Metadati SAML 2.0 SP
Questi sono i metadati che SimpleSAMLphp ha generato e che possono essere inviati ai partner fidati per creare una federazione tra siti.
Si possono ottenere i metadati in XML dall'URL dedicata:
https://spid.indire.it/sso/module.php/saml/sp/metadata.php/spid
Metadati
Metadati SAML 2.0 in formato XML:
<?xml version="1.0"?> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://spid.indire.it/sso/module.php/saml/sp/metadata.php/spid" ID="pfxa47e5542-5ec2-fc1f-2b3a-9379880717c2"><ds:Signature> <ds:SignedInfo><ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/> <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/> <ds:Reference URI="#pfxa47e5542-5ec2-fc1f-2b3a-9379880717c2"><ds:Transforms><ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/><ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/></ds:Transforms><ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/><ds:DigestValue>pFTx3k5kVqYJ3K8tNihNSl0wmnPv8B/rmHFc530wOuc=</ds:DigestValue></ds:Reference></ds:SignedInfo><ds:SignatureValue>W4fMhM4EDEDk4r8QqNod0hGahZBdTPUYLcNsdAzoa0g+oE7KmIhaQl+4oy6vBS5xy9kGK931joh2MedDcF4uZirTV9axZnZs+h7K3qH9Jrfwt88tx73OoDFvKbxhWHPpHLoMJ/YIqs/nZL3JM4ImCYeejRBAIO2ULj8F9dU/esiNetHvXpMxpbIMTNrdaeAfOb+yUarShRcwKmAlo0hkTEh2pQDuKiS7HpEPkeK+G/Dkswxhh1UHQZAtt+EQ9ZrKX4sHpeLzz94XUAmCVQovKy1XLhfF5AkARBLLDFGDVRQk0j1GWmTAfz8gUShVlnsSNYLwNgdxJS+/sM9zwkf02Q==</ds:SignatureValue> <ds:KeyInfo><ds:X509Data><ds:X509Certificate>MIIDyzCCArOgAwIBAgIJAMz5Vos7s2saMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNVBAYTAklUMRAwDgYDVQQIDAdGaXJlbnplMRAwDgYDVQQHDAdGaXJlbnplMQ8wDQYDVQQKDAZJTkRJUkUxFjAUBgNVBAMMDXd3dy5pbmRpcmUuaXQxIDAeBgkqhkiG9w0BCQEWEWEucm9uY2FAaW5kaXJlLml0MB4XDTE3MDkyNzEzNTU1N1oXDTI3MDkyNzEzNTU1N1owfDELMAkGA1UEBhMCSVQxEDAOBgNVBAgMB0ZpcmVuemUxEDAOBgNVBAcMB0ZpcmVuemUxDzANBgNVBAoMBklORElSRTEWMBQGA1UEAwwNd3d3LmluZGlyZS5pdDEgMB4GCSqGSIb3DQEJARYRYS5yb25jYUBpbmRpcmUuaXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCqaBl1EqGCPt5II53RjC4xmKEUCUMzEsJN6mkB97v1+qnPGaXAR3era6nwfT4SIZI6q8VrDgkqTiqtWsyK5wxnB7TM/SuOZZN8ULR2Ymd8yMw98FSotuPk7c8oSnPhot49wuNJENOB2xS40KsBY3bq39+vXEGrp9T6uJjQaCeoxryleLI5ORCKqraP36CTkp0aPGjTZw2dw7Sy1bL1vkzSOhs+Ud1EZhFogLeVh9O1NMSQ+MFjYiZOvXvictgQmqaOtPPDZR21/pXeTu8Ge30VyxHPXvcfhbmQR7JnDXVO+MTlVEXv2KZbeqi531Dg2zO2R5meB+WCYIhyWVoSuno3AgMBAAGjUDBOMB0GA1UdDgQWBBSTDV7yxd7KeIK/ok657XQfGUiRATAfBgNVHSMEGDAWgBSTDV7yxd7KeIK/ok657XQfGUiRATAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQAQaYfd76Lm6FUB6NwrvEAtSN3Z2eI06D3WwmSV6f7m2ZNdmivRenHIjQVu4qQmUC6dcWTVRN9dtVdWV+9Lao/rZeWhtw0kZqy0BXlOnrbsRIUlMdWiWERKdwaQWDOH2zxkJSN3YY6Z5VclPhHpJGxT/r7h3+/Dwi1xaOzZc3+m048jxV9GFwYSHu85+RnDA5Vj+ev7lxbgqeYpjkG2I1NaDHwuArmQdJ6hsy9jpAsBVv0pV7TagKpA9ljo0iJvUvT23vSayOwMElRLp8/7lzNHtF9naky4vL60B0cyvDR8WUxEx9P9a6RlhlsVE/WqqtyRwseC9QhrslsTk0re6fVp</ds:X509Certificate></ds:X509Data></ds:KeyInfo></ds:Signature> <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" AuthnRequestsSigned="true" WantAssertionsSigned="true"> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIDyzCCArOgAwIBAgIJAMz5Vos7s2saMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNVBAYTAklUMRAwDgYDVQQIDAdGaXJlbnplMRAwDgYDVQQHDAdGaXJlbnplMQ8wDQYDVQQKDAZJTkRJUkUxFjAUBgNVBAMMDXd3dy5pbmRpcmUuaXQxIDAeBgkqhkiG9w0BCQEWEWEucm9uY2FAaW5kaXJlLml0MB4XDTE3MDkyNzEzNTU1N1oXDTI3MDkyNzEzNTU1N1owfDELMAkGA1UEBhMCSVQxEDAOBgNVBAgMB0ZpcmVuemUxEDAOBgNVBAcMB0ZpcmVuemUxDzANBgNVBAoMBklORElSRTEWMBQGA1UEAwwNd3d3LmluZGlyZS5pdDEgMB4GCSqGSIb3DQEJARYRYS5yb25jYUBpbmRpcmUuaXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCqaBl1EqGCPt5II53RjC4xmKEUCUMzEsJN6mkB97v1+qnPGaXAR3era6nwfT4SIZI6q8VrDgkqTiqtWsyK5wxnB7TM/SuOZZN8ULR2Ymd8yMw98FSotuPk7c8oSnPhot49wuNJENOB2xS40KsBY3bq39+vXEGrp9T6uJjQaCeoxryleLI5ORCKqraP36CTkp0aPGjTZw2dw7Sy1bL1vkzSOhs+Ud1EZhFogLeVh9O1NMSQ+MFjYiZOvXvictgQmqaOtPPDZR21/pXeTu8Ge30VyxHPXvcfhbmQR7JnDXVO+MTlVEXv2KZbeqi531Dg2zO2R5meB+WCYIhyWVoSuno3AgMBAAGjUDBOMB0GA1UdDgQWBBSTDV7yxd7KeIK/ok657XQfGUiRATAfBgNVHSMEGDAWgBSTDV7yxd7KeIK/ok657XQfGUiRATAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQAQaYfd76Lm6FUB6NwrvEAtSN3Z2eI06D3WwmSV6f7m2ZNdmivRenHIjQVu4qQmUC6dcWTVRN9dtVdWV+9Lao/rZeWhtw0kZqy0BXlOnrbsRIUlMdWiWERKdwaQWDOH2zxkJSN3YY6Z5VclPhHpJGxT/r7h3+/Dwi1xaOzZc3+m048jxV9GFwYSHu85+RnDA5Vj+ev7lxbgqeYpjkG2I1NaDHwuArmQdJ6hsy9jpAsBVv0pV7TagKpA9ljo0iJvUvT23vSayOwMElRLp8/7lzNHtF9naky4vL60B0cyvDR8WUxEx9P9a6RlhlsVE/WqqtyRwseC9QhrslsTk0re6fVp</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIDyzCCArOgAwIBAgIJAMz5Vos7s2saMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNVBAYTAklUMRAwDgYDVQQIDAdGaXJlbnplMRAwDgYDVQQHDAdGaXJlbnplMQ8wDQYDVQQKDAZJTkRJUkUxFjAUBgNVBAMMDXd3dy5pbmRpcmUuaXQxIDAeBgkqhkiG9w0BCQEWEWEucm9uY2FAaW5kaXJlLml0MB4XDTE3MDkyNzEzNTU1N1oXDTI3MDkyNzEzNTU1N1owfDELMAkGA1UEBhMCSVQxEDAOBgNVBAgMB0ZpcmVuemUxEDAOBgNVBAcMB0ZpcmVuemUxDzANBgNVBAoMBklORElSRTEWMBQGA1UEAwwNd3d3LmluZGlyZS5pdDEgMB4GCSqGSIb3DQEJARYRYS5yb25jYUBpbmRpcmUuaXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCqaBl1EqGCPt5II53RjC4xmKEUCUMzEsJN6mkB97v1+qnPGaXAR3era6nwfT4SIZI6q8VrDgkqTiqtWsyK5wxnB7TM/SuOZZN8ULR2Ymd8yMw98FSotuPk7c8oSnPhot49wuNJENOB2xS40KsBY3bq39+vXEGrp9T6uJjQaCeoxryleLI5ORCKqraP36CTkp0aPGjTZw2dw7Sy1bL1vkzSOhs+Ud1EZhFogLeVh9O1NMSQ+MFjYiZOvXvictgQmqaOtPPDZR21/pXeTu8Ge30VyxHPXvcfhbmQR7JnDXVO+MTlVEXv2KZbeqi531Dg2zO2R5meB+WCYIhyWVoSuno3AgMBAAGjUDBOMB0GA1UdDgQWBBSTDV7yxd7KeIK/ok657XQfGUiRATAfBgNVHSMEGDAWgBSTDV7yxd7KeIK/ok657XQfGUiRATAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQAQaYfd76Lm6FUB6NwrvEAtSN3Z2eI06D3WwmSV6f7m2ZNdmivRenHIjQVu4qQmUC6dcWTVRN9dtVdWV+9Lao/rZeWhtw0kZqy0BXlOnrbsRIUlMdWiWERKdwaQWDOH2zxkJSN3YY6Z5VclPhHpJGxT/r7h3+/Dwi1xaOzZc3+m048jxV9GFwYSHu85+RnDA5Vj+ev7lxbgqeYpjkG2I1NaDHwuArmQdJ6hsy9jpAsBVv0pV7TagKpA9ljo0iJvUvT23vSayOwMElRLp8/7lzNHtF9naky4vL60B0cyvDR8WUxEx9P9a6RlhlsVE/WqqtyRwseC9QhrslsTk0re6fVp</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://spid.indire.it/sso/module.php/saml/sp/saml2-logout.php/spid"/> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://spid.indire.it/sso/module.php/saml/sp/saml2-acs.php/spid" index="0" isDefault="true"/> <md:AttributeConsumingService index="0"> <md:ServiceName xml:lang="it">Servizi indire</md:ServiceName> <md:RequestedAttribute Name="familyName" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"/> <md:RequestedAttribute Name="name" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"/> <md:RequestedAttribute Name="fiscalNumber" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"/> <md:RequestedAttribute Name="email" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"/> </md:AttributeConsumingService> </md:SPSSODescriptor> <md:Organization> <md:OrganizationName xml:lang="it">INDIRE</md:OrganizationName> <md:OrganizationDisplayName xml:lang="it">INDIRE</md:OrganizationDisplayName> <md:OrganizationURL xml:lang="it">http://www.indire.it/</md:OrganizationURL> </md:Organization> </md:EntityDescriptor>
In formato flat per SimpleSAMLphp - da utilizzare se dall'altra parte c'è un'entità che utilizza SimpleSAMLphp
