SAML 2.0 IdP metaandmed
Need on SimpleSAMLphp poolt sulle genereeritud metaandmed. Võid saata need metaandmed usaldatavatele partneritele usaldatava föderatsiooni loomiseks.
Metaandmete XML-i on võimalik saada spetsiaalselt aadressilt:
https://fzf-staff.idp-proxy.finki.ukim.mk/saml2/idp/metadata.php
Metaandmed
SAML 2.0 metaandmete XML-vormingus:
<?xml version="1.0"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://fzf-staff.idp-proxy.finki.ukim.mk/saml2/idp/metadata.php">
<md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<md:KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>MIIDqzCCApOgAwIBAgIUSNAzJ8qqyQekUbHdKClsEnYwcXowDQYJKoZIhvcNAQELBQAwZTELMAkGA1UEBhMCTUsxCjAIBgNVBAgMASAxDzANBgNVBAcMBlNrb3BqZTENMAsGA1UECgwEVUtJTTEqMCgGA1UEAwwhZnpmLXN0YWZmLmlkcC1wcm94eS5maW5raS51a2ltLm1rMB4XDTIwMDMzMDIzMDgzMFoXDTMwMDMyODIzMDgzMFowZTELMAkGA1UEBhMCTUsxCjAIBgNVBAgMASAxDzANBgNVBAcMBlNrb3BqZTENMAsGA1UECgwEVUtJTTEqMCgGA1UEAwwhZnpmLXN0YWZmLmlkcC1wcm94eS5maW5raS51a2ltLm1rMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvATHs7H0XX+Od5rUOVTMBvhOuA63+XNLkbiBRDVYnOT/UTP/IDVZXatkY0y9a3/Mrm7UQJBytWimud8VUHVAM6jyaPrwuWRZRBvULKuO0BI4E2/msVMElxQ1cIztWb19y2E1D69fAl9Mba/OrfZwwlUCZFBes9vJSDuhKw12MeL+GFyxv8DofmufllVdwNo/6bQG+l8ras5L1BwT2xK4uK/0RrA9igHIyd7ZRzCvklJnln9s6eciImb1Bm+/IFpgr+zche0MwW8ipwj/WZHSpTV3/tqAMWSTMN75Hv94FKpd9E8SQqQB21/eOnKnmWfGjVbxf7r18+n/u3oSNKJ1oQIDAQABo1MwUTAdBgNVHQ4EFgQUPEgyvCBNaP5DN7Tf7WAqQ1JPe50wHwYDVR0jBBgwFoAUPEgyvCBNaP5DN7Tf7WAqQ1JPe50wDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAatx8VP7FU86eZhKkcM+02hW3KixJsvlcBZjhUimaKr/O/BGruHLnRciMwDzBFiD0GcYJdOBokJzLbv0y3SKA6Evpb/OkufKiOrsqvHFPlBZ/j12QtQbNBO3dj9lakko4PSdXe4aB6tQPdqhXFxgNtB/8N7Be2cAo/XXiA4fGWmWTqMUJP7iwlxWnTDRPGr362nrwMUdguYNBA2ttJPXIQrIZEe8/vyDW1jD1XjYvyLabLN3zZvXDCvPbSujFjQJ0qTY4h7Hx+5lgK4IY7bqhJ0ELqjE98FFdmj/9mHVZ2NQKVvT3sla5aUxvLAFKSY6XfH0za5UxeGikpJc7CCZWkA==</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:KeyDescriptor use="encryption">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>MIIDqzCCApOgAwIBAgIUSNAzJ8qqyQekUbHdKClsEnYwcXowDQYJKoZIhvcNAQELBQAwZTELMAkGA1UEBhMCTUsxCjAIBgNVBAgMASAxDzANBgNVBAcMBlNrb3BqZTENMAsGA1UECgwEVUtJTTEqMCgGA1UEAwwhZnpmLXN0YWZmLmlkcC1wcm94eS5maW5raS51a2ltLm1rMB4XDTIwMDMzMDIzMDgzMFoXDTMwMDMyODIzMDgzMFowZTELMAkGA1UEBhMCTUsxCjAIBgNVBAgMASAxDzANBgNVBAcMBlNrb3BqZTENMAsGA1UECgwEVUtJTTEqMCgGA1UEAwwhZnpmLXN0YWZmLmlkcC1wcm94eS5maW5raS51a2ltLm1rMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvATHs7H0XX+Od5rUOVTMBvhOuA63+XNLkbiBRDVYnOT/UTP/IDVZXatkY0y9a3/Mrm7UQJBytWimud8VUHVAM6jyaPrwuWRZRBvULKuO0BI4E2/msVMElxQ1cIztWb19y2E1D69fAl9Mba/OrfZwwlUCZFBes9vJSDuhKw12MeL+GFyxv8DofmufllVdwNo/6bQG+l8ras5L1BwT2xK4uK/0RrA9igHIyd7ZRzCvklJnln9s6eciImb1Bm+/IFpgr+zche0MwW8ipwj/WZHSpTV3/tqAMWSTMN75Hv94FKpd9E8SQqQB21/eOnKnmWfGjVbxf7r18+n/u3oSNKJ1oQIDAQABo1MwUTAdBgNVHQ4EFgQUPEgyvCBNaP5DN7Tf7WAqQ1JPe50wHwYDVR0jBBgwFoAUPEgyvCBNaP5DN7Tf7WAqQ1JPe50wDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAatx8VP7FU86eZhKkcM+02hW3KixJsvlcBZjhUimaKr/O/BGruHLnRciMwDzBFiD0GcYJdOBokJzLbv0y3SKA6Evpb/OkufKiOrsqvHFPlBZ/j12QtQbNBO3dj9lakko4PSdXe4aB6tQPdqhXFxgNtB/8N7Be2cAo/XXiA4fGWmWTqMUJP7iwlxWnTDRPGr362nrwMUdguYNBA2ttJPXIQrIZEe8/vyDW1jD1XjYvyLabLN3zZvXDCvPbSujFjQJ0qTY4h7Hx+5lgK4IY7bqhJ0ELqjE98FFdmj/9mHVZ2NQKVvT3sla5aUxvLAFKSY6XfH0za5UxeGikpJc7CCZWkA==</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://fzf-staff.idp-proxy.finki.ukim.mk/saml2/idp/SingleLogoutService.php"/>
