Here is the metadata that SimpleSAMLphp has generated for you. You may send this metadata document to trusted partners to setup a trusted federation.
You can get the metadata xml on a dedicated URL:
https://test-idp.geant.org/saml2/idp/metadata.php
In SAML 2.0 Metadata XML format:
<?xml version="1.0"?> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://test-idp.geant.org"> <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> <md:Extensions> <mdui:UIInfo xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui"> <mdui:DisplayName xml:lang="en">GEANT Staff Identity Provider (TEST)</mdui:DisplayName> <mdui:InformationURL xml:lang="en">https://www.geant.org</mdui:InformationURL> <mdui:PrivacyStatementURL xml:lang="en">https://www.geant.org/privacy-notice/Pages/GEANT-Privacy-Notice.aspx</mdui:PrivacyStatementURL> <mdui:Keywords xml:lang="en">geant</mdui:Keywords> <mdui:Keywords xml:lang="nl">geant</mdui:Keywords> <mdui:Logo width="700" height="324" xml:lang="en">https://idp.geant.org/module.php/geant/resources/fancytheme/GEANT_logo_lo_res.jpg</mdui:Logo> </mdui:UIInfo> </md:Extensions> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIID3zCCAsegAwIBAgIJAOh2jzA9wf+WMA0GCSqGSIb3DQEBBQUAMIGFMQswCQYDVQQGEwJOTDELMAkGA1UECAwCTkgxEjAQBgNVBAcMCUFtc3RlcmRhbTERMA8GA1UECgwIR8ODwolBTlQxDDAKBgNVBAsMA0FBSTEWMBQGA1UEAwwNaWRwLmdlYW50Lm9yZzEcMBoGCSqGSIb3DQEJARYNYWFpQGdlYW50Lm9yZzAeFw0xNTExMjYxNDU0NDFaFw0yNTExMjUxNDU0NDFaMIGFMQswCQYDVQQGEwJOTDELMAkGA1UECAwCTkgxEjAQBgNVBAcMCUFtc3RlcmRhbTERMA8GA1UECgwIR8ODwolBTlQxDDAKBgNVBAsMA0FBSTEWMBQGA1UEAwwNaWRwLmdlYW50Lm9yZzEcMBoGCSqGSIb3DQEJARYNYWFpQGdlYW50Lm9yZzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAPaqRXNsP291EDW4N+hWaxE4Z1ulwg74Zw5cAWwgR7NAnEJRTeqDsfCIg1sG1AoHXE5tItbt8awpnghdMasKuACKJQSjQKjKnvBZL7tF1o2zZ2slprPiIo5l+8ouq8UD3/W8ANQ8GRQxJ3cIw6NDsNi+EwGaSKgyTweJJ1Cq5WjZdSctmqri3Vm9ROXHVRsDBfkPcItXSlXQEahfbkoGFhlPlNaSQBFBlyVDkP7oxa/kBSBOi3UL8ahs5thQ9L1sXLG4De9k6xtMc0AcBqpO0WRjBeyIuyVj/yEcGywEvWZkrNvr95Oij+dej3eSpb5FLwa7P/RFnKfKnUkigNF6xssCAwEAAaNQME4wHQYDVR0OBBYEFLHjkP7OC+4nobQyrPHQH36b/lLiMB8GA1UdIwQYMBaAFLHjkP7OC+4nobQyrPHQH36b/lLiMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEFBQADggEBAJCNEVPa/FmMKmwAKtpJz0mHVWlr/0b+UHD+W6poNpqMSKWtBJHk3OVHUcZxlXA8VUu9HVr9cNWtf/qZXzDMf+wdLkSnhYruknKW+ZVlX7CM2awxuEPnNIUo86trzA3JHB4Tc3sYvVxO6Qj0wtPDf+zvmUmJ41M00oIwV3nvBLWj60RCe8EEScEND+v1lj9RSNrHCIaH5gQJYOrD5dUq0+4dQJpZxekOiMqR3KMxPzwdW978423NNzHgjICBhioQ9SKgJpsXUXrPxn1tLSXzOU27hVyjuSreYtkwT1iM4LnzQFIl1YD/+Ds7BUsV/tZ0KeXK0qfYezcNdD/axPzHZ+c=</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIID3zCCAsegAwIBAgIJAOh2jzA9wf+WMA0GCSqGSIb3DQEBBQUAMIGFMQswCQYDVQQGEwJOTDELMAkGA1UECAwCTkgxEjAQBgNVBAcMCUFtc3RlcmRhbTERMA8GA1UECgwIR8ODwolBTlQxDDAKBgNVBAsMA0FBSTEWMBQGA1UEAwwNaWRwLmdlYW50Lm9yZzEcMBoGCSqGSIb3DQEJARYNYWFpQGdlYW50Lm9yZzAeFw0xNTExMjYxNDU0NDFaFw0yNTExMjUxNDU0NDFaMIGFMQswCQYDVQQGEwJOTDELMAkGA1UECAwCTkgxEjAQBgNVBAcMCUFtc3RlcmRhbTERMA8GA1UECgwIR8ODwolBTlQxDDAKBgNVBAsMA0FBSTEWMBQGA1UEAwwNaWRwLmdlYW50Lm9yZzEcMBoGCSqGSIb3DQEJARYNYWFpQGdlYW50Lm9yZzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAPaqRXNsP291EDW4N+hWaxE4Z1ulwg74Zw5cAWwgR7NAnEJRTeqDsfCIg1sG1AoHXE5tItbt8awpnghdMasKuACKJQSjQKjKnvBZL7tF1o2zZ2slprPiIo5l+8ouq8UD3/W8ANQ8GRQxJ3cIw6NDsNi+EwGaSKgyTweJJ1Cq5WjZdSctmqri3Vm9ROXHVRsDBfkPcItXSlXQEahfbkoGFhlPlNaSQBFBlyVDkP7oxa/kBSBOi3UL8ahs5thQ9L1sXLG4De9k6xtMc0AcBqpO0WRjBeyIuyVj/yEcGywEvWZkrNvr95Oij+dej3eSpb5FLwa7P/RFnKfKnUkigNF6xssCAwEAAaNQME4wHQYDVR0OBBYEFLHjkP7OC+4nobQyrPHQH36b/lLiMB8GA1UdIwQYMBaAFLHjkP7OC+4nobQyrPHQH36b/lLiMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEFBQADggEBAJCNEVPa/FmMKmwAKtpJz0mHVWlr/0b+UHD+W6poNpqMSKWtBJHk3OVHUcZxlXA8VUu9HVr9cNWtf/qZXzDMf+wdLkSnhYruknKW+ZVlX7CM2awxuEPnNIUo86trzA3JHB4Tc3sYvVxO6Qj0wtPDf+zvmUmJ41M00oIwV3nvBLWj60RCe8EEScEND+v1lj9RSNrHCIaH5gQJYOrD5dUq0+4dQJpZxekOiMqR3KMxPzwdW978423NNzHgjICBhioQ9SKgJpsXUXrPxn1tLSXzOU27hVyjuSreYtkwT1iM4LnzQFIl1YD/+Ds7BUsV/tZ0KeXK0qfYezcNdD/axPzHZ+c=</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://test-idp.geant.org/saml2/idp/SingleLogoutService.php"/> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://test-idp.geant.org/saml2/idp/SSOService.php"/> </md:IDPSSODescriptor> <md:Organization> <md:OrganizationName xml:lang="en">GÉANT</md:OrganizationName> <md:OrganizationDisplayName xml:lang="en">GEANT Staff Identity Provider (TEST)</md:OrganizationDisplayName> <md:OrganizationURL xml:lang="en">https://www.geant.org</md:OrganizationURL> </md:Organization> <md:ContactPerson contactType="technical"> <md:GivenName>AAI</md:GivenName> <md:SurName>Admins</md:SurName> <md:EmailAddress>mailto:aai@geant.org</md:EmailAddress> </md:ContactPerson> </md:EntityDescriptor>
In SimpleSAMLphp flat file format - use this if you are using a SimpleSAMLphp entity on the other side:
$metadata['https://test-idp.geant.org'] = array ( 'metadata-set' => 'saml20-idp-remote', 'entityid' => 'https://test-idp.geant.org', 'SingleSignOnService' => array ( 0 => array ( 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://test-idp.geant.org/saml2/idp/SSOService.php', ), ), 'SingleLogoutService' => array ( 0 => array ( 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://test-idp.geant.org/saml2/idp/SingleLogoutService.php', ), ), 'certData' => 