Staff Identity Provider

SAML 2.0 IdP Metadata

Here is the metadata that SimpleSAMLphp has generated for you. You may send this metadata document to trusted partners to setup a trusted federation.

You can get the metadata xml on a dedicated URL:

https://test-idp.geant.org/saml2/idp/metadata.php

Metadata

In SAML 2.0 Metadata XML format:

<?xml version="1.0"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://test-idp.geant.org">
  <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
    <md:Extensions>
      <mdui:UIInfo xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui">
        <mdui:DisplayName xml:lang="en">GEANT Staff Identity Provider (TEST)</mdui:DisplayName>
        <mdui:InformationURL xml:lang="en">https://www.geant.org</mdui:InformationURL>
        <mdui:PrivacyStatementURL xml:lang="en">https://www.geant.org/privacy-notice/Pages/GEANT-Privacy-Notice.aspx</mdui:PrivacyStatementURL>
        <mdui:Keywords xml:lang="en">geant</mdui:Keywords>
        <mdui:Keywords xml:lang="nl">geant</mdui:Keywords>
        <mdui:Logo width="700" height="324" xml:lang="en">https://idp.geant.org/module.php/geant/resources/fancytheme/GEANT_logo_lo_res.jpg</mdui:Logo>
      </mdui:UIInfo>
    </md:Extensions>
    <md:KeyDescriptor use="signing">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:X509Data>
          <ds:X509Certificate>MIID3zCCAsegAwIBAgIJAOh2jzA9wf+WMA0GCSqGSIb3DQEBBQUAMIGFMQswCQYDVQQGEwJOTDELMAkGA1UECAwCTkgxEjAQBgNVBAcMCUFtc3RlcmRhbTERMA8GA1UECgwIR8ODwolBTlQxDDAKBgNVBAsMA0FBSTEWMBQGA1UEAwwNaWRwLmdlYW50Lm9yZzEcMBoGCSqGSIb3DQEJARYNYWFpQGdlYW50Lm9yZzAeFw0xNTExMjYxNDU0NDFaFw0yNTExMjUxNDU0NDFaMIGFMQswCQYDVQQGEwJOTDELMAkGA1UECAwCTkgxEjAQBgNVBAcMCUFtc3RlcmRhbTERMA8GA1UECgwIR8ODwolBTlQxDDAKBgNVBAsMA0FBSTEWMBQGA1UEAwwNaWRwLmdlYW50Lm9yZzEcMBoGCSqGSIb3DQEJARYNYWFpQGdlYW50Lm9yZzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAPaqRXNsP291EDW4N+hWaxE4Z1ulwg74Zw5cAWwgR7NAnEJRTeqDsfCIg1sG1AoHXE5tItbt8awpnghdMasKuACKJQSjQKjKnvBZL7tF1o2zZ2slprPiIo5l+8ouq8UD3/W8ANQ8GRQxJ3cIw6NDsNi+EwGaSKgyTweJJ1Cq5WjZdSctmqri3Vm9ROXHVRsDBfkPcItXSlXQEahfbkoGFhlPlNaSQBFBlyVDkP7oxa/kBSBOi3UL8ahs5thQ9L1sXLG4De9k6xtMc0AcBqpO0WRjBeyIuyVj/yEcGywEvWZkrNvr95Oij+dej3eSpb5FLwa7P/RFnKfKnUkigNF6xssCAwEAAaNQME4wHQYDVR0OBBYEFLHjkP7OC+4nobQyrPHQH36b/lLiMB8GA1UdIwQYMBaAFLHjkP7OC+4nobQyrPHQH36b/lLiMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEFBQADggEBAJCNEVPa/FmMKmwAKtpJz0mHVWlr/0b+UHD+W6poNpqMSKWtBJHk3OVHUcZxlXA8VUu9HVr9cNWtf/qZXzDMf+wdLkSnhYruknKW+ZVlX7CM2awxuEPnNIUo86trzA3JHB4Tc3sYvVxO6Qj0wtPDf+zvmUmJ41M00oIwV3nvBLWj60RCe8EEScEND+v1lj9RSNrHCIaH5gQJYOrD5dUq0+4dQJpZxekOiMqR3KMxPzwdW978423NNzHgjICBhioQ9SKgJpsXUXrPxn1tLSXzOU27hVyjuSreYtkwT1iM4LnzQFIl1YD/+Ds7BUsV/tZ0KeXK0qfYezcNdD/axPzHZ+c=</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:KeyDescriptor use="encryption">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:X509Data>