$metadata['https://spid.indire.it/sso/module.php/saml/sp/metadata.php/spid'] = array ( 'SingleLogoutService' => array ( 0 => array ( 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST', 'Location' => 'https://spid.indire.it/sso/module.php/saml/sp/saml2-logout.php/spid', ), ), 'AssertionConsumerService' => array ( 0 => array ( 'index' => 0, 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST', 'Location' => 'https://spid.indire.it/sso/module.php/saml/sp/saml2-acs.php/spid', ), ), 'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient', 'name' => array ( 'it' => 'Servizi indire', ), 'attributes' => array ( 0 => 'familyName', 1 => 'name', 2 => 'fiscalNumber', 3 => 'email', ), 'attributes.NameFormat' => 'urn:oasis:names:tc:SAML:2.0:attrname-format:basic', 'OrganizationName' => array ( 'it' => 'INDIRE', ), 'OrganizationDisplayName' => array ( 'it' => 'INDIRE', ), 'OrganizationURL' => array ( 'it' => 'http://www.indire.it/', ), 'certData' => 'MIIDyzCCArOgAwIBAgIJAMz5Vos7s2saMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNVBAYTAklUMRAwDgYDVQQIDAdGaXJlbnplMRAwDgYDVQQHDAdGaXJlbnplMQ8wDQYDVQQKDAZJTkRJUkUxFjAUBgNVBAMMDXd3dy5pbmRpcmUuaXQxIDAeBgkqhkiG9w0BCQEWEWEucm9uY2FAaW5kaXJlLml0MB4XDTE3MDkyNzEzNTU1N1oXDTI3MDkyNzEzNTU1N1owfDELMAkGA1UEBhMCSVQxEDAOBgNVBAgMB0ZpcmVuemUxEDAOBgNVBAcMB0ZpcmVuemUxDzANBgNVBAoMBklORElSRTEWMBQGA1UEAwwNd3d3LmluZGlyZS5pdDEgMB4GCSqGSIb3DQEJARYRYS5yb25jYUBpbmRpcmUuaXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCqaBl1EqGCPt5II53RjC4xmKEUCUMzEsJN6mkB97v1+qnPGaXAR3era6nwfT4SIZI6q8VrDgkqTiqtWsyK5wxnB7TM/SuOZZN8ULR2Ymd8yMw98FSotuPk7c8oSnPhot49wuNJENOB2xS40KsBY3bq39+vXEGrp9T6uJjQaCeoxryleLI5ORCKqraP36CTkp0aPGjTZw2dw7Sy1bL1vkzSOhs+Ud1EZhFogLeVh9O1NMSQ+MFjYiZOvXvictgQmqaOtPPDZR21/pXeTu8Ge30VyxHPXvcfhbmQR7JnDXVO+MTlVEXv2KZbeqi531Dg2zO2R5meB+WCYIhyWVoSuno3AgMBAAGjUDBOMB0GA1UdDgQWBBSTDV7yxd7KeIK/ok657XQfGUiRATAfBgNVHSMEGDAWgBSTDV7yxd7KeIK/ok657XQfGUiRATAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQAQaYfd76Lm6FUB6NwrvEAtSN3Z2eI06D3WwmSV6f7m2ZNdmivRenHIjQVu4qQmUC6dcWTVRN9dtVdWV+9Lao/rZeWhtw0kZqy0BXlOnrbsRIUlMdWiWERKdwaQWDOH2zxkJSN3YY6Z5VclPhHpJGxT/r7h3+/Dwi1xaOzZc3+m048jxV9GFwYSHu85+RnDA5Vj+ev7lxbgqeYpjkG2I1NaDHwuArmQdJ6hsy9jpAsBVv0pV7TagKpA9ljo0iJvUvT23vSayOwMElRLp8/7lzNHtF9naky4vL60B0cyvDR8WUxEx9P9a6RlhlsVE/WqqtyRwseC9QhrslsTk0re6fVp', 'saml20.sign.assertion' => true, 'redirect.validate' => true, );