SAML 2.0 SP metaandmed
Need on SimpleSAMLphp poolt sulle genereeritud metaandmed. Võid saata need metaandmed usaldatavatele partneritele usaldatava föderatsiooni loomiseks.
Metaandmete XML-i on võimalik saada spetsiaalselt aadressilt:
https://sp-dev.ilc4clarin.ilc.cnr.it/module.php/saml/sp/metadata.php/default-sp
Metaandmed
SAML 2.0 metaandmete XML-vormingus:
<?xml version="1.0"?> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://sp-dev.ilc4clarin.ilc.cnr.it/module.php/saml/sp/metadata.php/default-sp"> <md:Extensions> <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute"> <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> <saml:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xs="http://www.w3.org/2001/XMLSchema" xsi:type="xs:string">http://www.geant.net/uri/dataprotection-code-of-conduct/v1</saml:AttributeValue> <saml:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xs="http://www.w3.org/2001/XMLSchema" xsi:type="xs:string">http://refeds.org/category/research-and-scholarship</saml:AttributeValue> <saml:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xs="http://www.w3.org/2001/XMLSchema" xsi:type="xs:string">http://clarin.eu/category/clarin-member</saml:AttributeValue> </saml:Attribute> </mdattr:EntityAttributes> </md:Extensions> <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol"> <md:Extensions> <mdui:UIInfo xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui"> <mdui:DisplayName xml:lang="en">ILC4Clarin Service Provider</mdui:DisplayName> <mdui:DisplayName xml:lang="it">ILC4Clarin Service Provider</mdui:DisplayName> <mdui:Description xml:lang="en">Test service provider for single sign on</mdui:Description> <mdui:Description xml:lang="it">Service provider di test per single sign on</mdui:Description> <mdui:PrivacyStatementURL xml:lang="en">https://sp-dev.ilc4clarin.ilc.cnr.it/xxx</mdui:PrivacyStatementURL> <mdui:PrivacyStatementURL xml:lang="it">https://sp-dev.ilc4clarin.ilc.cnr.it/xxx</mdui:PrivacyStatementURL> <mdui:Logo width="80" height="60">https://sp-dev.ilc4clarin.ilc.cnr.it/xxx.png</mdui:Logo> <mdui:Logo width="16" height="16">https://sp-dev.ilc4clarin.ilc.cnr.it/xxx.png</mdui:Logo> </mdui:UIInfo> </md:Extensions> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIFCDCCA/CgAwIBAgISBMCN0XbI3feV1FvYiz4K7WSaMA0GCSqGSIb3DQEBCwUAMDMxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQwwCgYDVQQDEwNSMTEwHhcNMjQxMDE2MDcwMzQ5WhcNMjUwMTE0MDcwMzQ4WjAnMSUwIwYDVQQDExxzcC1kZXYuaWxjNGNsYXJpbi5pbGMuY25yLml0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvlwxp/TefiAnw0upMtYWTcegCsu5lOB77au73ZNWGclPTBCrAAiNJO0hBRwJccmW4broyd6TIGusaLvjFTj7y29dldZ5+QvwEo6wGLJWfhI4ebBMLpHpcD39n3WeZdfvJ5ZOks3xMTCuq2O1WNmGdvW2f/jCDA5/ic0lNPjj5E782dSAj6mnNRPw8EpkKZNyMKRjAtc1zXYa+T6gxf4BMyd/jhwStOuIMkdgJsxCZWwktYz7KnzWDMs9gAldbq6zMOnJZuWQ8lmqc5Q1l5cF2OuPeDKGgVhg1xpERW7Xmf8gMNvlJqm1C5Oi+K2eJ0fZEf2u3UC+rVhfkIG4qQmCMQIDAQABo4ICIDCCAhwwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQWbole1WpxrOs1TfMQGW0E/x0tDTAfBgNVHSMEGDAWgBTFz0ak6vTDwHpslcQtsF6SLybjuTBXBggrBgEFBQcBAQRLMEkwIgYIKwYBBQUHMAGGFmh0dHA6Ly9yMTEuby5sZW5jci5vcmcwIwYIKwYBBQUHMAKGF2h0dHA6Ly9yMTEuaS5sZW5jci5vcmcvMCcGA1UdEQQgMB6CHHNwLWRldi5pbGM0Y2xhcmluLmlsYy5jbnIuaXQwEwYDVR0gBAwwCjAIBgZngQwBAgEwggEEBgorBgEEAdZ5AgQCBIH1BIHyAPAAdwA/F0tP1yJHWJQdZRyEvg0S7ZA3fx+FauvBvyiF7PhkbgAAAZKUWWXsAAAEAwBIMEYCIQDOoFTmqI1eozEho4TdQMCbjvb9xkG2lGbKNnPnLLh9GgIhAORfK4/B22OUPR3HBe8+HxAR2+uf9Brbtp7B5EZyQEQ5AHUA4JKz/AwdyOdoNh/eYbmWTQpSeBmKctZyxLBNpW1vVAQAAAGSlFltzAAABAMARjBEAiB9MFu81IhmhbCE0Tvhv3jbWZGQIdeeZb9lqT9o68NK3wIgVda88qoE0wPe2ocWZC4GzXYlLVpAmuhraWQYG1AFFNUwDQYJKoZIhvcNAQELBQADggEBADrWZLIIGHUNZEmfEtuCAYeKv4uCLXghjcCSaEOQMGr+Na2PdoXUW/VtemC/L5s5v3DiV3D40keItHorakqdqk4oSoh0DfQi+CglOqL3LoClIzUh7L5Ygl8BwiTrGpXNxj20VqvmZLzKOKjwhD4Pi5D27xi+HNqSyOZlX3OkXY8cPXlaJpn4B8KxGOlEbutK+2W7rWu/gz4ozaAVj8dnwG10kQ1fh5sEXaFaKkG5NTqVYFfqrlCfHG4roa04hf7trZvQsm/KuZ+Tp+E/KGDi8HasXcMY1Iyl5mk/7YAyh9V8bDKHzswwMEVyT6FIl9fN0CsOY4ob05laN8MKWnFGl7c=</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIFCDCCA/CgAwIBAgISBMCN0XbI3feV1FvYiz4K7WSaMA0GCSqGSIb3DQEBCwUAMDMxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQwwCgYDVQQDEwNSMTEwHhcNMjQxMDE2MDcwMzQ5WhcNMjUwMTE0MDcwMzQ4WjAnMSUwIwYDVQQDExxzcC1kZXYuaWxjNGNsYXJpbi5pbGMuY25yLml0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvlwxp/TefiAnw0upMtYWTcegCsu5lOB77au73ZNWGclPTBCrAAiNJO0hBRwJccmW4broyd6TIGusaLvjFTj7y29dldZ5+QvwEo6wGLJWfhI4ebBMLpHpcD39n3WeZdfvJ5ZOks3xMTCuq2O1WNmGdvW2f/jCDA5/ic0lNPjj5E782dSAj6mnNRPw8EpkKZNyMKRjAtc1zXYa+T6gxf4BMyd/jhwStOuIMkdgJsxCZWwktYz7KnzWDMs9gAldbq6zMOnJZuWQ8lmqc5Q1l5cF2OuPeDKGgVhg1xpERW7Xmf8gMNvlJqm1C5Oi+K2eJ0fZEf2u3UC+rVhfkIG4qQmCMQIDAQABo4ICIDCCAhwwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQWbole1WpxrOs1TfMQGW0E/x0tDTAfBgNVHSMEGDAWgBTFz0ak6vTDwHpslcQtsF6SLybjuTBXBggrBgEFBQcBAQRLMEkwIgYIKwYBBQUHMAGGFmh0dHA6Ly9yMTEuby5sZW5jci5vcmcwIwYIKwYBBQUHMAKGF2h0dHA6Ly9yMTEuaS5sZW5jci5vcmcvMCcGA1UdEQQgMB6CHHNwLWRldi5pbGM0Y2xhcmluLmlsYy5jbnIuaXQwEwYDVR0gBAwwCjAIBgZngQwBAgEwggEEBgorBgEEAdZ5AgQCBIH1BIHyAPAAdwA/F0tP1yJHWJQdZRyEvg0S7ZA3fx+FauvBvyiF7PhkbgAAAZKUWWXsAAAEAwBIMEYCIQDOoFTmqI1eozEho4TdQMCbjvb9xkG2lGbKNnPnLLh9GgIhAORfK4/B22OUPR3HBe8+HxAR2+uf9Brbtp7B5EZyQEQ5AHUA4JKz/AwdyOdoNh/eYbmWTQpSeBmKctZyxLBNpW1vVAQAAAGSlFltzAAABAMARjBEAiB9MFu81IhmhbCE0Tvhv3jbWZGQIdeeZb9lqT9o68NK3wIgVda88qoE0wPe2ocWZC4GzXYlLVpAmuhraWQYG1AFFNUwDQYJKoZIhvcNAQELBQADggEBADrWZLIIGHUNZEmfEtuCAYeKv4uCLXghjcCSaEOQMGr+Na2PdoXUW/VtemC/L5s5v3DiV3D40keItHorakqdqk4oSoh0DfQi+CglOqL3LoClIzUh7L5Ygl8BwiTrGpXNxj20VqvmZLzKOKjwhD4Pi5D27xi+HNqSyOZlX3OkXY8cPXlaJpn4B8KxGOlEbutK+2W7rWu/gz4ozaAVj8dnwG10kQ1fh5sEXaFaKkG5NTqVYFfqrlCfHG4roa04hf7trZvQsm/KuZ+Tp+E/KGDi8HasXcMY1Iyl5mk/7YAyh9V8bDKHzswwMEVyT6FIl9fN0CsOY4ob05laN8MKWnFGl7c=</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://sp-dev.ilc4clarin.ilc.cnr.it/module.php/saml/sp/saml2-logout.php/default-sp"/> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://sp-dev.ilc4clarin.ilc.cnr.it/module.php/saml/sp/saml2-acs.php/default-sp" index="0"/> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://sp-dev.ilc4clarin.ilc.cnr.it/module.php/saml/sp/saml1-acs.php/default-sp" index="1"/> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://sp-dev.ilc4clarin.ilc.cnr.it/module.php/saml/sp/saml2-acs.php/default-sp" index="2"/> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://sp-dev.ilc4clarin.ilc.cnr.it/module.php/saml/sp/saml1-acs.php/default-sp/artifact" index="3"/> <md:AttributeConsumingService index="0"> <md:ServiceName xml:lang="it">Test di configurazione service provider</md:ServiceName> <md:ServiceName xml:lang="en">Configuration test service provider</md:ServiceName> <md:ServiceDescription xml:lang="it">Test configurazione service provider</md:ServiceDescription> <md:ServiceDescription xml:lang="en">Service provider configuration test</md:ServiceDescription> <md:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonPrincipalName" isRequired="true"/> <md:RequestedAttribute Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="email" isRequired="true"/> <md:RequestedAttribute Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="displayName" isRequired="true"/> <md:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonTargetedID" isRequired="true"/> <md:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonScopedAffiliation" isRequired="true"/> </md:AttributeConsumingService> </md:SPSSODescriptor> <md:Organization> <md:OrganizationName xml:lang="en">National Research Council</md:OrganizationName> <md:OrganizationName xml:lang="it">Consiglio Nazionale delle Ricerche</md:OrganizationName> <md:OrganizationDisplayName xml:lang="it">CNR</md:OrganizationDisplayName> <md:OrganizationDisplayName xml:lang="en">CNR</md:OrganizationDisplayName> <md:OrganizationURL xml:lang="it">https://www.cnr.it/it</md:OrganizationURL> <md:OrganizationURL