English | Nederlands

SAML 2.0 IdP Metadata

Here is the metadata that SimpleSAMLphp has generated for you. You may send this metadata document to trusted partners to setup a trusted federation.

You can get the metadata xml on a dedicated URL:

https://pieter.aai.surfnet.nl/simplesamlphp/saml2/idp/metadata.php

Metadata

In SAML 2.0 Metadata XML format:

<?xml version="1.0"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://pieter.aai.surfnet.nl/simplesamlphp/saml2/idp/metadata.php">
  <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" WantAuthnRequestsSigned="false">
    <md:KeyDescriptor use="signing">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:X509Data>
          <ds:X509Certificate>MIIDljCCAn4CCQCf5qiSFFL8GTANBgkqhkiG9w0BAQUFADCBjDELMAkGA1UEBhMCTkwxEDAOBgNVBAgMB1V0cmVjaHQxEDAOBgNVBAcMB1V0cmVjaHQxEzARBgNVBAoMClNVUkZuZXQgYnYxIjAgBgNVBAMMGXBpZXRlci5hYWkuc3VyZm5ldC5ubCBJZFAxIDAeBgkqhkiG9w0BCQEWEXBpZXRlckBzdXJmbmV0Lm5sMB4XDTE0MDIxODIxMjY0OFoXDTI0MDIxNjIxMjY0OFowgYwxCzAJBgNVBAYTAk5MMRAwDgYDVQQIDAdVdHJlY2h0MRAwDgYDVQQHDAdVdHJlY2h0MRMwEQYDVQQKDApTVVJGbmV0IGJ2MSIwIAYDVQQDDBlwaWV0ZXIuYWFpLnN1cmZuZXQubmwgSWRQMSAwHgYJKoZIhvcNAQkBFhFwaWV0ZXJAc3VyZm5ldC5ubDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALAlPPLgPQ96Q4H2zjxnUtjfP8sc48p3euo7nt7DMqF5LvpRemRFUV1wmsFJ/7o8aGiN7eNxlhjM9uOkdj17UBy/jzCuGFbYoroe3FmVBdX0foJNxltu5JtYJF81HYnYZyIMSGyzrT9vxwHf3oM3YgIaWpjVKO+2Ud/pwEeTIEY/R0CHe/VM4KejHV570cvMosmVjMqQhMePR8obMkDDGS9JkGDtN7q7x9T3EF8sZXdXe84B11NqinHtxXF+QdXnTeZmD85cr7wtkAxDB7iBYoD+/HFsiw9sGxHMs+B4tX+mcyfQAt8Xzw+w9uSWi85u6xXiRXeZmvsycoy6CyuB5McCAwEAATANBgkqhkiG9w0BAQUFAAOCAQEArbt4ooNReiSCp00BdWiooOz8cNdDAdx2iW2+gRdUev+xSPJ86I3l/51xt52XcJtEmGEZA6BVm/nHTMg1uWYGvioWsIeThqR7doKlY7Np7o6ASjxCb/GQhVQczwxcxpKoXyfR9yP28backHzTaaxxFCEjnKcGA+NGAdzUz12g+05o620mklmSmuO+dhos3AyLb9qnSpdmJTi5fyJbdZLEph0jM1zJLLVyT0wsN1kWjQq0hB1MpVYwESFWAv4ZdqWWcaOBW36bouEQ+tKpvpaeMvzzT5Nb8SGX07eiOWspt3rJNAQ8K404QL2VSWk/iG3dkvaDyESa0SjcD50L37VOXQ==</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:KeyDescriptor use="encryption">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:X509Data>
          <ds:X509Certificate>MIIDljCCAn4CCQCf5qiSFFL8GTANBgkqhkiG9w0BAQUFADCBjDELMAkGA1UEBhMCTkwxEDAOBgNVBAgMB1V0cmVjaHQxEDAOBgNVBAcMB1V0cmVjaHQxEzARBgNVBAoMClNVUkZuZXQgYnYxIjAgBgNVBAMMGXBpZXRlci5hYWkuc3VyZm5ldC5ubCBJZFAxIDAeBgkqhkiG9w0BCQEWEXBpZXRlckBzdXJmbmV0Lm5sMB4XDTE0MDIxODIxMjY0OFoXDTI0MDIxNjIxMjY0OFowgYwxCzAJBgNVBAYTAk5MMRAwDgYDVQQIDAdVdHJlY2h0MRAwDgYDVQQHDAdVdHJlY2h0MRMwEQYDVQQKDApTVVJGbmV0IGJ2MSIwIAYDVQQDDBlwaWV0ZXIuYWFpLnN1cmZuZXQubmwgSWRQMSAwHgYJKoZIhvcNAQkBFhFwaWV0ZXJAc3VyZm5ldC5ubDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALAlPPLgPQ96Q4H2zjxnUtjfP8sc48p3euo7nt7DMqF5LvpRemRFUV1wmsFJ/7o8aGiN7eNxlhjM9uOkdj17UBy/jzCuGFbYoroe3FmVBdX0foJNxltu5JtYJF81HYnYZyIMSGyzrT9vxwHf3oM3YgIaWpjVKO+2Ud/pwEeTIEY/R0CHe/VM4KejHV570cvMosmVjMqQhMePR8obMkDDGS9JkGDtN7q7x9T3EF8sZXdXe84B11NqinHtxXF+QdXnTeZmD85cr7wtkAxDB7iBYoD+/HFsiw9sGxHMs+B4tX+mcyfQAt8Xzw+w9uSWi85u6xXiRXeZmvsycoy6CyuB5McCAwEAATANBgkqhkiG9w0BAQUFAAOCAQEArbt4ooNReiSCp00BdWiooOz8cNdDAdx2iW2+gRdUev+xSPJ86I3l/51xt52XcJtEmGEZA6BVm/nHTMg1uWYGvioWsIeThqR7doKlY7Np7o6ASjxCb/GQhVQczwxcxpKoXyfR9yP28backHzTaaxxFCEjnKcGA+NGAdzUz12g+05o620mklmSmuO+dhos3AyLb9qnSpdmJTi5fyJbdZLEph0jM1zJLLVyT0wsN1kWjQq0hB1MpVYwESFWAv4ZdqWWcaOBW36bouEQ+tKpvpaeMvzzT5Nb8SGX07eiOWspt3rJNAQ8K404QL2VSWk/iG3dkvaDyESa0SjcD50L37VOXQ==</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://pieter.aai.surfnet.nl/simplesamlphp/saml2/idp/ArtifactResolutionService.php" index="0"/>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://pieter.aai.surfnet.nl/simplesamlphp/saml2/idp/SingleLogoutService.php"/>
    <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
    <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://pieter.aai.surfnet.nl/simplesamlphp/saml2/idp/SSOService.php"/>
  </md:IDPSSODescriptor>
  <md:ContactPerson contactType="technical">
    <md:GivenName>Pieter van der Meulen</md:GivenName>
    <md:EmailAddress>pieter@surfnet.nl</md:EmailAddress>
  </md:ContactPerson>
</md:EntityDescriptor>

