IT | EN

Metadati SAML 2.0 SP

Questi sono i metadati che SimpleSAMLphp ha generato e che possono essere inviati ai partner fidati per creare una federazione tra siti.

Si possono ottenere i metadati in XML dall'URL dedicata:

https://idp.infn.it/module.php/saml/sp/metadata.php/samltest-sp

Metadati

Metadati SAML 2.0 in formato XML:

<?xml version="1.0"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://idp.infn.it/module.php/saml/sp/metadata.php/samltest-sp">
  <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol" AuthnRequestsSigned="true">
    <md:KeyDescriptor use="signing">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:X509Data>
          <ds:X509Certificate>MIIDjTCCAvagAwIBAgIJAPfq4OwPSMNYMA0GCSqGSIb3DQEBBQUAMIGMMQswCQYDVQQGEwJJVDEOMAwGA1UECBMFSXRhbHkxETAPBgNVBAcTCEZyYXNjYXRpMQ0wCwYDVQQKEwRJTkZOMQwwCgYDVQQLEwNMTkYxFDASBgNVBAMTC2lkcC5pbmZuLml0MScwJQYJKoZIhvcNAQkBFhhkYWVsLm1hc2VsbGlAbG5mLmluZm4uaXQwHhcNMDkxMTExMTE0MTA0WhcNMTkxMTExMTE0MTA0WjCBjDELMAkGA1UEBhMCSVQxDjAMBgNVBAgTBUl0YWx5MREwDwYDVQQHEwhGcmFzY2F0aTENMAsGA1UEChMESU5GTjEMMAoGA1UECxMDTE5GMRQwEgYDVQQDEwtpZHAuaW5mbi5pdDEnMCUGCSqGSIb3DQEJARYYZGFlbC5tYXNlbGxpQGxuZi5pbmZuLml0MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQChOkr433M/VQloPoEATlkzWvyFYezT5u09y0KDstDavCCRVVx/r0DSBWdjl9lX4tS1PyDYaIk6sB8L9byI2gtKkGF0Lhvtt5uJ5SInCf7CZkTjBhOcFLBvsdy92Zy5tAbiUPfUOgca4NnJZd3cYV5Vgzv7qeL6viVPDdhAaxt5gwIDAQABo4H0MIHxMB0GA1UdDgQWBBRiuYdkP0U+Z+OAedE6B857jS/TLjCBwQYDVR0jBIG5MIG2gBRiuYdkP0U+Z+OAedE6B857jS/TLqGBkqSBjzCBjDELMAkGA1UEBhMCSVQxDjAMBgNVBAgTBUl0YWx5MREwDwYDVQQHEwhGcmFzY2F0aTENMAsGA1UEChMESU5GTjEMMAoGA1UECxMDTE5GMRQwEgYDVQQDEwtpZHAuaW5mbi5pdDEnMCUGCSqGSIb3DQEJARYYZGFlbC5tYXNlbGxpQGxuZi5pbmZuLml0ggkA9+rg7A9Iw1gwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQUFAAOBgQA1/1W9YoeDO6Sfsur7Tud2MLE0/9ZO57cWq7cBgEg+KfD2yThbyPNlA6dcLiq8Q1yw5WP7ATMpF0C91vjUPpMtdJFr0GOYjyjCkgz4hSE8DwkqaKw2y/uhB63ChMx3zEiR7onoMPdvSmP5NG2k4JP3kP2Bu43wf1GCpgSYJCqRCg==</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:KeyDescriptor use="encryption">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:X509Data>
          <ds:X509Certificate>MIIDjTCCAvagAwIBAgIJAPfq4OwPSMNYMA0GCSqGSIb3DQEBBQUAMIGMMQswCQYDVQQGEwJJVDEOMAwGA1UECBMFSXRhbHkxETAPBgNVBAcTCEZyYXNjYXRpMQ0wCwYDVQQKEwRJTkZOMQwwCgYDVQQLEwNMTkYxFDASBgNVBAMTC2lkcC5pbmZuLml0MScwJQYJKoZIhvcNAQkBFhhkYWVsLm1hc2VsbGlAbG5mLmluZm4uaXQwHhcNMDkxMTExMTE0MTA0WhcNMTkxMTExMTE0MTA0WjCBjDELMAkGA1UEBhMCSVQxDjAMBgNVBAgTBUl0YWx5MREwDwYDVQQHEwhGcmFzY2F0aTENMAsGA1UEChMESU5GTjEMMAoGA1UECxMDTE5GMRQwEgYDVQQDEwtpZHAuaW5mbi5pdDEnMCUGCSqGSIb3DQEJARYYZGFlbC5tYXNlbGxpQGxuZi5pbmZuLml0MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQChOkr433M/VQloPoEATlkzWvyFYezT5u09y0KDstDavCCRVVx/r0DSBWdjl9lX4tS1PyDYaIk6sB8L9byI2gtKkGF0Lhvtt5uJ5SInCf7CZkTjBhOcFLBvsdy92Zy5tAbiUPfUOgca4NnJZd3cYV5Vgzv7qeL6viVPDdhAaxt5gwIDAQABo4H0MIHxMB0GA1UdDgQWBBRiuYdkP0U+Z+OAedE6B857jS/TLjCBwQYDVR0jBIG5MIG2gBRiuYdkP0U+Z+OAedE6B857jS/TLqGBkqSBjzCBjDELMAkGA1UEBhMCSVQxDjAMBgNVBAgTBUl0YWx5MREwDwYDVQQHEwhGcmFzY2F0aTENMAsGA1UEChMESU5GTjEMMAoGA1UECxMDTE5GMRQwEgYDVQQDEwtpZHAuaW5mbi5pdDEnMCUGCSqGSIb3DQEJARYYZGFlbC5tYXNlbGxpQGxuZi5pbmZuLml0ggkA9+rg7A9Iw1gwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQUFAAOBgQA1/1W9YoeDO6Sfsur7Tud2MLE0/9ZO57cWq7cBgEg+KfD2yThbyPNlA6dcLiq8Q1yw5WP7ATMpF0C91vjUPpMtdJFr0GOYjyjCkgz4hSE8DwkqaKw2y/uhB63ChMx3zEiR7onoMPdvSmP5NG2k4JP3kP2Bu43wf1GCpgSYJCqRCg==</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.infn.it/module.php/saml/sp/saml2-logout.php/samltest-sp"/>
    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.infn.it/module.php/saml/sp/saml2-acs.php/samltest-sp" index="0"/>
    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://idp.infn.it/module.php/saml/sp/saml1-acs.php/samltest-sp" index="1"/>
    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://idp.infn.it/module.php/saml/sp/saml2-acs.php/samltest-sp" index="2"/>
    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://idp.infn.it/module.php/saml/sp/saml1-acs.php/samltest-sp/artifact" index="3"/>
  </md:SPSSODescriptor>
</md:EntityDescriptor>