xml:lang="en">https://www.cnr.it/en</md:OrganizationURL> </md:Organization> <md:ContactPerson contactType="support"> <md:Company>Consiglio Nazionale delle Ricerche</md:Company> <md:GivenName>Michele</md:GivenName> <md:SurName>Mallia</md:SurName> <md:EmailAddress>mailto:michele.mallia@cnr.it</md:EmailAddress> <md:TelephoneNumber>(+39)3392804180</md:TelephoneNumber> </md:ContactPerson> <md:ContactPerson contactType="administrative"> <md:Company>Consiglio Nazionale delle Ricerche</md:Company> <md:GivenName>Michele</md:GivenName> <md:SurName>Mallia</md:SurName> <md:EmailAddress>mailto:michele.mallia@cnr.it</md:EmailAddress> <md:TelephoneNumber>(+39)3392804180</md:TelephoneNumber> </md:ContactPerson> </md:EntityDescriptor>
SimpleSAMLphp formaadis: kasuta seda siis, kui ka teine pool kasutab SimpleSAMLphp-d:
$metadata['https://sp-dev.ilc4clarin.ilc.cnr.it/module.php/saml/sp/metadata.php/default-sp'] = [ 'SingleLogoutService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://sp-dev.ilc4clarin.ilc.cnr.it/module.php/saml/sp/saml2-logout.php/default-sp', ], ], 'AssertionConsumerService' => [ [ 'index' => 0, 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST', 'Location' => 'https://sp-dev.ilc4clarin.ilc.cnr.it/module.php/saml/sp/saml2-acs.php/default-sp', ], [ 'index' => 1, 'Binding' => 'urn:oasis:names:tc:SAML:1.0:profiles:browser-post', 'Location' => 'https://sp-dev.ilc4clarin.ilc.cnr.it/module.php/saml/sp/saml1-acs.php/default-sp', ], [ 'index' => 2, 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact', 'Location' => 'https://sp-dev.ilc4clarin.ilc.cnr.it/module.php/saml/sp/saml2-acs.php/default-sp', ], [ 'index' => 3, 'Binding' => 'urn:oasis:names:tc:SAML:1.0:profiles:artifact-01', 'Location' => 'https://sp-dev.ilc4clarin.ilc.cnr.it/module.php/saml/sp/saml1-acs.php/default-sp/artifact', ], ], 'name' => [ 'it' => 'Test di configurazione service provider', 'en' => 'Configuration test service provider', ], 'attributes' => [ 'urn:oid:1.3.6.1.4.1.5923.1.1.1.6', 'urn:oid:0.9.2342.19200300.100.1.3', 'urn:oid:2.16.840.1.113730.3.1.241', 'urn:oid:1.3.6.1.4.1.5923.1.1.1.10', 'urn:oid:1.3.6.1.4.1.5923.1.1.1.9', ], 'attributes.required' => [ 'urn:oid:1.3.6.1.4.1.5923.1.1.1.6', 'urn:oid:0.9.2342.19200300.100.1.3', 'urn:oid:2.16.840.1.113730.3.1.241', 'urn:oid:1.3.6.1.4.1.5923.1.1.1.10', 'urn:oid:1.3.6.1.4.1.5923.1.1.1.9', ], 'description' => [ 'it' => 'Test configurazione service provider', 'en' => 'Service provider configuration test', ], 'attributes.NameFormat' => 'urn:oasis:names:tc:SAML:2.0:attrname-format:uri', 'OrganizationName' => [ 'en' => 'National Research Council', 'it' => 'Consiglio Nazionale delle Ricerche', ], 