SAML 2.0 IdP 元信息
这里是SimpleSAMLphp为你生成的元信息,你应该发送这个元信息文档给你的信任的合作伙伴以建立信任的联盟
你可以在 获取元信息XML
https://box-idp.nordu.net/simplesaml/saml2/idp/metadata.php
元信息
在SAML 2.0 XML 元信息格式中:
<?xml version="1.0"?> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://box-idp.nordu.net/simplesaml/saml2/idp/metadata.php"> <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIEtDCCApwCCQC4IVr+uQQuQjANBgkqhkiG9w0BAQsFADAcMRowGAYDVQQDDBFib3gtaWRwLm5vcmR1Lm5ldDAeFw0yMzA0MTcwODEzMTZaFw0zMzA0MTQwODEzMTZaMBwxGjAYBgNVBAMMEWJveC1pZHAubm9yZHUubmV0MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAt4jNjYzRt6Ljqma3G+Z03rivSGGsVC1kYmMAE6/U+n6jLT9zL+m8L+Sc6hZYInA/STvrGCNCvk4KCveO3ZFbWjANicTwOxzsYxgGH8AddO+4KVmxfGjjkiOHZ1JuNUG8xQKMaL288kye7ueZQs7gvPT2P7J0TUcif7mgQfTjrsNvoNdCMRqHnYJUpxqdFpWNX9mDUJgxG+DeFkn4DuVE4UfSpkg3VCtq3TPRcr0+adrTC/0dtFd/ocw956ATOuUqXQtrSqWrIA1bFJePmWughAfGYob+W2tJe3PCsy2uiJewOsz/KkK/Di+fFsZXGL4NOwwFww2gglnbjmQbTGxgYTFtEWmHa5rN6NBR9+YQkdQvAaH21jgpB7fxNuUrzLX38WV/O3abYAv0ndJxgR72AR8rD/lI2dNVglNK+JLtSDrgsehhdJQYICyAOsg/+EKvB84V+f8g5MnHsDaq+ztiQYx1xF9K5qV0NgqRnDBoBsIWCPWnFU2Hujd9ua+6hCMp3QFXjb6PJXnWbXJR71+U0xHlwLUV+BDDzxm4XPn3VGCpWiH5WIf9gRdiwO4CUWjBHbHqrkJDfl4/qGzUFSdDSxoNvior82QfYLGj2UlDmey7GpFZatwWxGvyk226qComY0YRddD0WDEkjzKSiF0BIv1PAEyYWjaUyst4dfULUr8CAwEAATANBgkqhkiG9w0BAQsFAAOCAgEABC9jC22UPFbcwIOCSbBPfnbztm4rywbixbtoZzpwV2tb0XKSjtVMobuoKhQIO7rQ73VkqZWvM199msZ63TEQiKaFYZU5K4erFfh6e0FXh4N86CSGIeveXxOwJHKAzgOTHKWTuoSbJjMnzlTkqIs0xhWn39n11mz5YXxWwTWdz/+Om8aGt3IPSTpYhMgVSXMWBMf7qnWDkmT93hNQobWZRmINVsxuHLkePoi+/ATtBjsX1X8B7tZUYbSNrnWhVqqcuY8APmWDdCfcbDMrEkyhzQH6Rc/NKvE9jQRdj4FP2KTTNbUr2WNIzAFDi+Ob7zr8olaSBOgrdX+GGopsyUdJnaP7NYk9QUfsU9e7c4yPKi/JzNtRg1/XjRQrbsso+sQUz44T0SX79cupLBF0v4UI7Rxe47p7cDNDKr1uWiRowvv8rr1ulviclpMre94+HX6SiVtYNc1Kr6DznJX9Kw+rFKRgTK49NIt5XYW11X9JRbQHE70hDBR73kFDxzgs7DXyVDi9IqAteFxhluzrzj8AYFt6tfonH9HK0oYU7JRdwtwdMvBbsTTxN5H2gp4iED98u9nhk7XFMCTnJCSO+FrQ7ZS4udNP5vTHihiRBKiRcgah+zDpDdvXr7ltKiSZSZ4HkLOJnPG4sN3Pbp58yCqAerAvxW7UN5Wafbypb1DOrVI=</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIEtDCCApwCCQC4IVr+uQQuQjANBgkqhkiG9w0BAQsFADAcMRowGAYDVQQDDBFib3gtaWRwLm5vcmR1Lm5ldDAeFw0yMzA0MTcwODEzMTZaFw0zMzA0MTQwODEzMTZaMBwxGjAYBgNVBAMMEWJveC1pZHAubm9yZHUubmV0MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAt4jNjYzRt6Ljqma3G+Z03rivSGGsVC1kYmMAE6/U+n6jLT9zL+m8L+Sc6hZYInA/STvrGCNCvk4KCveO3ZFbWjANicTwOxzsYxgGH8AddO+4KVmxfGjjkiOHZ1JuNUG8xQKMaL288kye7ueZQs7gvPT2P7J0TUcif7mgQfTjrsNvoNdCMRqHnYJUpxqdFpWNX9mDUJgxG+DeFkn4DuVE4UfSpkg3VCtq3TPRcr0+adrTC/0dtFd/ocw956ATOuUqXQtrSqWrIA1bFJePmWughAfGYob+W2tJe3PCsy2uiJewOsz/KkK/Di+fFsZXGL4NOwwFww2gglnbjmQbTGxgYTFtEWmHa5rN6NBR9+YQkdQvAaH21jgpB7fxNuUrzLX38WV/O3abYAv0ndJxgR72AR8rD/lI2dNVglNK+JLtSDrgsehhdJQYICyAOsg/+EKvB84V+f8g5MnHsDaq+ztiQYx1xF9K5qV0NgqRnDBoBsIWCPWnFU2Hujd9ua+6hCMp3QFXjb6PJXnWbXJR71+U0xHlwLUV+BDDzxm4XPn3VGCpWiH5WIf9gRdiwO4CUWjBHbHqrkJDfl4/qGzUFSdDSxoNvior82QfYLGj2UlDmey7GpFZatwWxGvyk226qComY0YRddD0WDEkjzKSiF0BIv1PAEyYWjaUyst4dfULUr8CAwEAATANBgkqhkiG9w0BAQsFAAOCAgEABC9jC22UPFbcwIOCSbBPfnbztm4rywbixbtoZzpwV2tb0XKSjtVMobuoKhQIO7rQ73VkqZWvM199msZ63TEQiKaFYZU5K4erFfh6e0FXh4N86CSGIeveXxOwJHKAzgOTHKWTuoSbJjMnzlTkqIs0xhWn39n11mz5YXxWwTWdz/+Om8aGt3IPSTpYhMgVSXMWBMf7qnWDkmT93hNQobWZRmINVsxuHLkePoi+/ATtBjsX1X8B7tZUYbSNrnWhVqqcuY8APmWDdCfcbDMrEkyhzQH6Rc/NKvE9jQRdj4FP2KTTNbUr2WNIzAFDi+Ob7zr8olaSBOgrdX+GGopsyUdJnaP7NYk9QUfsU9e7c4yPKi/JzNtRg1/XjRQrbsso+sQUz44T0SX79cupLBF0v4UI7Rxe47p7cDNDKr1uWiRowvv8rr1ulviclpMre94+HX6SiVtYNc1Kr6DznJX9Kw+rFKRgTK49NIt5XYW11X9JRbQHE70hDBR73kFDxzgs7DXyVDi9IqAteFxhluzrzj8AYFt6tfonH9HK0oYU7JRdwtwdMvBbsTTxN5H2gp4iED98u9nhk7XFMCTnJCSO+FrQ7ZS4udNP5vTHihiRBKiRcgah+zDpDdvXr7ltKiSZSZ4HkLOJnPG4sN3Pbp58yCqAerAvxW7UN5Wafbypb1DOrVI=</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://box-idp.nordu.net/simplesaml/saml2/idp/SingleLogoutService.php"/> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://box-idp.nordu.net/simplesaml/saml2/idp/SSOService.php"/> </md:IDPSSODescriptor> <md:ContactPerson contactType="technical"> <md:GivenName>NORDUNet</md:GivenName> <md:SurName>NOC</md:SurName> <md:EmailAddress>mailto:noc@nordu.net</md:EmailAddress> </md:ContactPerson> </md:EntityDescriptor>
如果你想在其他网站使用的SimpleSAMLphp,那么你应该使用SimpleSAMLphp扁平的文件格式
