Metadati SAML 2.0 IdP
Questi sono i metadati che SimpleSAMLphp ha generato e che possono essere inviati ai partner fidati per creare una federazione tra siti.
Si possono ottenere i metadati in XML dall'URL dedicata:
https://spid.indire.it/sso/saml2/idp/metadata.php
Metadati
Metadati SAML 2.0 in formato XML:
<?xml version="1.0"?> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://spid.indire.it/sso/saml2/idp/metadata.php"> <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIDyzCCArOgAwIBAgIJAMz5Vos7s2saMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNVBAYTAklUMRAwDgYDVQQIDAdGaXJlbnplMRAwDgYDVQQHDAdGaXJlbnplMQ8wDQYDVQQKDAZJTkRJUkUxFjAUBgNVBAMMDXd3dy5pbmRpcmUuaXQxIDAeBgkqhkiG9w0BCQEWEWEucm9uY2FAaW5kaXJlLml0MB4XDTE3MDkyNzEzNTU1N1oXDTI3MDkyNzEzNTU1N1owfDELMAkGA1UEBhMCSVQxEDAOBgNVBAgMB0ZpcmVuemUxEDAOBgNVBAcMB0ZpcmVuemUxDzANBgNVBAoMBklORElSRTEWMBQGA1UEAwwNd3d3LmluZGlyZS5pdDEgMB4GCSqGSIb3DQEJARYRYS5yb25jYUBpbmRpcmUuaXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCqaBl1EqGCPt5II53RjC4xmKEUCUMzEsJN6mkB97v1+qnPGaXAR3era6nwfT4SIZI6q8VrDgkqTiqtWsyK5wxnB7TM/SuOZZN8ULR2Ymd8yMw98FSotuPk7c8oSnPhot49wuNJENOB2xS40KsBY3bq39+vXEGrp9T6uJjQaCeoxryleLI5ORCKqraP36CTkp0aPGjTZw2dw7Sy1bL1vkzSOhs+Ud1EZhFogLeVh9O1NMSQ+MFjYiZOvXvictgQmqaOtPPDZR21/pXeTu8Ge30VyxHPXvcfhbmQR7JnDXVO+MTlVEXv2KZbeqi531Dg2zO2R5meB+WCYIhyWVoSuno3AgMBAAGjUDBOMB0GA1UdDgQWBBSTDV7yxd7KeIK/ok657XQfGUiRATAfBgNVHSMEGDAWgBSTDV7yxd7KeIK/ok657XQfGUiRATAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQAQaYfd76Lm6FUB6NwrvEAtSN3Z2eI06D3WwmSV6f7m2ZNdmivRenHIjQVu4qQmUC6dcWTVRN9dtVdWV+9Lao/rZeWhtw0kZqy0BXlOnrbsRIUlMdWiWERKdwaQWDOH2zxkJSN3YY6Z5VclPhHpJGxT/r7h3+/Dwi1xaOzZc3+m048jxV9GFwYSHu85+RnDA5Vj+ev7lxbgqeYpjkG2I1NaDHwuArmQdJ6hsy9jpAsBVv0pV7TagKpA9ljo0iJvUvT23vSayOwMElRLp8/7lzNHtF9naky4vL60B0cyvDR8WUxEx9P9a6RlhlsVE/WqqtyRwseC9QhrslsTk0re6fVp</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIDyzCCArOgAwIBAgIJAMz5Vos7s2saMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNVBAYTAklUMRAwDgYDVQQIDAdGaXJlbnplMRAwDgYDVQQHDAdGaXJlbnplMQ8wDQYDVQQKDAZJTkRJUkUxFjAUBgNVBAMMDXd3dy5pbmRpcmUuaXQxIDAeBgkqhkiG9w0BCQEWEWEucm9uY2FAaW5kaXJlLml0MB4XDTE3MDkyNzEzNTU1N1oXDTI3MDkyNzEzNTU1N1owfDELMAkGA1UEBhMCSVQxEDAOBgNVBAgMB0ZpcmVuemUxEDAOBgNVBAcMB0ZpcmVuemUxDzANBgNVBAoMBklORElSRTEWMBQGA1UEAwwNd3d3LmluZGlyZS5pdDEgMB4GCSqGSIb3DQEJARYRYS5yb25jYUBpbmRpcmUuaXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCqaBl1EqGCPt5II53RjC4xmKEUCUMzEsJN6mkB97v1+qnPGaXAR3era6nwfT4SIZI6q8VrDgkqTiqtWsyK5wxnB7TM/SuOZZN8ULR2Ymd8yMw98FSotuPk7c8oSnPhot49wuNJENOB2xS40KsBY3bq39+vXEGrp9T6uJjQaCeoxryleLI5ORCKqraP36CTkp0aPGjTZw2dw7Sy1bL1vkzSOhs+Ud1EZhFogLeVh9O1NMSQ+MFjYiZOvXvictgQmqaOtPPDZR21/pXeTu8Ge30VyxHPXvcfhbmQR7JnDXVO+MTlVEXv2KZbeqi531Dg2zO2R5meB+WCYIhyWVoSuno3AgMBAAGjUDBOMB0GA1UdDgQWBBSTDV7yxd7KeIK/ok657XQfGUiRATAfBgNVHSMEGDAWgBSTDV7yxd7KeIK/ok657XQfGUiRATAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQAQaYfd76Lm6FUB6NwrvEAtSN3Z2eI06D3WwmSV6f7m2ZNdmivRenHIjQVu4qQmUC6dcWTVRN9dtVdWV+9Lao/rZeWhtw0kZqy0BXlOnrbsRIUlMdWiWERKdwaQWDOH2zxkJSN3YY6Z5VclPhHpJGxT/r7h3+/Dwi1xaOzZc3+m048jxV9GFwYSHu85+RnDA5Vj+ev7lxbgqeYpjkG2I1NaDHwuArmQdJ6hsy9jpAsBVv0pV7TagKpA9ljo0iJvUvT23vSayOwMElRLp8/7lzNHtF9naky4vL60B0cyvDR8WUxEx9P9a6RlhlsVE/WqqtyRwseC9QhrslsTk0re6fVp</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://spid.indire.it/sso/saml2/idp/SingleLogoutService.php"/> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://spid.indire.it/sso/saml2/idp/SSOService.php"/> </md:IDPSSODescriptor> </md:EntityDescriptor>
In formato flat per SimpleSAMLphp - da utilizzare se dall'altra parte c'è un'entità che utilizza SimpleSAMLphp
$metadata['https://spid.indire.it/sso/saml2/idp/metadata.php'] = array ( 'metadata-set' => 'saml20-idp-remote', 'entityid' => 'https://spid.indire.it/sso/saml2/idp/metadata.php', 'SingleSignOnService' => array ( 0 => array ( 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://spid.indire.it/sso/saml2/idp/SSOService.php', ), ), 'SingleLogoutService' => array ( 0 => array ( 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://spid.indire.it/sso/saml2/idp/SingleLogoutService.php', ), ), 'certData' => 'MIIDyzCCArOgAwIBAgIJAMz5Vos7s2saMA0GCSqGSIb3DQEBCwUAMHwxCzAJBgNVBAYTAklUMRAwDgYDVQQIDAdGaXJlbnplMRAwDgYDVQQHDAdGaXJlbnplMQ8wDQYDVQQKDAZJTkRJUkUxFjAUBgNVBAMMDXd3dy5pbmRpcmUuaXQxIDAeBgkqhkiG9w0BCQEWEWEucm9uY2FAaW5kaXJlLml0MB4XDTE3MDkyNzEzNTU1N1oXDTI3MDkyNzEzNTU1N1owfDELMAkGA1UEBhMCSVQxEDAOBgNVBAgMB0ZpcmVuemUxEDAOBgNVBAcMB0ZpcmVuemUxDzANBgNVBAoMBklORElSRTEWMBQGA1UEAwwNd3d3LmluZGlyZS5pdDEgMB4GCSqGSIb3DQEJARYRYS5yb25jYUBpbmRpcmUuaXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCqaBl1EqGCPt5II53RjC4xmKEUCUMzEsJN6mkB97v1+qnPGaXAR3era6nwfT4SIZI6q8VrDgkqTiqtWsyK5wxnB7TM/SuOZZN8ULR2Ymd8yMw98FSotuPk7c8oSnPhot49wuNJENOB2xS40KsBY3bq39+vXEGrp9T6uJjQaCeoxryleLI5ORCKqraP36CTkp0aPGjTZw2dw7Sy1bL1vkzSOhs+Ud1EZhFogLeVh9O1NMSQ+MFjYiZOvXvictgQmqaOtPPDZR21/pXeTu8Ge30VyxHPXvcfhbmQR7JnDXVO+MTlVEXv2KZbeqi531Dg2zO2R5meB+WCYIhyWVoSuno3AgMBAAGjUDBOMB0GA1UdDgQWBBSTDV7yxd7KeIK/ok657XQfGUiRATAfBgNVHSMEGDAWgBSTDV7yxd7KeIK/ok657XQfGUiRATAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQAQaYfd76Lm6FUB6NwrvEAtSN3Z2eI06D3WwmSV6f7m2ZNdmivRenHIjQVu4qQmUC6dcWTVRN9dtVdWV+9Lao/rZeWhtw0kZqy0BXlOnrbsRIUlMdWiWERKdwaQWDOH2zxkJSN3YY6Z5VclPhHpJGxT/r7h3+/Dwi1xaOzZc3+m048jxV9GFwYSHu85+RnDA5Vj+ev7lxbgqeYpjkG2I1NaDHwuArmQdJ6hsy9jpAsBVv0pV7TagKpA9ljo0iJvUvT23vSayOwMElRLp8/7lzNHtF9naky4vL60B0cyvDR8WUxEx9P9a6RlhlsVE/WqqtyRwseC9QhrslsTk0re6fVp', 'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient', );
Certificati
Scarica i certificati X509 come file PEM-encoded