          <ds:X509Certificate>MIID3zCCAsegAwIBAgIJAOh2jzA9wf+WMA0GCSqGSIb3DQEBBQUAMIGFMQswCQYDVQQGEwJOTDELMAkGA1UECAwCTkgxEjAQBgNVBAcMCUFtc3RlcmRhbTERMA8GA1UECgwIR8ODwolBTlQxDDAKBgNVBAsMA0FBSTEWMBQGA1UEAwwNaWRwLmdlYW50Lm9yZzEcMBoGCSqGSIb3DQEJARYNYWFpQGdlYW50Lm9yZzAeFw0xNTExMjYxNDU0NDFaFw0yNTExMjUxNDU0NDFaMIGFMQswCQYDVQQGEwJOTDELMAkGA1UECAwCTkgxEjAQBgNVBAcMCUFtc3RlcmRhbTERMA8GA1UECgwIR8ODwolBTlQxDDAKBgNVBAsMA0FBSTEWMBQGA1UEAwwNaWRwLmdlYW50Lm9yZzEcMBoGCSqGSIb3DQEJARYNYWFpQGdlYW50Lm9yZzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAPaqRXNsP291EDW4N+hWaxE4Z1ulwg74Zw5cAWwgR7NAnEJRTeqDsfCIg1sG1AoHXE5tItbt8awpnghdMasKuACKJQSjQKjKnvBZL7tF1o2zZ2slprPiIo5l+8ouq8UD3/W8ANQ8GRQxJ3cIw6NDsNi+EwGaSKgyTweJJ1Cq5WjZdSctmqri3Vm9ROXHVRsDBfkPcItXSlXQEahfbkoGFhlPlNaSQBFBlyVDkP7oxa/kBSBOi3UL8ahs5thQ9L1sXLG4De9k6xtMc0AcBqpO0WRjBeyIuyVj/yEcGywEvWZkrNvr95Oij+dej3eSpb5FLwa7P/RFnKfKnUkigNF6xssCAwEAAaNQME4wHQYDVR0OBBYEFLHjkP7OC+4nobQyrPHQH36b/lLiMB8GA1UdIwQYMBaAFLHjkP7OC+4nobQyrPHQH36b/lLiMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEFBQADggEBAJCNEVPa/FmMKmwAKtpJz0mHVWlr/0b+UHD+W6poNpqMSKWtBJHk3OVHUcZxlXA8VUu9HVr9cNWtf/qZXzDMf+wdLkSnhYruknKW+ZVlX7CM2awxuEPnNIUo86trzA3JHB4Tc3sYvVxO6Qj0wtPDf+zvmUmJ41M00oIwV3nvBLWj60RCe8EEScEND+v1lj9RSNrHCIaH5gQJYOrD5dUq0+4dQJpZxekOiMqR3KMxPzwdW978423NNzHgjICBhioQ9SKgJpsXUXrPxn1tLSXzOU27hVyjuSreYtkwT1iM4LnzQFIl1YD/+Ds7BUsV/tZ0KeXK0qfYezcNdD/axPzHZ+c=</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://test-idp.geant.org/saml2/idp/SingleLogoutService.php"/>
    <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
    <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://test-idp.geant.org/saml2/idp/SSOService.php"/>
  </md:IDPSSODescriptor>
  <md:Organization>
    <md:OrganizationName xml:lang="en">G&#xC9;ANT</md:OrganizationName>
    <md:OrganizationDisplayName xml:lang="en">GEANT Staff Identity Provider (TEST)</md:OrganizationDisplayName>
    <md:OrganizationURL xml:lang="en">https://www.geant.org</md:OrganizationURL>
  </md:Organization>
  <md:ContactPerson contactType="technical">
    <md:GivenName>AAI</md:GivenName>
    <md:SurName>Admins</md:SurName>
    <md:EmailAddress>mailto:aai@geant.org</md:EmailAddress>
  </md:ContactPerson>
</md:EntityDescriptor>

