SAML 2.0 IdP Metapodatki
Tu so metapodatki, ki jih je generiral SimpleSAMLphp. Dokument lahko pošljete zaupanja vrednim partnerjem, s katerimi boste ustvarili federacijo.
XML metapodatki se nahajajo na tem naslovu:
https://ai-tool-sso.staging.ingress-team-elster.n4group.eu/saml2/idp/metadata.php
Metapodatki
V SAML 2.0 Metapodatkovni XML format:
<?xml version="1.0"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://ai-tool-sso.staging.ingress-team-elster.n4group.eu/saml2/idp/metadata.php">
<md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<md:KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>MIIDaTCCAlGgAwIBAgIQCJtDdr8A0G9+J/JGonTAUzANBgkqhkiG9w0BAQsFADAkMSIwIAYDVQQDDBlBSS1Ub29sIFRlc3QgSW50ZXJtZWRpYXRlMB4XDTI1MTIwNTE0MTgzOVoXDTI2MDQwNDE0MTgzOVowFzEVMBMGA1UEAwwMYWktdG9vbC1zYW1sMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1hzVZ8pOLe5ZiqWZEfovvKIMA1iP0vy5ds9aC9TfFxcDmPVTAHi8zWC81+OlNFw+fi5PTXtSmSQhNu/8seUz/ZSyEXBGQTsF+/U0eDQYEPFhUmKb00B37B8sFiThds73PlKMJ2Xo5KXUHYbPJnt7n2xoyldQF16SA7iEa/DldRdtEr9okdbYjDS5IBtsbuj3u2k9aN6Z8Y65ncdLqGva86SH+VN+gtV7ZMSJOYWx9C7i1w8N1R5B1hCpCMejTiUL4voOkBK4LWQYcc+3pN5uUqD7PgjAQt+JCcZhIwAY86HWXz2QyRY18wUxd/H9wBikfRxYRq89zmaCtWHHEqLogwIDAQABo4GjMIGgMAkGA1UdEwQCMAAwHQYDVR0OBBYEFGOUZ4xf6gBFa5tjI/kLoZWYlboBMFIGA1UdIwRLMEmAFNWf9vvEE9P2vnHH8it9r8J74fieoR6kHDAaMRgwFgYDVQQDDA9BSS1Ub29sIFRlc3QgQ0GCEQDr0tpLK6HS4WRmM+U6Fk2UMBMGA1UdJQQMMAoGCCsGAQUFBwMBMAsGA1UdDwQEAwIFoDANBgkqhkiG9w0BAQsFAAOCAQEApz0GHbQ8BKioRsmy5sezzUd+YJqfR78odHwoCrEr7sgKXtgvUNZTYig64gsp3c6wIvdjigBl6C+agmohvnwVgRsz9RKqs9GUTQimhShnLN3C4a7+tkGxpBNwsLEFGeVBnUiJo7uCeSSpuvXh1GIupsQjKAmlU/uL9sr4sv+EB6ZZMYwfX5aeEoPownmZdfeoASBHe2/zUzZkPBVpRg3+X71nJyyaD/HgMHoakTerXmdamx6dZsc5xP0q5Af2UikYOFPfY73Jx2PnkIJGMyOe7YDf0VrXswfrPGdnRM1pxMKX6fm6tik0UkkgFFByxqkRj4Uw5oXT4f2aEuWGUZ+fKg==</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:KeyDescriptor use="encryption">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>MIIDaTCCAlGgAwIBAgIQCJtDdr8A0G9+J/JGonTAUzANBgkqhkiG9w0BAQsFADAkMSIwIAYDVQQDDBlBSS1Ub29sIFRlc3QgSW50ZXJtZWRpYXRlMB4XDTI1MTIwNTE0MTgzOVoXDTI2MDQwNDE0MTgzOVowFzEVMBMGA1UEAwwMYWktdG9vbC1zYW1sMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1hzVZ8pOLe5ZiqWZEfovvKIMA1iP0vy5ds9aC9TfFxcDmPVTAHi8zWC81+OlNFw+fi5PTXtSmSQhNu/8seUz/ZSyEXBGQTsF+/U0eDQYEPFhUmKb00B37B8sFiThds73PlKMJ2Xo5KXUHYbPJnt7n2xoyldQF16SA7iEa/DldRdtEr9okdbYjDS5IBtsbuj3u2k9aN6Z8Y65ncdLqGva86SH+VN+gtV7ZMSJOYWx9C7i1w8N1R5B1hCpCMejTiUL4voOkBK4LWQYcc+3pN5uUqD7PgjAQt+JCcZhIwAY86HWXz2QyRY18wUxd/H9wBikfRxYRq89zmaCtWHHEqLogwIDAQABo4GjMIGgMAkGA1UdEwQCMAAwHQYDVR0OBBYEFGOUZ4xf6gBFa5tjI/kLoZWYlboBMFIGA1UdIwRLMEmAFNWf9vvEE9P2vnHH8it9r8J74fieoR6kHDAaMRgwFgYDVQQDDA9BSS1Ub29sIFRlc3QgQ0GCEQDr0tpLK6HS4WRmM+U6Fk2UMBMGA1UdJQQMMAoGCCsGAQUFBwMBMAsGA1UdDwQEAwIFoDANBgkqhkiG9w0BAQsFAAOCAQEApz0GHbQ8BKioRsmy5sezzUd+YJqfR78odHwoCrEr7sgKXtgvUNZTYig64gsp3c6wIvdjigBl6C+agmohvnwVgRsz9RKqs9GUTQimhShnLN3C4a7+tkGxpBNwsLEFGeVBnUiJo7uCeSSpuvXh1GIupsQjKAmlU/uL9sr4sv+EB6ZZMYwfX5aeEoPownmZdfeoASBHe2/zUzZkPBVpRg3+X71nJyyaD/HgMHoakTerXmdamx6dZsc5xP0q5Af2UikYOFPfY73Jx2PnkIJGMyOe7YDf0VrXswfrPGdnRM1pxMKX6fm6tik0UkkgFFByxqkRj4Uw5oXT4f2aEuWGUZ+fKg==</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://ai-tool-sso.staging.ingress-team-elster.n4group.eu/saml2/idp/SingleLogoutService.php"/>