In SimpleSAMLphp flat file format - use this if you are using a SimpleSAMLphp entity on the other side:

$metadata['https://pieter.aai.surfnet.nl/simplesamlphp/saml2/idp/metadata.php'] = array (
  'metadata-set' => 'saml20-idp-remote',
  'entityid' => 'https://pieter.aai.surfnet.nl/simplesamlphp/saml2/idp/metadata.php',
  'SingleSignOnService' => 
  array (
    0 => 
    array (
      'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
      'Location' => 'https://pieter.aai.surfnet.nl/simplesamlphp/saml2/idp/SSOService.php',
    ),
  ),
  'SingleLogoutService' => 
  array (
    0 => 
    array (
      'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
      'Location' => 'https://pieter.aai.surfnet.nl/simplesamlphp/saml2/idp/SingleLogoutService.php',
    ),
  ),
  'certData' => 'MIIDljCCAn4CCQCf5qiSFFL8GTANBgkqhkiG9w0BAQUFADCBjDELMAkGA1UEBhMCTkwxEDAOBgNVBAgMB1V0cmVjaHQxEDAOBgNVBAcMB1V0cmVjaHQxEzARBgNVBAoMClNVUkZuZXQgYnYxIjAgBgNVBAMMGXBpZXRlci5hYWkuc3VyZm5ldC5ubCBJZFAxIDAeBgkqhkiG9w0BCQEWEXBpZXRlckBzdXJmbmV0Lm5sMB4XDTE0MDIxODIxMjY0OFoXDTI0MDIxNjIxMjY0OFowgYwxCzAJBgNVBAYTAk5MMRAwDgYDVQQIDAdVdHJlY2h0MRAwDgYDVQQHDAdVdHJlY2h0MRMwEQYDVQQKDApTVVJGbmV0IGJ2MSIwIAYDVQQDDBlwaWV0ZXIuYWFpLnN1cmZuZXQubmwgSWRQMSAwHgYJKoZIhvcNAQkBFhFwaWV0ZXJAc3VyZm5ldC5ubDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALAlPPLgPQ96Q4H2zjxnUtjfP8sc48p3euo7nt7DMqF5LvpRemRFUV1wmsFJ/7o8aGiN7eNxlhjM9uOkdj17UBy/jzCuGFbYoroe3FmVBdX0foJNxltu5JtYJF81HYnYZyIMSGyzrT9vxwHf3oM3YgIaWpjVKO+2Ud/pwEeTIEY/R0CHe/VM4KejHV570cvMosmVjMqQhMePR8obMkDDGS9JkGDtN7q7x9T3EF8sZXdXe84B11NqinHtxXF+QdXnTeZmD85cr7wtkAxDB7iBYoD+/HFsiw9sGxHMs+B4tX+mcyfQAt8Xzw+w9uSWi85u6xXiRXeZmvsycoy6CyuB5McCAwEAATANBgkqhkiG9w0BAQUFAAOCAQEArbt4ooNReiSCp00BdWiooOz8cNdDAdx2iW2+gRdUev+xSPJ86I3l/51xt52XcJtEmGEZA6BVm/nHTMg1uWYGvioWsIeThqR7doKlY7Np7o6ASjxCb/GQhVQczwxcxpKoXyfR9yP28backHzTaaxxFCEjnKcGA+NGAdzUz12g+05o620mklmSmuO+dhos3AyLb9qnSpdmJTi5fyJbdZLEph0jM1zJLLVyT0wsN1kWjQq0hB1MpVYwESFWAv4ZdqWWcaOBW36bouEQ+tKpvpaeMvzzT5Nb8SGX07eiOWspt3rJNAQ8K404QL2VSWk/iG3dkvaDyESa0SjcD50L37VOXQ==',
  'ArtifactResolutionService' => 
  array (
    0 => 
    array (
      'index' => 0,
      'Location' => 'https://pieter.aai.surfnet.nl/simplesamlphp/saml2/idp/ArtifactResolutionService.php',
      'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:SOAP',
    ),
  ),
  'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient',
  'redirect.sign' => false,
  'contacts' => 
  array (
    0 => 
    array (
      'emailAddress' => 'pieter@surfnet.nl',
      'contactType' => 'technical',
      'givenName' => 'Pieter van der Meulen',
    ),
  ),
);

Certificates

Download the X509 certificates as PEM-encoded files.