In formato flat per SimpleSAMLphp - da utilizzare se dall'altra parte c'è un'entità che utilizza SimpleSAMLphp

$metadata['https://idp.infn.it/module.php/saml/sp/metadata.php/samltest-sp'] = [
    'SingleLogoutService' => [
        [
            'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
            'Location' => 'https://idp.infn.it/module.php/saml/sp/saml2-logout.php/samltest-sp',
        ],
    ],
    'AssertionConsumerService' => [
        [
            'index' => 0,
            'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST',
            'Location' => 'https://idp.infn.it/module.php/saml/sp/saml2-acs.php/samltest-sp',
        ],
        [
            'index' => 1,
            'Binding' => 'urn:oasis:names:tc:SAML:1.0:profiles:browser-post',
            'Location' => 'https://idp.infn.it/module.php/saml/sp/saml1-acs.php/samltest-sp',
        ],
        [
            'index' => 2,
            'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact',
            'Location' => 'https://idp.infn.it/module.php/saml/sp/saml2-acs.php/samltest-sp',
        ],
        [
            'index' => 3,
            'Binding' => 'urn:oasis:names:tc:SAML:1.0:profiles:artifact-01',
            'Location' => 'https://idp.infn.it/module.php/saml/sp/saml1-acs.php/samltest-sp/artifact',
        ],
    ],
    'certData' => 'MIIDjTCCAvagAwIBAgIJAPfq4OwPSMNYMA0GCSqGSIb3DQEBBQUAMIGMMQswCQYDVQQGEwJJVDEOMAwGA1UECBMFSXRhbHkxETAPBgNVBAcTCEZyYXNjYXRpMQ0wCwYDVQQKEwRJTkZOMQwwCgYDVQQLEwNMTkYxFDASBgNVBAMTC2lkcC5pbmZuLml0MScwJQYJKoZIhvcNAQkBFhhkYWVsLm1hc2VsbGlAbG5mLmluZm4uaXQwHhcNMDkxMTExMTE0MTA0WhcNMTkxMTExMTE0MTA0WjCBjDELMAkGA1UEBhMCSVQxDjAMBgNVBAgTBUl0YWx5MREwDwYDVQQHEwhGcmFzY2F0aTENMAsGA1UEChMESU5GTjEMMAoGA1UECxMDTE5GMRQwEgYDVQQDEwtpZHAuaW5mbi5pdDEnMCUGCSqGSIb3DQEJARYYZGFlbC5tYXNlbGxpQGxuZi5pbmZuLml0MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQChOkr433M/VQloPoEATlkzWvyFYezT5u09y0KDstDavCCRVVx/r0DSBWdjl9lX4tS1PyDYaIk6sB8L9byI2gtKkGF0Lhvtt5uJ5SInCf7CZkTjBhOcFLBvsdy92Zy5tAbiUPfUOgca4NnJZd3cYV5Vgzv7qeL6viVPDdhAaxt5gwIDAQABo4H0MIHxMB0GA1UdDgQWBBRiuYdkP0U+Z+OAedE6B857jS/TLjCBwQYDVR0jBIG5MIG2gBRiuYdkP0U+Z+OAedE6B857jS/TLqGBkqSBjzCBjDELMAkGA1UEBhMCSVQxDjAMBgNVBAgTBUl0YWx5MREwDwYDVQQHEwhGcmFzY2F0aTENMAsGA1UEChMESU5GTjEMMAoGA1UECxMDTE5GMRQwEgYDVQQDEwtpZHAuaW5mbi5pdDEnMCUGCSqGSIb3DQEJARYYZGFlbC5tYXNlbGxpQGxuZi5pbmZuLml0ggkA9+rg7A9Iw1gwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQUFAAOBgQA1/1W9YoeDO6Sfsur7Tud2MLE0/9ZO57cWq7cBgEg+KfD2yThbyPNlA6dcLiq8Q1yw5WP7ATMpF0C91vjUPpMtdJFr0GOYjyjCkgz4hSE8DwkqaKw2y/uhB63ChMx3zEiR7onoMPdvSmP5NG2k4JP3kP2Bu43wf1GCpgSYJCqRCg==',
    'redirect.validate' => true,
];