'OrganizationDisplayName' => [ 'it' => 'CNR', 'en' => 'CNR', ], 'OrganizationURL' => [ 'it' => 'https://www.cnr.it/it', 'en' => 'https://www.cnr.it/en', ], 'contacts' => [ [ 'contactType' => 'support', 'emailAddress' => 'michele.mallia@cnr.it', 'givenName' => 'Michele', 'surName' => 'Mallia', 'telephoneNumber' => '(+39)3392804180', 'company' => 'Consiglio Nazionale delle Ricerche', ], [ 'contactType' => 'administrative', 'emailAddress' => 'michele.mallia@cnr.it', 'givenName' => 'Michele', 'surName' => 'Mallia', 'telephoneNumber' => '(+39)3392804180', 'company' => 'Consiglio Nazionale delle Ricerche', ], ], 'certData' => 'MIIFCDCCA/CgAwIBAgISBMCN0XbI3feV1FvYiz4K7WSaMA0GCSqGSIb3DQEBCwUAMDMxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQwwCgYDVQQDEwNSMTEwHhcNMjQxMDE2MDcwMzQ5WhcNMjUwMTE0MDcwMzQ4WjAnMSUwIwYDVQQDExxzcC1kZXYuaWxjNGNsYXJpbi5pbGMuY25yLml0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvlwxp/TefiAnw0upMtYWTcegCsu5lOB77au73ZNWGclPTBCrAAiNJO0hBRwJccmW4broyd6TIGusaLvjFTj7y29dldZ5+QvwEo6wGLJWfhI4ebBMLpHpcD39n3WeZdfvJ5ZOks3xMTCuq2O1WNmGdvW2f/jCDA5/ic0lNPjj5E782dSAj6mnNRPw8EpkKZNyMKRjAtc1zXYa+T6gxf4BMyd/jhwStOuIMkdgJsxCZWwktYz7KnzWDMs9gAldbq6zMOnJZuWQ8lmqc5Q1l5cF2OuPeDKGgVhg1xpERW7Xmf8gMNvlJqm1C5Oi+K2eJ0fZEf2u3UC+rVhfkIG4qQmCMQIDAQABo4ICIDCCAhwwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQWbole1WpxrOs1TfMQGW0E/x0tDTAfBgNVHSMEGDAWgBTFz0ak6vTDwHpslcQtsF6SLybjuTBXBggrBgEFBQcBAQRLMEkwIgYIKwYBBQUHMAGGFmh0dHA6Ly9yMTEuby5sZW5jci5vcmcwIwYIKwYBBQUHMAKGF2h0dHA6Ly9yMTEuaS5sZW5jci5vcmcvMCcGA1UdEQQgMB6CHHNwLWRldi5pbGM0Y2xhcmluLmlsYy5jbnIuaXQwEwYDVR0gBAwwCjAIBgZngQwBAgEwggEEBgorBgEEAdZ5AgQCBIH1BIHyAPAAdwA/F0tP1yJHWJQdZRyEvg0S7ZA3fx+FauvBvyiF7PhkbgAAAZKUWWXsAAAEAwBIMEYCIQDOoFTmqI1eozEho4TdQMCbjvb9xkG2lGbKNnPnLLh9GgIhAORfK4/B22OUPR3HBe8+HxAR2+uf9Brbtp7B5EZyQEQ5AHUA4JKz/AwdyOdoNh/eYbmWTQpSeBmKctZyxLBNpW1vVAQAAAGSlFltzAAABAMARjBEAiB9MFu81IhmhbCE0Tvhv3jbWZGQIdeeZb9lqT9o68NK3wIgVda88qoE0wPe2ocWZC4GzXYlLVpAmuhraWQYG1AFFNUwDQYJKoZIhvcNAQELBQADggEBADrWZLIIGHUNZEmfEtuCAYeKv4uCLXghjcCSaEOQMGr+Na2PdoXUW/VtemC/L5s5v3DiV3D40keItHorakqdqk4oSoh0DfQi+CglOqL3LoClIzUh7L5Ygl8BwiTrGpXNxj20VqvmZLzKOKjwhD4Pi5D27xi+HNqSyOZlX3OkXY8cPXlaJpn4B8KxGOlEbutK+2W7rWu/gz4ozaAVj8dnwG10kQ1fh5sEXaFaKkG5NTqVYFfqrlCfHG4roa04hf7trZvQsm/KuZ+Tp+E/KGDi8HasXcMY1Iyl5mk/7YAyh9V8bDKHzswwMEVyT6FIl9fN0CsOY4ob05laN8MKWnFGl7c=', 'EntityAttributes' => [ '{urn:oasis:names:tc:SAML:2.0:attrname-format:uri}http://macedir.org/entity-category' => [ 'http://www.geant.net/uri/dataprotection-code-of-conduct/v1', 'http://refeds.org/category/research-and-scholarship', 'http://clarin.eu/category/clarin-member', ], ], ];