<md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://ai-tool-sso.staging.ingress-team-elster.n4group.eu/saml2/idp/SSOService.php"/>
</md:IDPSSODescriptor>
<md:ContactPerson contactType="technical">
<md:GivenName>Jan</md:GivenName>
<md:SurName>Kohnert</md:SurName>
<md:EmailAddress>mailto:jan.kohnert@n4.de</md:EmailAddress>
</md:ContactPerson>
</md:EntityDescriptor>
V SimpleSAMLphp "flat file" formatu - ta format uporabite, če uporabljate SimpleSAMLphp entiteto na drugi strani:
$metadata['https://ai-tool-sso.staging.ingress-team-elster.n4group.eu/saml2/idp/metadata.php'] = [
'metadata-set' => 'saml20-idp-remote',
'entityid' => 'https://ai-tool-sso.staging.ingress-team-elster.n4group.eu/saml2/idp/metadata.php',
'SingleSignOnService' => [
[
'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
'Location' => 'https://ai-tool-sso.staging.ingress-team-elster.n4group.eu/saml2/idp/SSOService.php',
],
],
'SingleLogoutService' => [
[
'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
'Location' => 'https://ai-tool-sso.staging.ingress-team-elster.n4group.eu/saml2/idp/SingleLogoutService.php',
],
],
'certData' => 'MIIDaTCCAlGgAwIBAgIQCJtDdr8A0G9+J/JGonTAUzANBgkqhkiG9w0BAQsFADAkMSIwIAYDVQQDDBlBSS1Ub29sIFRlc3QgSW50ZXJtZWRpYXRlMB4XDTI1MTIwNTE0MTgzOVoXDTI2MDQwNDE0MTgzOVowFzEVMBMGA1UEAwwMYWktdG9vbC1zYW1sMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1hzVZ8pOLe5ZiqWZEfovvKIMA1iP0vy5ds9aC9TfFxcDmPVTAHi8zWC81+OlNFw+fi5PTXtSmSQhNu/8seUz/ZSyEXBGQTsF+/U0eDQYEPFhUmKb00B37B8sFiThds73PlKMJ2Xo5KXUHYbPJnt7n2xoyldQF16SA7iEa/DldRdtEr9okdbYjDS5IBtsbuj3u2k9aN6Z8Y65ncdLqGva86SH+VN+gtV7ZMSJOYWx9C7i1w8N1R5B1hCpCMejTiUL4voOkBK4LWQYcc+3pN5uUqD7PgjAQt+JCcZhIwAY86HWXz2QyRY18wUxd/H9wBikfRxYRq89zmaCtWHHEqLogwIDAQABo4GjMIGgMAkGA1UdEwQCMAAwHQYDVR0OBBYEFGOUZ4xf6gBFa5tjI/kLoZWYlboBMFIGA1UdIwRLMEmAFNWf9vvEE9P2vnHH8it9r8J74fieoR6kHDAaMRgwFgYDVQQDDA9BSS1Ub29sIFRlc3QgQ0GCEQDr0tpLK6HS4WRmM+U6Fk2UMBMGA1UdJQQMMAoGCCsGAQUFBwMBMAsGA1UdDwQEAwIFoDANBgkqhkiG9w0BAQsFAAOCAQEApz0GHbQ8BKioRsmy5sezzUd+YJqfR78odHwoCrEr7sgKXtgvUNZTYig64gsp3c6wIvdjigBl6C+agmohvnwVgRsz9RKqs9GUTQimhShnLN3C4a7+tkGxpBNwsLEFGeVBnUiJo7uCeSSpuvXh1GIupsQjKAmlU/uL9sr4sv+EB6ZZMYwfX5aeEoPownmZdfeoASBHe2/zUzZkPBVpRg3+X71nJyyaD/HgMHoakTerXmdamx6dZsc5xP0q5Af2UikYOFPfY73Jx2PnkIJGMyOe7YDf0VrXswfrPGdnRM1pxMKX6fm6tik0UkkgFFByxqkRj4Uw5oXT4f2aEuWGUZ+fKg==',
'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient',
'contacts' => [
[
'emailAddress' => 'jan.kohnert@n4.de',
'contactType' => 'technical',
'givenName' => 'Jan',
'surName' => 'Kohnert',
],
],
];
Digitalna potrdila
Prenesi X509 digitalno potrdilo v PEM datoteki.