Metadati SAML 2.0 IdP
Questi sono i metadati che SimpleSAMLphp ha generato e che possono essere inviati ai partner fidati per creare una federazione tra siti.
Si possono ottenere i metadati in XML dall'URL dedicata:
https://idp.demotestwip.it/saml2/idp/metadata.php
Metadati
Metadati SAML 2.0 in formato XML:
<?xml version="1.0"?> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://team.elitedivision.it/"> <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIDrDCCApSgAwIBAgITRdRDV2LcfyLgRgI1f7oA2CUhGDANBgkqhkiG9w0BAQsFADBmMQswCQYDVQQGEwJJVDEOMAwGA1UECAwFSXRhbHkxHTAbBgNVBAoMFEVsaXRlRGl2aXNpb24gUy5SLkwuMSgwJgYJKoZIhvcNAQkBFhlzZWN1cml0eUBlbGl0ZWRpdmlzaW9uLml0MB4XDTIyMDIxMTEzMzcyOVoXDTIzMDIxMTEzMzcyOVowZjELMAkGA1UEBhMCSVQxDjAMBgNVBAgMBUl0YWx5MR0wGwYDVQQKDBRFbGl0ZURpdmlzaW9uIFMuUi5MLjEoMCYGCSqGSIb3DQEJARYZc2VjdXJpdHlAZWxpdGVkaXZpc2lvbi5pdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL2/YHAfiR0jxcMFKUiTJ8SaYVGM0WH3usWvo21wjuFDy8zdXuBPmUa+B7EcyJ4i9z7KmWrZEzJ/X4iBlw/a0Z755PGKKZ60A3slYb0kNvUEKwSsOKIg9kKhYjxBE6Ro5xDV+niiXOuEghujMBCUDhej7v+5pVLoiY7V/jp8lb7uX4CZ/E6/ovPZWuDsJ4MuT6xndSmYkLuiZta4kNw9ipvAMUMKGx9UzL59ezUxWyCKWGokSVjbCUCmD2xRnLntN3CMuxtljUQpI/Cb+b8TClaYDJW+QnEFRXdVnQDfGhScmUNuNTP2KqlXHHaLxzwpuWFl+tWLbqJtPZ99E/0850ECAwEAAaNTMFEwHQYDVR0OBBYEFIzNZOWGQ69fa9eclzuR4rD0NEWkMB8GA1UdIwQYMBaAFIzNZOWGQ69fa9eclzuR4rD0NEWkMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBALkdFJMOZ6SJ3kGgWjKyTZ1Uf6vq76VF96Jx1ZySIgyU0NQfzfz2tiPs/RxzMcsZ25oxbVlIaiieG+mPBVRQ7VhpnzTAPNmwwIa+BmJLeiDkEI6xGeHrZfKo77i0wpXWNi5HPvCn8vKhafb0/Pz1Ws7b05sVl4m5S64+/knmy5ebCIt5/HgtZ0iyXJJNOuSCiZ7YmsyIy3Dfbd6VrVMy3Jn/za9B1b+MpmE8q1I/HOl9Fg7VEP3QEoyXMPyu4cM6Co3MfRdDwkH1/c16KAnMKxniZSPOvHB2UPE9JEPutSRT0Cbrt8WARSwE6a6UpYvRkOK9Wkc2xZeTfxYkEVnRm6I=</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIDrDCCApSgAwIBAgITRdRDV2LcfyLgRgI1f7oA2CUhGDANBgkqhkiG9w0BAQsFADBmMQswCQYDVQQGEwJJVDEOMAwGA1UECAwFSXRhbHkxHTAbBgNVBAoMFEVsaXRlRGl2aXNpb24gUy5SLkwuMSgwJgYJKoZIhvcNAQkBFhlzZWN1cml0eUBlbGl0ZWRpdmlzaW9uLml0MB4XDTIyMDIxMTEzMzcyOVoXDTIzMDIxMTEzMzcyOVowZjELMAkGA1UEBhMCSVQxDjAMBgNVBAgMBUl0YWx5MR0wGwYDVQQKDBRFbGl0ZURpdmlzaW9uIFMuUi5MLjEoMCYGCSqGSIb3DQEJARYZc2VjdXJpdHlAZWxpdGVkaXZpc2lvbi5pdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL2/YHAfiR0jxcMFKUiTJ8SaYVGM0WH3usWvo21wjuFDy8zdXuBPmUa+B7EcyJ4i9z7KmWrZEzJ/X4iBlw/a0Z755PGKKZ60A3slYb0kNvUEKwSsOKIg9kKhYjxBE6Ro5xDV+niiXOuEghujMBCUDhej7v+5pVLoiY7V/jp8lb7uX4CZ/E6/ovPZWuDsJ4MuT6xndSmYkLuiZta4kNw9ipvAMUMKGx9UzL59ezUxWyCKWGokSVjbCUCmD2xRnLntN3CMuxtljUQpI/Cb+b8TClaYDJW+QnEFRXdVnQDfGhScmUNuNTP2KqlXHHaLxzwpuWFl+tWLbqJtPZ99E/0850ECAwEAAaNTMFEwHQYDVR0OBBYEFIzNZOWGQ69fa9eclzuR4rD0NEWkMB8GA1UdIwQYMBaAFIzNZOWGQ69fa9eclzuR4rD0NEWkMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBALkdFJMOZ6SJ3kGgWjKyTZ1Uf6vq76VF96Jx1ZySIgyU0NQfzfz2tiPs/RxzMcsZ25oxbVlIaiieG+mPBVRQ7VhpnzTAPNmwwIa+BmJLeiDkEI6xGeHrZfKo77i0wpXWNi5HPvCn8vKhafb0/Pz1Ws7b05sVl4m5S64+/knmy5ebCIt5/HgtZ0iyXJJNOuSCiZ7YmsyIy3Dfbd6VrVMy3Jn/za9B1b+MpmE8q1I/HOl9Fg7VEP3QEoyXMPyu4cM6Co3MfRdDwkH1/c16KAnMKxniZSPOvHB2UPE9JEPutSRT0Cbrt8WARSwE6a6UpYvRkOK9Wkc2xZeTfxYkEVnRm6I=</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.demotestwip.it/saml2/idp/SingleLogoutService.php"/> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.demotestwip.it/saml2/idp/SSOService.php"/> </md:IDPSSODescriptor> <md:ContactPerson contactType="technical"> <md:GivenName>Security</md:GivenName> <md:EmailAddress>mailto:security@elitedivision.it</md:EmailAddress> </md:ContactPerson> </md:EntityDescriptor>
In formato flat per SimpleSAMLphp - da utilizzare se dall'altra parte c'è un'entità che utilizza SimpleSAMLphp
$metadata['https://team.elitedivision.it/'] = [ 'metadata-set' => 'saml20-idp-remote', 'entityid' => 'https://team.elitedivision.it/', 'SingleSignOnService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://idp.demotestwip.it/saml2/idp/SSOService.php', ], ], 'SingleLogoutService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://idp.demotestwip.it/saml2/idp/SingleLogoutService.php', ], ], 'certData' => 'MIIDrDCCApSgAwIBAgITRdRDV2LcfyLgRgI1f7oA2CUhGDANBgkqhkiG9w0BAQsFADBmMQswCQYDVQQGEwJJVDEOMAwGA1UECAwFSXRhbHkxHTAbBgNVBAoMFEVsaXRlRGl2aXNpb24gUy5SLkwuMSgwJgYJKoZIhvcNAQkBFhlzZWN1cml0eUBlbGl0ZWRpdmlzaW9uLml0MB4XDTIyMDIxMTEzMzcyOVoXDTIzMDIxMTEzMzcyOVowZjELMAkGA1UEBhMCSVQxDjAMBgNVBAgMBUl0YWx5MR0wGwYDVQQKDBRFbGl0ZURpdmlzaW9uIFMuUi5MLjEoMCYGCSqGSIb3DQEJARYZc2VjdXJpdHlAZWxpdGVkaXZpc2lvbi5pdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL2/YHAfiR0jxcMFKUiTJ8SaYVGM0WH3usWvo21wjuFDy8zdXuBPmUa+B7EcyJ4i9z7KmWrZEzJ/X4iBlw/a0Z755PGKKZ60A3slYb0kNvUEKwSsOKIg9kKhYjxBE6Ro5xDV+niiXOuEghujMBCUDhej7v+5pVLoiY7V/jp8lb7uX4CZ/E6/ovPZWuDsJ4MuT6xndSmYkLuiZta4kNw9ipvAMUMKGx9UzL59ezUxWyCKWGokSVjbCUCmD2xRnLntN3CMuxtljUQpI/Cb+b8TClaYDJW+QnEFRXdVnQDfGhScmUNuNTP2KqlXHHaLxzwpuWFl+tWLbqJtPZ99E/0850ECAwEAAaNTMFEwHQYDVR0OBBYEFIzNZOWGQ69fa9eclzuR4rD0NEWkMB8GA1UdIwQYMBaAFIzNZOWGQ69fa9eclzuR4rD0NEWkMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBALkdFJMOZ6SJ3kGgWjKyTZ1Uf6vq76VF96Jx1ZySIgyU0NQfzfz2tiPs/RxzMcsZ25oxbVlIaiieG+mPBVRQ7VhpnzTAPNmwwIa+BmJLeiDkEI6xGeHrZfKo77i0wpXWNi5HPvCn8vKhafb0/Pz1Ws7b05sVl4m5S64+/knmy5ebCIt5/HgtZ0iyXJJNOuSCiZ7YmsyIy3Dfbd6VrVMy3Jn/za9B1b+MpmE8q1I/HOl9Fg7VEP3QEoyXMPyu4cM6Co3MfRdDwkH1/c16KAnMKxniZSPOvHB2UPE9JEPutSRT0Cbrt8WARSwE6a6UpYvRkOK9Wkc2xZeTfxYkEVnRm6I=', 'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient', 'contacts' => [ [ 'emailAddress' => 'security@elitedivision.it', 'contactType' => 'technical', 'givenName' => 'Security', ], ], ];
Certificati
Scarica i certificati X509 come file PEM-encoded