<md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat>
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://fzf-staff.idp-proxy.finki.ukim.mk/saml2/idp/SSOService.php"/>
</md:IDPSSODescriptor>
<md:ContactPerson contactType="technical">
<md:GivenName>FINKI</md:GivenName>
<md:SurName>FCC</md:SurName>
<md:EmailAddress>fcc@finki.ukim.mk</md:EmailAddress>
</md:ContactPerson>
</md:EntityDescriptor>
SimpleSAMLphp formaadis: kasuta seda siis, kui ka teine pool kasutab SimpleSAMLphp-d:
$metadata['https://fzf-staff.idp-proxy.finki.ukim.mk/saml2/idp/metadata.php'] = array (
'metadata-set' => 'saml20-idp-remote',
'entityid' => 'https://fzf-staff.idp-proxy.finki.ukim.mk/saml2/idp/metadata.php',
'SingleSignOnService' =>
array (
0 =>
array (
'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
'Location' => 'https://fzf-staff.idp-proxy.finki.ukim.mk/saml2/idp/SSOService.php',
),
),
'SingleLogoutService' =>
array (
0 =>
array (
'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
'Location' => 'https://fzf-staff.idp-proxy.finki.ukim.mk/saml2/idp/SingleLogoutService.php',
),
),
'certData' => 'MIIDqzCCApOgAwIBAgIUSNAzJ8qqyQekUbHdKClsEnYwcXowDQYJKoZIhvcNAQELBQAwZTELMAkGA1UEBhMCTUsxCjAIBgNVBAgMASAxDzANBgNVBAcMBlNrb3BqZTENMAsGA1UECgwEVUtJTTEqMCgGA1UEAwwhZnpmLXN0YWZmLmlkcC1wcm94eS5maW5raS51a2ltLm1rMB4XDTIwMDMzMDIzMDgzMFoXDTMwMDMyODIzMDgzMFowZTELMAkGA1UEBhMCTUsxCjAIBgNVBAgMASAxDzANBgNVBAcMBlNrb3BqZTENMAsGA1UECgwEVUtJTTEqMCgGA1UEAwwhZnpmLXN0YWZmLmlkcC1wcm94eS5maW5raS51a2ltLm1rMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvATHs7H0XX+Od5rUOVTMBvhOuA63+XNLkbiBRDVYnOT/UTP/IDVZXatkY0y9a3/Mrm7UQJBytWimud8VUHVAM6jyaPrwuWRZRBvULKuO0BI4E2/msVMElxQ1cIztWb19y2E1D69fAl9Mba/OrfZwwlUCZFBes9vJSDuhKw12MeL+GFyxv8DofmufllVdwNo/6bQG+l8ras5L1BwT2xK4uK/0RrA9igHIyd7ZRzCvklJnln9s6eciImb1Bm+/IFpgr+zche0MwW8ipwj/WZHSpTV3/tqAMWSTMN75Hv94FKpd9E8SQqQB21/eOnKnmWfGjVbxf7r18+n/u3oSNKJ1oQIDAQABo1MwUTAdBgNVHQ4EFgQUPEgyvCBNaP5DN7Tf7WAqQ1JPe50wHwYDVR0jBBgwFoAUPEgyvCBNaP5DN7Tf7WAqQ1JPe50wDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAatx8VP7FU86eZhKkcM+02hW3KixJsvlcBZjhUimaKr/O/BGruHLnRciMwDzBFiD0GcYJdOBokJzLbv0y3SKA6Evpb/OkufKiOrsqvHFPlBZ/j12QtQbNBO3dj9lakko4PSdXe4aB6tQPdqhXFxgNtB/8N7Be2cAo/XXiA4fGWmWTqMUJP7iwlxWnTDRPGr362nrwMUdguYNBA2ttJPXIQrIZEe8/vyDW1jD1XjYvyLabLN3zZvXDCvPbSujFjQJ0qTY4h7Hx+5lgK4IY7bqhJ0ELqjE98FFdmj/9mHVZ2NQKVvT3sla5aUxvLAFKSY6XfH0za5UxeGikpJc7CCZWkA==',
'NameIDFormat' =>
array (
0 => 'urn:oasis:names:tc:SAML:2.0:nameid-format:persistent',
),
'contacts' =>
array (
0 =>
array (
'emailAddress' => 'fcc@finki.ukim.mk',
'contactType' => 'technical',
'givenName' => 'FINKI',
'surName' => 'FCC',
),
),
);
Sertifikaadid
Lae alla X509 sertifikaadid PEM kodeeringus failidena.