SAML 2.0 IdP 元信息
这里是SimpleSAMLphp为你生成的元信息,你应该发送这个元信息文档给你的信任的合作伙伴以建立信任的联盟
你可以在 获取元信息XML
http://cusg-identity.net/saml2/idp/metadata.php
元信息
在SAML 2.0 XML 元信息格式中:
<?xml version="1.0"?> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="http://cusg-identity.net/saml2/idp/metadata.php"> <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIEizCCAvOgAwIBAgIJAL8433hgH5kJMA0GCSqGSIb3DQEBBQUAMFwxCzAJBgNVBAYTAlVTMQswCQYDVQQIDAJNSTEVMBMGA1UEBwwMRGVmYXVsdCBDaXR5MQ0wCwYDVQQKDARDVVNHMRowGAYDVQQDDBFjdXNnLWlkZW50aXR5Lm5ldDAeFw0yMDA2MDQyMDM4MDFaFw0zMDA2MDQyMDM4MDFaMFwxCzAJBgNVBAYTAlVTMQswCQYDVQQIDAJNSTEVMBMGA1UEBwwMRGVmYXVsdCBDaXR5MQ0wCwYDVQQKDARDVVNHMRowGAYDVQQDDBFjdXNnLWlkZW50aXR5Lm5ldDCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBALVuwnMtQGXCZg7CeEkO7x/aH0cA5xH9+X9blwgI3jpWI5rQEQCY/e6Vc5/qPSoW3hKlwWoMO7UEFfwGPqBxei5g5Tj3S3Nu3EPKHYaDb0KwKxAMRpaIQlK10IRRVbD6wfBOc8nlSK1L2YQCfue+ZXJUlldl7Xg4ECS4bbc9yha94iAKMfGMbYYAhsNF6j2eU5ljyASSBYML27K5rDeiWuVq/FtTM1FWVCW7FjNQ5RkA+hzGmmRXsoWteX+XRU8aS+4t0XOVz8Mbo6jiZ4wfwMB6j9Igyxi0w2i42SC46lc7LnqoVpS7HZAzAYXVfcDuTVHEIk/oDMkhaBqHe/oqXgxe0NuKI9BYrXbXMuypLhY1qGwzwXmJ12zU0vscgUI1FqAJLhMJ29M5ggDzCnI5liuGC5yhH5kK409zPzAwbRMWFqxiYuRO+SmlsHH1qOT/YCj4YmifdyvKWxuGxZrN8JmD+l44tc+Pw6LwlrkVd1aimeKQpYybs8kbBli3bz8meQIDAQABo1AwTjAdBgNVHQ4EFgQU5A7PL4dqiNOQXf31A9LvO3ckEc4wHwYDVR0jBBgwFoAU5A7PL4dqiNOQXf31A9LvO3ckEc4wDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQUFAAOCAYEAHz/NY2f0zkSo7v1XuYHKTMbTGXdlxyRaQeVFW+TvBHzuCBkijHhgW3mBLoMQBwFVcGM4nz0j7Xdpi+z2mlJpoz1uJVEUPANj5jYB/IZCOLVGS/guFX+3kuza24z9gebtyKotmjmFkJfxrlwK4/DNuFa1PHryKo16sSOG8QooabhqRUrdFPsWwyJrbf7kRz6MN2qCa1ECdPOyTguZ24QE3jGL74cHuN72hTnXEKUMlPla5s9Fczp8hM+eJmSdu7R9WbkMkPIkwGnyJJBP1Aeujt8VLiEwgDfwdPKQgmt1heftPjbT+qp9vtMOuA0wkwG/M/D/Mqd3hoKi3q/ihnkqpT+cDvgo8Q0j1XU2Pv51NeTbUVlFErhmf/A62MfuZRGhnkXhYWrIOP54x24oLg4B6+vZCChSYEwua9lrfTjTwcLxem75DXkH7KCramsOz85BloAOe2Mbvz9MJZ4S4ZtVQQXS+ly25wAWRqXS8TkQt7z4/xw+34FnTmOsuQR1LhOJ</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIEizCCAvOgAwIBAgIJAL8433hgH5kJMA0GCSqGSIb3DQEBBQUAMFwxCzAJBgNVBAYTAlVTMQswCQYDVQQIDAJNSTEVMBMGA1UEBwwMRGVmYXVsdCBDaXR5MQ0wCwYDVQQKDARDVVNHMRowGAYDVQQDDBFjdXNnLWlkZW50aXR5Lm5ldDAeFw0yMDA2MDQyMDM4MDFaFw0zMDA2MDQyMDM4MDFaMFwxCzAJBgNVBAYTAlVTMQswCQYDVQQIDAJNSTEVMBMGA1UEBwwMRGVmYXVsdCBDaXR5MQ0wCwYDVQQKDARDVVNHMRowGAYDVQQDDBFjdXNnLWlkZW50aXR5Lm5ldDCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBALVuwnMtQGXCZg7CeEkO7x/aH0cA5xH9+X9blwgI3jpWI5rQEQCY/e6Vc5/qPSoW3hKlwWoMO7UEFfwGPqBxei5g5Tj3S3Nu3EPKHYaDb0KwKxAMRpaIQlK10IRRVbD6wfBOc8nlSK1L2YQCfue+ZXJUlldl7Xg4ECS4bbc9yha94iAKMfGMbYYAhsNF6j2eU5ljyASSBYML27K5rDeiWuVq/FtTM1FWVCW7FjNQ5RkA+hzGmmRXsoWteX+XRU8aS+4t0XOVz8Mbo6jiZ4wfwMB6j9Igyxi0w2i42SC46lc7LnqoVpS7HZAzAYXVfcDuTVHEIk/oDMkhaBqHe/oqXgxe0NuKI9BYrXbXMuypLhY1qGwzwXmJ12zU0vscgUI1FqAJLhMJ29M5ggDzCnI5liuGC5yhH5kK409zPzAwbRMWFqxiYuRO+SmlsHH1qOT/YCj4YmifdyvKWxuGxZrN8JmD+l44tc+Pw6LwlrkVd1aimeKQpYybs8kbBli3bz8meQIDAQABo1AwTjAdBgNVHQ4EFgQU5A7PL4dqiNOQXf31A9LvO3ckEc4wHwYDVR0jBBgwFoAU5A7PL4dqiNOQXf31A9LvO3ckEc4wDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQUFAAOCAYEAHz/NY2f0zkSo7v1XuYHKTMbTGXdlxyRaQeVFW+TvBHzuCBkijHhgW3mBLoMQBwFVcGM4nz0j7Xdpi+z2mlJpoz1uJVEUPANj5jYB/IZCOLVGS/guFX+3kuza24z9gebtyKotmjmFkJfxrlwK4/DNuFa1PHryKo16sSOG8QooabhqRUrdFPsWwyJrbf7kRz6MN2qCa1ECdPOyTguZ24QE3jGL74cHuN72hTnXEKUMlPla5s9Fczp8hM+eJmSdu7R9WbkMkPIkwGnyJJBP1Aeujt8VLiEwgDfwdPKQgmt1heftPjbT+qp9vtMOuA0wkwG/M/D/Mqd3hoKi3q/ihnkqpT+cDvgo8Q0j1XU2Pv51NeTbUVlFErhmf/A62MfuZRGhnkXhYWrIOP54x24oLg4B6+vZCChSYEwua9lrfTjTwcLxem75DXkH7KCramsOz85BloAOe2Mbvz9MJZ4S4ZtVQQXS+ly25wAWRqXS8TkQt7z4/xw+34FnTmOsuQR1LhOJ</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="http://cusg-identity.net/saml2/idp/SingleLogoutService.php"/> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="http://cusg-identity.net/saml2/idp/SSOService.php"/> </md:IDPSSODescriptor> <md:ContactPerson contactType="technical"> <md:GivenName>Administrator</md:GivenName> <md:EmailAddress>jej@mcul.org</md:EmailAddress> </md:ContactPerson> </md:EntityDescriptor>
如果你想在其他网站使用的SimpleSAMLphp,那么你应该使用SimpleSAMLphp扁平的文件格式