In SimpleSAMLphp flat file format - use this if you are using a SimpleSAMLphp entity on the other side:

$metadata['https://test-idp.geant.org'] = array (
  'metadata-set' => 'saml20-idp-remote',
  'entityid' => 'https://test-idp.geant.org',
  'SingleSignOnService' => 
  array (
    0 => 
    array (
      'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
      'Location' => 'https://test-idp.geant.org/saml2/idp/SSOService.php',
    ),
  ),
  'SingleLogoutService' => 
  array (
    0 => 
    array (
      'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
      'Location' => 'https://test-idp.geant.org/saml2/idp/SingleLogoutService.php',
    ),
  ),
  'certData' => 'MIID3zCCAsegAwIBAgIJAOh2jzA9wf+WMA0GCSqGSIb3DQEBBQUAMIGFMQswCQYDVQQGEwJOTDELMAkGA1UECAwCTkgxEjAQBgNVBAcMCUFtc3RlcmRhbTERMA8GA1UECgwIR8ODwolBTlQxDDAKBgNVBAsMA0FBSTEWMBQGA1UEAwwNaWRwLmdlYW50Lm9yZzEcMBoGCSqGSIb3DQEJARYNYWFpQGdlYW50Lm9yZzAeFw0xNTExMjYxNDU0NDFaFw0yNTExMjUxNDU0NDFaMIGFMQswCQYDVQQGEwJOTDELMAkGA1UECAwCTkgxEjAQBgNVBAcMCUFtc3RlcmRhbTERMA8GA1UECgwIR8ODwolBTlQxDDAKBgNVBAsMA0FBSTEWMBQGA1UEAwwNaWRwLmdlYW50Lm9yZzEcMBoGCSqGSIb3DQEJARYNYWFpQGdlYW50Lm9yZzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAPaqRXNsP291EDW4N+hWaxE4Z1ulwg74Zw5cAWwgR7NAnEJRTeqDsfCIg1sG1AoHXE5tItbt8awpnghdMasKuACKJQSjQKjKnvBZL7tF1o2zZ2slprPiIo5l+8ouq8UD3/W8ANQ8GRQxJ3cIw6NDsNi+EwGaSKgyTweJJ1Cq5WjZdSctmqri3Vm9ROXHVRsDBfkPcItXSlXQEahfbkoGFhlPlNaSQBFBlyVDkP7oxa/kBSBOi3UL8ahs5thQ9L1sXLG4De9k6xtMc0AcBqpO0WRjBeyIuyVj/yEcGywEvWZkrNvr95Oij+dej3eSpb5FLwa7P/RFnKfKnUkigNF6xssCAwEAAaNQME4wHQYDVR0OBBYEFLHjkP7OC+4nobQyrPHQH36b/lLiMB8GA1UdIwQYMBaAFLHjkP7OC+4nobQyrPHQH36b/lLiMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEFBQADggEBAJCNEVPa/FmMKmwAKtpJz0mHVWlr/0b+UHD+W6poNpqMSKWtBJHk3OVHUcZxlXA8VUu9HVr9cNWtf/qZXzDMf+wdLkSnhYruknKW+ZVlX7CM2awxuEPnNIUo86trzA3JHB4Tc3sYvVxO6Qj0wtPDf+zvmUmJ41M00oIwV3nvBLWj60RCe8EEScEND+v1lj9RSNrHCIaH5gQJYOrD5dUq0+4dQJpZxekOiMqR3KMxPzwdW978423NNzHgjICBhioQ9SKgJpsXUXrPxn1tLSXzOU27hVyjuSreYtkwT1iM4LnzQFIl1YD/+Ds7BUsV/tZ0KeXK0qfYezcNdD/axPzHZ+c=',
  'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient',
  'OrganizationName' => 
  array (
    'en' => 'GÉANT',
  ),
  'OrganizationDisplayName' => 
  array (
    'en' => 'GEANT Staff Identity Provider (TEST)',
  ),
  'OrganizationURL' => 
  array (
    'en' => 'https://www.geant.org',
  ),
  'UIInfo' => 
  array (
    'DisplayName' => 
    array (
      'en' => 'GEANT Staff Identity Provider (TEST)',
    ),
    'InformationURL' => 
    array (
      'en' => 'https://www.geant.org',
    ),
    'Keywords' => 
    array (
      'en' => 
      array (
        0 => 'geant',
      ),
      'nl' => 
      array (
        0 => 'geant',
      ),
    ),
    'PrivacyStatementURL' => 
    array (
      'en' => 'https://www.geant.org/privacy-notice/Pages/GEANT-Privacy-Notice.aspx',
    ),
    'Logo' => 
    array (
      0 => 
      array (
        'url' => 'https://idp.geant.org/module.php/geant/resources/fancytheme/GEANT_logo_lo_res.jpg',
        'height' => 324,
        'width' => 700,
        'lang' => 'en',
      ),
    ),
    'DiscoHints' => 
    array (
      'IPHint' => 
      array (
        0 => '195.169.24.0/24',
        1 => '2001:610:9d8::/48',
        2 => '62.40.101.0/24',
        3 => '2001:799:cb2::/48',
        4 => '62.40.99.129/32',
        5 => '2001:798:4::/48',
      ),
      'DomainHint' => 
      array (
        0 => 'geant.org',
      ),
      'GeolocationHint' => 
      array (
        0 => 'geo:52.3672847,4.8891733',
        1 => 'geo:52.1917609,0.1338814',
      ),
    ),
  ),
  'contacts' => 
  array (
    0 => 
    array (
      'emailAddress' => 'aai@geant.org',
      'contactType' => 'technical',
      'givenName' => 'AAI',
      'surName' => 'Admins',
    ),
  ),
);

Certificates

Download the X509 certificates as PEM-encoded files.