Metadati SAML 2.0 IdP
Questi sono i metadati che SimpleSAMLphp ha generato e che possono essere inviati ai partner fidati per creare una federazione tra siti.
Si possono ottenere i metadati in XML dall'URL dedicata:
https://idp.demotestwip.it/saml2/idp/metadata.php
Metadati
Metadati SAML 2.0 in formato XML:
<?xml version="1.0"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://team.elitedivision.it/">
<md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<md:KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>MIIDrDCCApSgAwIBAgITRdRDV2LcfyLgRgI1f7oA2CUhGDANBgkqhkiG9w0BAQsFADBmMQswCQYDVQQGEwJJVDEOMAwGA1UECAwFSXRhbHkxHTAbBgNVBAoMFEVsaXRlRGl2aXNpb24gUy5SLkwuMSgwJgYJKoZIhvcNAQkBFhlzZWN1cml0eUBlbGl0ZWRpdmlzaW9uLml0MB4XDTIyMDIxMTEzMzcyOVoXDTIzMDIxMTEzMzcyOVowZjELMAkGA1UEBhMCSVQxDjAMBgNVBAgMBUl0YWx5MR0wGwYDVQQKDBRFbGl0ZURpdmlzaW9uIFMuUi5MLjEoMCYGCSqGSIb3DQEJARYZc2VjdXJpdHlAZWxpdGVkaXZpc2lvbi5pdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL2/YHAfiR0jxcMFKUiTJ8SaYVGM0WH3usWvo21wjuFDy8zdXuBPmUa+B7EcyJ4i9z7KmWrZEzJ/X4iBlw/a0Z755PGKKZ60A3slYb0kNvUEKwSsOKIg9kKhYjxBE6Ro5xDV+niiXOuEghujMBCUDhej7v+5pVLoiY7V/jp8lb7uX4CZ/E6/ovPZWuDsJ4MuT6xndSmYkLuiZta4kNw9ipvAMUMKGx9UzL59ezUxWyCKWGokSVjbCUCmD2xRnLntN3CMuxtljUQpI/Cb+b8TClaYDJW+QnEFRXdVnQDfGhScmUNuNTP2KqlXHHaLxzwpuWFl+tWLbqJtPZ99E/0850ECAwEAAaNTMFEwHQYDVR0OBBYEFIzNZOWGQ69fa9eclzuR4rD0NEWkMB8GA1UdIwQYMBaAFIzNZOWGQ69fa9eclzuR4rD0NEWkMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBALkdFJMOZ6SJ3kGgWjKyTZ1Uf6vq76VF96Jx1ZySIgyU0NQfzfz2tiPs/RxzMcsZ25oxbVlIaiieG+mPBVRQ7VhpnzTAPNmwwIa+BmJLeiDkEI6xGeHrZfKo77i0wpXWNi5HPvCn8vKhafb0/Pz1Ws7b05sVl4m5S64+/knmy5ebCIt5/HgtZ0iyXJJNOuSCiZ7YmsyIy3Dfbd6VrVMy3Jn/za9B1b+MpmE8q1I/HOl9Fg7VEP3QEoyXMPyu4cM6Co3MfRdDwkH1/c16KAnMKxniZSPOvHB2UPE9JEPutSRT0Cbrt8WARSwE6a6UpYvRkOK9Wkc2xZeTfxYkEVnRm6I=</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:KeyDescriptor use="encryption">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>MIIDrDCCApSgAwIBAgITRdRDV2LcfyLgRgI1f7oA2CUhGDANBgkqhkiG9w0BAQsFADBmMQswCQYDVQQGEwJJVDEOMAwGA1UECAwFSXRhbHkxHTAbBgNVBAoMFEVsaXRlRGl2aXNpb24gUy5SLkwuMSgwJgYJKoZIhvcNAQkBFhlzZWN1cml0eUBlbGl0ZWRpdmlzaW9uLml0MB4XDTIyMDIxMTEzMzcyOVoXDTIzMDIxMTEzMzcyOVowZjELMAkGA1UEBhMCSVQxDjAMBgNVBAgMBUl0YWx5MR0wGwYDVQQKDBRFbGl0ZURpdmlzaW9uIFMuUi5MLjEoMCYGCSqGSIb3DQEJARYZc2VjdXJpdHlAZWxpdGVkaXZpc2lvbi5pdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL2/YHAfiR0jxcMFKUiTJ8SaYVGM0WH3usWvo21wjuFDy8zdXuBPmUa+B7EcyJ4i9z7KmWrZEzJ/X4iBlw/a0Z755PGKKZ60A3slYb0kNvUEKwSsOKIg9kKhYjxBE6Ro5xDV+niiXOuEghujMBCUDhej7v+5pVLoiY7V/jp8lb7uX4CZ/E6/ovPZWuDsJ4MuT6xndSmYkLuiZta4kNw9ipvAMUMKGx9UzL59ezUxWyCKWGokSVjbCUCmD2xRnLntN3CMuxtljUQpI/Cb+b8TClaYDJW+QnEFRXdVnQDfGhScmUNuNTP2KqlXHHaLxzwpuWFl+tWLbqJtPZ99E/0850ECAwEAAaNTMFEwHQYDVR0OBBYEFIzNZOWGQ69fa9eclzuR4rD0NEWkMB8GA1UdIwQYMBaAFIzNZOWGQ69fa9eclzuR4rD0NEWkMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBALkdFJMOZ6SJ3kGgWjKyTZ1Uf6vq76VF96Jx1ZySIgyU0NQfzfz2tiPs/RxzMcsZ25oxbVlIaiieG+mPBVRQ7VhpnzTAPNmwwIa+BmJLeiDkEI6xGeHrZfKo77i0wpXWNi5HPvCn8vKhafb0/Pz1Ws7b05sVl4m5S64+/knmy5ebCIt5/HgtZ0iyXJJNOuSCiZ7YmsyIy3Dfbd6VrVMy3Jn/za9B1b+MpmE8q1I/HOl9Fg7VEP3QEoyXMPyu4cM6Co3MfRdDwkH1/c16KAnMKxniZSPOvHB2UPE9JEPutSRT0Cbrt8WARSwE6a6UpYvRkOK9Wkc2xZeTfxYkEVnRm6I=</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.demotestwip.it/saml2/idp/SingleLogoutService.php"/>
<md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.demotestwip.it/saml2/idp/SSOService.php"/>
</md:IDPSSODescriptor>
<md:ContactPerson contactType="technical">
<md:GivenName>Security</md:GivenName>
<md:EmailAddress>mailto:security@elitedivision.it</md:EmailAddress>
</md:ContactPerson>
</md:EntityDescriptor>
In formato flat per SimpleSAMLphp - da utilizzare se dall'altra parte c'è un'entità che utilizza SimpleSAMLphp
$metadata['https://team.elitedivision.it/'] = [
'metadata-set' => 'saml20-idp-remote',
'entityid' => 'https://team.elitedivision.it/',
'SingleSignOnService' => [
[
'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
'Location' => 'https://idp.demotestwip.it/saml2/idp/SSOService.php',
],
],
'SingleLogoutService' => [
[
'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
'Location' => 'https://idp.demotestwip.it/saml2/idp/SingleLogoutService.php',
],
],
'certData' => 'MIIDrDCCApSgAwIBAgITRdRDV2LcfyLgRgI1f7oA2CUhGDANBgkqhkiG9w0BAQsFADBmMQswCQYDVQQGEwJJVDEOMAwGA1UECAwFSXRhbHkxHTAbBgNVBAoMFEVsaXRlRGl2aXNpb24gUy5SLkwuMSgwJgYJKoZIhvcNAQkBFhlzZWN1cml0eUBlbGl0ZWRpdmlzaW9uLml0MB4XDTIyMDIxMTEzMzcyOVoXDTIzMDIxMTEzMzcyOVowZjELMAkGA1UEBhMCSVQxDjAMBgNVBAgMBUl0YWx5MR0wGwYDVQQKDBRFbGl0ZURpdmlzaW9uIFMuUi5MLjEoMCYGCSqGSIb3DQEJARYZc2VjdXJpdHlAZWxpdGVkaXZpc2lvbi5pdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL2/YHAfiR0jxcMFKUiTJ8SaYVGM0WH3usWvo21wjuFDy8zdXuBPmUa+B7EcyJ4i9z7KmWrZEzJ/X4iBlw/a0Z755PGKKZ60A3slYb0kNvUEKwSsOKIg9kKhYjxBE6Ro5xDV+niiXOuEghujMBCUDhej7v+5pVLoiY7V/jp8lb7uX4CZ/E6/ovPZWuDsJ4MuT6xndSmYkLuiZta4kNw9ipvAMUMKGx9UzL59ezUxWyCKWGokSVjbCUCmD2xRnLntN3CMuxtljUQpI/Cb+b8TClaYDJW+QnEFRXdVnQDfGhScmUNuNTP2KqlXHHaLxzwpuWFl+tWLbqJtPZ99E/0850ECAwEAAaNTMFEwHQYDVR0OBBYEFIzNZOWGQ69fa9eclzuR4rD0NEWkMB8GA1UdIwQYMBaAFIzNZOWGQ69fa9eclzuR4rD0NEWkMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBALkdFJMOZ6SJ3kGgWjKyTZ1Uf6vq76VF96Jx1ZySIgyU0NQfzfz2tiPs/RxzMcsZ25oxbVlIaiieG+mPBVRQ7VhpnzTAPNmwwIa+BmJLeiDkEI6xGeHrZfKo77i0wpXWNi5HPvCn8vKhafb0/Pz1Ws7b05sVl4m5S64+/knmy5ebCIt5/HgtZ0iyXJJNOuSCiZ7YmsyIy3Dfbd6VrVMy3Jn/za9B1b+MpmE8q1I/HOl9Fg7VEP3QEoyXMPyu4cM6Co3MfRdDwkH1/c16KAnMKxniZSPOvHB2UPE9JEPutSRT0Cbrt8WARSwE6a6UpYvRkOK9Wkc2xZeTfxYkEVnRm6I=',
'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient',
'contacts' => [
[
'emailAddress' => 'security@elitedivision.it',
'contactType' => 'technical',
'givenName' => 'Security',
],
],
];
Certificati
Scarica i certificati X509 come file PEM-encoded