$metadata['http://cusg-identity.net/saml2/idp/metadata.php'] = array ( 'metadata-set' => 'saml20-idp-remote', 'entityid' => 'http://cusg-identity.net/saml2/idp/metadata.php', 'SingleSignOnService' => array ( 0 => array ( 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'http://cusg-identity.net/saml2/idp/SSOService.php', ), ), 'SingleLogoutService' => array ( 0 => array ( 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'http://cusg-identity.net/saml2/idp/SingleLogoutService.php', ), ), 'certData' => 'MIIEizCCAvOgAwIBAgIJAL8433hgH5kJMA0GCSqGSIb3DQEBBQUAMFwxCzAJBgNVBAYTAlVTMQswCQYDVQQIDAJNSTEVMBMGA1UEBwwMRGVmYXVsdCBDaXR5MQ0wCwYDVQQKDARDVVNHMRowGAYDVQQDDBFjdXNnLWlkZW50aXR5Lm5ldDAeFw0yMDA2MDQyMDM4MDFaFw0zMDA2MDQyMDM4MDFaMFwxCzAJBgNVBAYTAlVTMQswCQYDVQQIDAJNSTEVMBMGA1UEBwwMRGVmYXVsdCBDaXR5MQ0wCwYDVQQKDARDVVNHMRowGAYDVQQDDBFjdXNnLWlkZW50aXR5Lm5ldDCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBALVuwnMtQGXCZg7CeEkO7x/aH0cA5xH9+X9blwgI3jpWI5rQEQCY/e6Vc5/qPSoW3hKlwWoMO7UEFfwGPqBxei5g5Tj3S3Nu3EPKHYaDb0KwKxAMRpaIQlK10IRRVbD6wfBOc8nlSK1L2YQCfue+ZXJUlldl7Xg4ECS4bbc9yha94iAKMfGMbYYAhsNF6j2eU5ljyASSBYML27K5rDeiWuVq/FtTM1FWVCW7FjNQ5RkA+hzGmmRXsoWteX+XRU8aS+4t0XOVz8Mbo6jiZ4wfwMB6j9Igyxi0w2i42SC46lc7LnqoVpS7HZAzAYXVfcDuTVHEIk/oDMkhaBqHe/oqXgxe0NuKI9BYrXbXMuypLhY1qGwzwXmJ12zU0vscgUI1FqAJLhMJ29M5ggDzCnI5liuGC5yhH5kK409zPzAwbRMWFqxiYuRO+SmlsHH1qOT/YCj4YmifdyvKWxuGxZrN8JmD+l44tc+Pw6LwlrkVd1aimeKQpYybs8kbBli3bz8meQIDAQABo1AwTjAdBgNVHQ4EFgQU5A7PL4dqiNOQXf31A9LvO3ckEc4wHwYDVR0jBBgwFoAU5A7PL4dqiNOQXf31A9LvO3ckEc4wDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQUFAAOCAYEAHz/NY2f0zkSo7v1XuYHKTMbTGXdlxyRaQeVFW+TvBHzuCBkijHhgW3mBLoMQBwFVcGM4nz0j7Xdpi+z2mlJpoz1uJVEUPANj5jYB/IZCOLVGS/guFX+3kuza24z9gebtyKotmjmFkJfxrlwK4/DNuFa1PHryKo16sSOG8QooabhqRUrdFPsWwyJrbf7kRz6MN2qCa1ECdPOyTguZ24QE3jGL74cHuN72hTnXEKUMlPla5s9Fczp8hM+eJmSdu7R9WbkMkPIkwGnyJJBP1Aeujt8VLiEwgDfwdPKQgmt1heftPjbT+qp9vtMOuA0wkwG/M/D/Mqd3hoKi3q/ihnkqpT+cDvgo8Q0j1XU2Pv51NeTbUVlFErhmf/A62MfuZRGhnkXhYWrIOP54x24oLg4B6+vZCChSYEwua9lrfTjTwcLxem75DXkH7KCramsOz85BloAOe2Mbvz9MJZ4S4ZtVQQXS+ly25wAWRqXS8TkQt7z4/xw+34FnTmOsuQR1LhOJ', 'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient', 'contacts' => array ( 0 => array ( 'emailAddress' => 'jej@mcul.org', 'contactType' => 'technical', 'givenName' => 'Administrator', ), ), );
证书
下载X509证书作为PEM编码的文件