFyLm10YS5odTAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMGsGA1UdHwRkMGIwL6AtoCuGKWh0dHA6Ly9jcmwzLmRpZ2ljZXJ0LmNvbS9URVJFTkFTU0xDQTMuY3JsMC+gLaArhilodHRwOi8vY3JsNC5kaWdpY2VydC5jb20vVEVSRU5BU1NMQ0EzLmNybDBMBgNVHSAERTBDMDcGCWCGSAGG/WwBATAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BTMAgGBmeBDAECAjBuBggrBgEFBQcBAQRiMGAwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmRpZ2ljZXJ0LmNvbTA4BggrBgEFBQcwAoYsaHR0cDovL2NhY2VydHMuZGlnaWNlcnQuY29tL1RFUkVOQVNTTENBMy5jcnQwDAYDVR0TAQH/BAIwADANBgkqhkiG9w0BAQsFAAOCAQEARiYOv4/2B1sxUE6mVIBGESg4BcaFCohlxrvYZZ4N5OAohq62RT/aUxVHgZN7PE2q6APBhlIjiGO1Aa8ez60ZvM1jAhfagYVnMGyD6xDdlFkOChscLUHdaWKCRqEFtJ9f/HwT+1LZGx0YQBQEO3qghAuJJ+ITMcJGFaeCPJrz/LpvVs7rvfteHpRebOUgjP25nzJ6KvIZbu2qBXGtJ9cgXHr5TfknyOclL2GmLXEFaePFNYMjBi/QgPSwdVyDIEnch1xtNBROO6TsOPSvbKmCJj0xmtFIajeaOl7A10YYAFxMKNFjSFbFW2C0dvIQXTPTuZXkQd+14TkxpLY+ixIB9g==', 'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:persistent', 'contacts' => array ( 0 => array ( 'emailAddress' => 'admin@konyvtar.mta.hu', 'contactType' => 'technical', 'givenName' => 'MTA_KIK_admin', ), ), );
Sertifikaadid
Lae alla X509 sertifikaadid PEM kodeeringus failidena.