SAML 2.0 IdP Metapodatki
Tu so metapodatki, ki jih je generiral SimpleSAMLphp. Dokument lahko pošljete zaupanja vrednim partnerjem, s katerimi boste ustvarili federacijo.
XML metapodatki se nahajajo na tem naslovu:
https://idp-social-linkedin.dev.rctsaai.pt/simplesaml/saml2/idp/metadata.php
Metapodatki
V SAML 2.0 Metapodatkovni XML format:
<?xml version="1.0"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://idp-social-linkedin.dev.rctsaai.pt">
<md:Extensions>
<mdrpi:RegistrationInfo xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" registrationAuthority="urn:mace:example.org" registrationInstant="2008-01-17T11:28:03Z">
<mdrpi:RegistrationPolicy xml:lang="en">http://example.org/policy</mdrpi:RegistrationPolicy>
<mdrpi:RegistrationPolicy xml:lang="es">http://example.org/politica</mdrpi:RegistrationPolicy>
</mdrpi:RegistrationInfo>
</md:Extensions>
<md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<md:KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>MIIDhzCCAm+gAwIBAgIJANReKmqIbbfaMA0GCSqGSIb3DQEBCwUAMFoxCzAJBgNVBAYTAlBUMQ8wDQYDVQQIDAZMaXNib24xDzANBgNVBAcMBkxpc2JvbjEMMAoGA1UECgwDRkNUMRswGQYDVQQDDBJpZHAtc29jaWFsLmZjY24ucHQwHhcNMjEwNDI4MjE1MTE0WhcNMzEwNDI4MjE1MTE0WjBaMQswCQYDVQQGEwJQVDEPMA0GA1UECAwGTGlzYm9uMQ8wDQYDVQQHDAZMaXNib24xDDAKBgNVBAoMA0ZDVDEbMBkGA1UEAwwSaWRwLXNvY2lhbC5mY2NuLnB0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4ia7OY/iVRMnoOZGmECb5j2OVtu0sY/uULhEQj6nZ/vg4h7Znl2wy/PUNx++kVxFsab2xO6PZrrjeWMYHSL/NqhUxKmVyFsDPQEM50TU3I600O6WePnME75hZE8K3isohOabyTI+NW5RFlMzwiciXhbfbxVKJ+e/gMOxVSs5Ay5p3dflJRTXT5lPlN4wcSdg0g9Mkysnv0daJ6BHcyaA2UDvsKjkTMEShgfKixyGdO5UmjXWnbav0BsIqOCDyx4mqsbR35BO0Lpchhl3XZsUGSphW9EfuitTU5d9A6Yadb0xaYzGZOBdTWWLDUS8StiikYkfv7vE1PztwC2XklI3OwIDAQABo1AwTjAdBgNVHQ4EFgQUFCO0HyI69rSVz6ozU+7SaPiBAUEwHwYDVR0jBBgwFoAUFCO0HyI69rSVz6ozU+7SaPiBAUEwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAjIaXoKNoXCwPuMBFuOCRU9M8J/ODIZZUIohCQOJHZoYlF8A8Rgr0EIXuaV8CffWnbLaoQP+ozTgekUAtCkNWw2/qzh3BfF+MpzTyjyBWDMdGeDnbT8QWZb3BH61A3w2WKctxd2NPuga8PUuP4w4VNjUXcRzBsmrNEEhZRtpHCp8yqzcP8DJt9BzU9Gl5SdUOV6zFR50GKNj8i11Sirc6TcVTORkDBg6YQe3Nac/GT9idyZwjqaABANM9A0Q3TwkVY+hrVc03bTyzLVJSsrJQzvffal6gFjOUo16P8MOzpxrcLN9Bn+ZS2c85ZE9myfLnoA9gSFY7ESVBWpbul1G+BQ==</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:KeyDescriptor use="encryption">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>MIIDhzCCAm+gAwIBAgIJANReKmqIbbfaMA0GCSqGSIb3DQEBCwUAMFoxCzAJBgNVBAYTAlBUMQ8wDQYDVQQIDAZMaXNib24xDzANBgNVBAcMBkxpc2JvbjEMMAoGA1UECgwDRkNUMRswGQYDVQQDDBJpZHAtc29jaWFsLmZjY24ucHQwHhcNMjEwNDI4MjE1MTE0WhcNMzEwNDI4MjE1MTE0WjBaMQswCQYDVQQGEwJQVDEPMA0GA1UECAwGTGlzYm9uMQ8wDQYDVQQHDAZMaXNib24xDDAKBgNVBAoMA0ZDVDEbMBkGA1UEAwwSaWRwLXNvY2lhbC5mY2NuLnB0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4ia7OY/iVRMnoOZGmECb5j2OVtu0sY/uULhEQj6nZ/vg4h7Znl2wy/PUNx++kVxFsab2xO6PZrrjeWMYHSL/NqhUxKmVyFsDPQEM50TU3I600O6WePnME75hZE8K3isohOabyTI+NW5RFlMzwiciXhbfbxVKJ+e/gMOxVSs5Ay5p3dflJRTXT5lPlN4wcSdg0g9Mkysnv0daJ6BHcyaA2UDvsKjkTMEShgfKixyGdO5UmjXWnbav0BsIqOCDyx4mqsbR35BO0Lpchhl3XZsUGSphW9EfuitTU5d9A6Yadb0xaYzGZOBdTWWLDUS8StiikYkfv7vE1PztwC2XklI3OwIDAQABo1AwTjAdBgNVHQ4EFgQUFCO0HyI69rSVz6ozU+7SaPiBAUEwHwYDVR0jBBgwFoAUFCO0HyI69rSVz6ozU+7SaPiBAUEwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAjIaXoKNoXCwPuMBFuOCRU9M8J/ODIZZUIohCQOJHZoYlF8A8Rgr0EIXuaV8CffWnbLaoQP+ozTgekUAtCkNWw2/qzh3BfF+MpzTyjyBWDMdGeDnbT8QWZb3BH61A3w2WKctxd2NPuga8PUuP4w4VNjUXcRzBsmrNEEhZRtpHCp8yqzcP8DJt9BzU9Gl5SdUOV6zFR50GKNj8i11Sirc6TcVTORkDBg6YQe3Nac/GT9idyZwjqaABANM9A0Q3TwkVY+hrVc03bTyzLVJSsrJQzvffal6gFjOUo16P8MOzpxrcLN9Bn+ZS2c85ZE9myfLnoA9gSFY7ESVBWpbul1G+BQ==</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp-social-linkedin.dev.rctsaai.pt/simplesaml/saml2/idp/SingleLogoutService.php"/>