'MIID3zCCAsegAwIBAgIJAOh2jzA9wf+WMA0GCSqGSIb3DQEBBQUAMIGFMQswCQYDVQQGEwJOTDELMAkGA1UECAwCTkgxEjAQBgNVBAcMCUFtc3RlcmRhbTERMA8GA1UECgwIR8ODwolBTlQxDDAKBgNVBAsMA0FBSTEWMBQGA1UEAwwNaWRwLmdlYW50Lm9yZzEcMBoGCSqGSIb3DQEJARYNYWFpQGdlYW50Lm9yZzAeFw0xNTExMjYxNDU0NDFaFw0yNTExMjUxNDU0NDFaMIGFMQswCQYDVQQGEwJOTDELMAkGA1UECAwCTkgxEjAQBgNVBAcMCUFtc3RlcmRhbTERMA8GA1UECgwIR8ODwolBTlQxDDAKBgNVBAsMA0FBSTEWMBQGA1UEAwwNaWRwLmdlYW50Lm9yZzEcMBoGCSqGSIb3DQEJARYNYWFpQGdlYW50Lm9yZzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAPaqRXNsP291EDW4N+hWaxE4Z1ulwg74Zw5cAWwgR7NAnEJRTeqDsfCIg1sG1AoHXE5tItbt8awpnghdMasKuACKJQSjQKjKnvBZL7tF1o2zZ2slprPiIo5l+8ouq8UD3/W8ANQ8GRQxJ3cIw6NDsNi+EwGaSKgyTweJJ1Cq5WjZdSctmqri3Vm9ROXHVRsDBfkPcItXSlXQEahfbkoGFhlPlNaSQBFBlyVDkP7oxa/kBSBOi3UL8ahs5thQ9L1sXLG4De9k6xtMc0AcBqpO0WRjBeyIuyVj/yEcGywEvWZkrNvr95Oij+dej3eSpb5FLwa7P/RFnKfKnUkigNF6xssCAwEAAaNQME4wHQYDVR0OBBYEFLHjkP7OC+4nobQyrPHQH36b/lLiMB8GA1UdIwQYMBaAFLHjkP7OC+4nobQyrPHQH36b/lLiMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEFBQADggEBAJCNEVPa/FmMKmwAKtpJz0mHVWlr/0b+UHD+W6poNpqMSKWtBJHk3OVHUcZxlXA8VUu9HVr9cNWtf/qZXzDMf+wdLkSnhYruknKW+ZVlX7CM2awxuEPnNIUo86trzA3JHB4Tc3sYvVxO6Qj0wtPDf+zvmUmJ41M00oIwV3nvBLWj60RCe8EEScEND+v1lj9RSNrHCIaH5gQJYOrD5dUq0+4dQJpZxekOiMqR3KMxPzwdW978423NNzHgjICBhioQ9SKgJpsXUXrPxn1tLSXzOU27hVyjuSreYtkwT1iM4LnzQFIl1YD/+Ds7BUsV/tZ0KeXK0qfYezcNdD/axPzHZ+c=', 'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient', 'OrganizationName' => array ( 'en' => 'GÉANT', ), 'OrganizationDisplayName' => array ( 'en' => 'GEANT Staff Identity Provider (TEST)', ), 'OrganizationURL' => array ( 'en' => 'https://www.geant.org', ), 'UIInfo' => array ( 'DisplayName' => array ( 'en' => 'GEANT Staff Identity Provider (TEST)', ), 'InformationURL' => array ( 'en' => 'https://www.geant.org', ), 'Keywords' => array ( 'en' => array ( 0 => 'geant', ), 'nl' => array ( 0 => 'geant', ), ), 'PrivacyStatementURL' => array ( 'en' => 'https://www.geant.org/privacy-notice/Pages/GEANT-Privacy-Notice.aspx', ), 'Logo' => array ( 0 => array ( 'url' => 'https://idp.geant.org/module.php/geant/resources/fancytheme/GEANT_logo_lo_res.jpg', 'height' => 324, 'width' => 700, 'lang' => 'en', ), ), 'DiscoHints' => array ( 'IPHint' => array ( 0 => '195.169.24.0/24', 1 => '2001:610:9d8::/48', 2 => '62.40.101.0/24', 3 => '2001:799:cb2::/48', 4 => '62.40.99.129/32', 5 => '2001:798:4::/48', ), 'DomainHint' => array ( 0 => 'geant.org', ), 'GeolocationHint' => array ( 0 => 'geo:52.3672847,4.8891733', 1 => 'geo:52.1917609,0.1338814', ), ), ), 'contacts' => array ( 0 => array ( 'emailAddress' => 'aai@geant.org', 'contactType' => 'technical', 'givenName' => 'AAI', 'surName' => 'Admins', ), ), );
Download the X509 certificates as PEM-encoded files.
Copyright © 2007-2024 GÉANT