$metadata['https://box-idp.nordu.net/simplesaml/saml2/idp/metadata.php'] = [ 'metadata-set' => 'saml20-idp-remote', 'entityid' => 'https://box-idp.nordu.net/simplesaml/saml2/idp/metadata.php', 'SingleSignOnService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://box-idp.nordu.net/simplesaml/saml2/idp/SSOService.php', ], ], 'SingleLogoutService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://box-idp.nordu.net/simplesaml/saml2/idp/SingleLogoutService.php', ], ], 'certData' => 'MIIEtDCCApwCCQC4IVr+uQQuQjANBgkqhkiG9w0BAQsFADAcMRowGAYDVQQDDBFib3gtaWRwLm5vcmR1Lm5ldDAeFw0yMzA0MTcwODEzMTZaFw0zMzA0MTQwODEzMTZaMBwxGjAYBgNVBAMMEWJveC1pZHAubm9yZHUubmV0MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAt4jNjYzRt6Ljqma3G+Z03rivSGGsVC1kYmMAE6/U+n6jLT9zL+m8L+Sc6hZYInA/STvrGCNCvk4KCveO3ZFbWjANicTwOxzsYxgGH8AddO+4KVmxfGjjkiOHZ1JuNUG8xQKMaL288kye7ueZQs7gvPT2P7J0TUcif7mgQfTjrsNvoNdCMRqHnYJUpxqdFpWNX9mDUJgxG+DeFkn4DuVE4UfSpkg3VCtq3TPRcr0+adrTC/0dtFd/ocw956ATOuUqXQtrSqWrIA1bFJePmWughAfGYob+W2tJe3PCsy2uiJewOsz/KkK/Di+fFsZXGL4NOwwFww2gglnbjmQbTGxgYTFtEWmHa5rN6NBR9+YQkdQvAaH21jgpB7fxNuUrzLX38WV/O3abYAv0ndJxgR72AR8rD/lI2dNVglNK+JLtSDrgsehhdJQYICyAOsg/+EKvB84V+f8g5MnHsDaq+ztiQYx1xF9K5qV0NgqRnDBoBsIWCPWnFU2Hujd9ua+6hCMp3QFXjb6PJXnWbXJR71+U0xHlwLUV+BDDzxm4XPn3VGCpWiH5WIf9gRdiwO4CUWjBHbHqrkJDfl4/qGzUFSdDSxoNvior82QfYLGj2UlDmey7GpFZatwWxGvyk226qComY0YRddD0WDEkjzKSiF0BIv1PAEyYWjaUyst4dfULUr8CAwEAATANBgkqhkiG9w0BAQsFAAOCAgEABC9jC22UPFbcwIOCSbBPfnbztm4rywbixbtoZzpwV2tb0XKSjtVMobuoKhQIO7rQ73VkqZWvM199msZ63TEQiKaFYZU5K4erFfh6e0FXh4N86CSGIeveXxOwJHKAzgOTHKWTuoSbJjMnzlTkqIs0xhWn39n11mz5YXxWwTWdz/+Om8aGt3IPSTpYhMgVSXMWBMf7qnWDkmT93hNQobWZRmINVsxuHLkePoi+/ATtBjsX1X8B7tZUYbSNrnWhVqqcuY8APmWDdCfcbDMrEkyhzQH6Rc/NKvE9jQRdj4FP2KTTNbUr2WNIzAFDi+Ob7zr8olaSBOgrdX+GGopsyUdJnaP7NYk9QUfsU9e7c4yPKi/JzNtRg1/XjRQrbsso+sQUz44T0SX79cupLBF0v4UI7Rxe47p7cDNDKr1uWiRowvv8rr1ulviclpMre94+HX6SiVtYNc1Kr6DznJX9Kw+rFKRgTK49NIt5XYW11X9JRbQHE70hDBR73kFDxzgs7DXyVDi9IqAteFxhluzrzj8AYFt6tfonH9HK0oYU7JRdwtwdMvBbsTTxN5H2gp4iED98u9nhk7XFMCTnJCSO+FrQ7ZS4udNP5vTHihiRBKiRcgah+zDpDdvXr7ltKiSZSZ4HkLOJnPG4sN3Pbp58yCqAerAvxW7UN5Wafbypb1DOrVI=', 'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient', 'contacts' => [ [ 'emailAddress' => 'noc@nordu.net', 'contactType' => 'technical', 'givenName' => 'NORDUNet', 'surName' => 'NOC', ], ], ];
证书
下载X509证书作为PEM编码的文件