<md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp-social-linkedin.dev.rctsaai.pt/simplesaml/saml2/idp/SSOService.php"/>
</md:IDPSSODescriptor>
<md:ContactPerson contactType="technical">
<md:GivenName>RCTSaai</md:GivenName>
<md:SurName>Team</md:SurName>
<md:EmailAddress>mailto:suporte@rctsaai.pt</md:EmailAddress>
</md:ContactPerson>
</md:EntityDescriptor>
V SimpleSAMLphp "flat file" formatu - ta format uporabite, če uporabljate SimpleSAMLphp entiteto na drugi strani:
$metadata['https://idp-social-linkedin.dev.rctsaai.pt'] = array (
'metadata-set' => 'saml20-idp-remote',
'entityid' => 'https://idp-social-linkedin.dev.rctsaai.pt',
'SingleSignOnService' =>
array (
0 =>
array (
'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
'Location' => 'https://idp-social-linkedin.dev.rctsaai.pt/simplesaml/saml2/idp/SSOService.php',
),
),
'SingleLogoutService' =>
array (
0 =>
array (
'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
'Location' => 'https://idp-social-linkedin.dev.rctsaai.pt/simplesaml/saml2/idp/SingleLogoutService.php',
),
),
'certData' => 'MIIDhzCCAm+gAwIBAgIJANReKmqIbbfaMA0GCSqGSIb3DQEBCwUAMFoxCzAJBgNVBAYTAlBUMQ8wDQYDVQQIDAZMaXNib24xDzANBgNVBAcMBkxpc2JvbjEMMAoGA1UECgwDRkNUMRswGQYDVQQDDBJpZHAtc29jaWFsLmZjY24ucHQwHhcNMjEwNDI4MjE1MTE0WhcNMzEwNDI4MjE1MTE0WjBaMQswCQYDVQQGEwJQVDEPMA0GA1UECAwGTGlzYm9uMQ8wDQYDVQQHDAZMaXNib24xDDAKBgNVBAoMA0ZDVDEbMBkGA1UEAwwSaWRwLXNvY2lhbC5mY2NuLnB0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4ia7OY/iVRMnoOZGmECb5j2OVtu0sY/uULhEQj6nZ/vg4h7Znl2wy/PUNx++kVxFsab2xO6PZrrjeWMYHSL/NqhUxKmVyFsDPQEM50TU3I600O6WePnME75hZE8K3isohOabyTI+NW5RFlMzwiciXhbfbxVKJ+e/gMOxVSs5Ay5p3dflJRTXT5lPlN4wcSdg0g9Mkysnv0daJ6BHcyaA2UDvsKjkTMEShgfKixyGdO5UmjXWnbav0BsIqOCDyx4mqsbR35BO0Lpchhl3XZsUGSphW9EfuitTU5d9A6Yadb0xaYzGZOBdTWWLDUS8StiikYkfv7vE1PztwC2XklI3OwIDAQABo1AwTjAdBgNVHQ4EFgQUFCO0HyI69rSVz6ozU+7SaPiBAUEwHwYDVR0jBBgwFoAUFCO0HyI69rSVz6ozU+7SaPiBAUEwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAjIaXoKNoXCwPuMBFuOCRU9M8J/ODIZZUIohCQOJHZoYlF8A8Rgr0EIXuaV8CffWnbLaoQP+ozTgekUAtCkNWw2/qzh3BfF+MpzTyjyBWDMdGeDnbT8QWZb3BH61A3w2WKctxd2NPuga8PUuP4w4VNjUXcRzBsmrNEEhZRtpHCp8yqzcP8DJt9BzU9Gl5SdUOV6zFR50GKNj8i11Sirc6TcVTORkDBg6YQe3Nac/GT9idyZwjqaABANM9A0Q3TwkVY+hrVc03bTyzLVJSsrJQzvffal6gFjOUo16P8MOzpxrcLN9Bn+ZS2c85ZE9myfLnoA9gSFY7ESVBWpbul1G+BQ==',
'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient',
'RegistrationInfo' =>
array (
'authority' => 'urn:mace:example.org',
'instant' => '2008-01-17T11:28:03Z',
'policies' =>
array (
'en' => 'http://example.org/policy',
'es' => 'http://example.org/politica',
),
),
'contacts' =>
array (
0 =>
array (
'emailAddress' => 'suporte@rctsaai.pt',
'contactType' => 'technical',
'givenName' => 'RCTSaai',
'surName' => 'Team',
),
),
);
Digitalna potrdila
Prenesi X509 digitalno potrdilo v PEM datoteki.