Identity Access Management for Research Communities Use the same credentials for all our services

SAML 2.0 IdP metaandmed

Need on SimpleSAMLphp poolt sulle genereeritud metaandmed. Võid saata need metaandmed usaldatavatele partneritele usaldatava föderatsiooni loomiseks.

Metaandmete XML-i on võimalik saada spetsiaalselt aadressilt:

https://idp.rocstar.tv/saml2/idp/metadata.php

Metaandmed

SAML 2.0 metaandmete XML-vormingus:

<?xml version="1.0"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://idp.rocstar.tv/saml2/idp/metadata.php">
  <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
    <md:KeyDescriptor use="signing">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:X509Data>
          <ds:X509Certificate>MIIBnDCCAQUCFEjuA9fYvC7yfOkqmLJ3EKf4c5W+MA0GCSqGSIb3DQEBCwUAMA0xCzAJBgNVBAYTAkFSMB4XDTIxMDMyOTE4MzA0NVoXDTI2MDMyODE4MzA0NVowDTELMAkGA1UEBhMCQVIwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAM1xRKTdeTrLJIZBaDu14MoQrhpI07s+bi2Y7f5WXHtiEW4mYdjvkR8peVdxdU3TbmYr0ERfXbrFd7EIGYCTJW1cGcmd9uGxJHjQzBJvzx4EPIjqeycZAhQzFQdPV0Zr9DaLkNVb/ukkuByB5wq2ikaVnBQjhNntdEQ0pIQst0GdAgMBAAEwDQYJKoZIhvcNAQELBQADgYEAXdyDzYVdTHWBMmEY0+M3/2bRaU8szsxgBEk17uKMENrs6He9bOKHaHDyyYiyPwlm6y39F/gBLC/bwuklTcj+BqnpHGcZCRTeOrKa9U5ju/kaVNlTYb0HZBWWT6nqpw/Jc7fZnuAjPSkPWIgCRFlzJ5TnBV+Yfk35USi4nSXt+UE=</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:KeyDescriptor use="encryption">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:X509Data>
          <ds:X509Certificate>MIIBnDCCAQUCFEjuA9fYvC7yfOkqmLJ3EKf4c5W+MA0GCSqGSIb3DQEBCwUAMA0xCzAJBgNVBAYTAkFSMB4XDTIxMDMyOTE4MzA0NVoXDTI2MDMyODE4MzA0NVowDTELMAkGA1UEBhMCQVIwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAM1xRKTdeTrLJIZBaDu14MoQrhpI07s+bi2Y7f5WXHtiEW4mYdjvkR8peVdxdU3TbmYr0ERfXbrFd7EIGYCTJW1cGcmd9uGxJHjQzBJvzx4EPIjqeycZAhQzFQdPV0Zr9DaLkNVb/ukkuByB5wq2ikaVnBQjhNntdEQ0pIQst0GdAgMBAAEwDQYJKoZIhvcNAQELBQADgYEAXdyDzYVdTHWBMmEY0+M3/2bRaU8szsxgBEk17uKMENrs6He9bOKHaHDyyYiyPwlm6y39F/gBLC/bwuklTcj+BqnpHGcZCRTeOrKa9U5ju/kaVNlTYb0HZBWWT6nqpw/Jc7fZnuAjPSkPWIgCRFlzJ5TnBV+Yfk35USi4nSXt+UE=</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.rocstar.tv/saml2/idp/SingleLogoutService.php"/>
    <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
    <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.rocstar.tv/saml2/idp/SSOService.php"/>
  </md:IDPSSODescriptor>
  <md:Organization>
    <md:OrganizationName xml:lang="en">Rocstar S.A.</md:OrganizationName>
    <md:OrganizationDisplayName xml:lang="en">Rocstar S.A.</md:OrganizationDisplayName>
    <md:OrganizationURL xml:lang="en">https://idp.rocstar.tv</md:OrganizationURL>
  </md:Organization>
  <md:ContactPerson contactType="technical">
    <md:GivenName>Administrator</md:GivenName>
    <md:EmailAddress>mailto:operaciones@rocstar.tv</md:EmailAddress>
  </md:ContactPerson>
</md:EntityDescriptor>

SimpleSAMLphp formaadis: kasuta seda siis, kui ka teine pool kasutab SimpleSAMLphp-d:

$metadata['https://idp.rocstar.tv/saml2/idp/metadata.php'] = [
    'metadata-set' => 'saml20-idp-remote',
    'entityid' => 'https://idp.rocstar.tv/saml2/idp/metadata.php',
    'SingleSignOnService' => [
        [
            'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
            'Location' => 'https://idp.rocstar.tv/saml2/idp/SSOService.php',
        ],
    ],
    'SingleLogoutService' => [
        [
            'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
            'Location' => 'https://idp.rocstar.tv/saml2/idp/SingleLogoutService.php',
        ],
    ],
    'certData' => 'MIIBnDCCAQUCFEjuA9fYvC7yfOkqmLJ3EKf4c5W+MA0GCSqGSIb3DQEBCwUAMA0xCzAJBgNVBAYTAkFSMB4XDTIxMDMyOTE4MzA0NVoXDTI2MDMyODE4MzA0NVowDTELMAkGA1UEBhMCQVIwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAM1xRKTdeTrLJIZBaDu14MoQrhpI07s+bi2Y7f5WXHtiEW4mYdjvkR8peVdxdU3TbmYr0ERfXbrFd7EIGYCTJW1cGcmd9uGxJHjQzBJvzx4EPIjqeycZAhQzFQdPV0Zr9DaLkNVb/ukkuByB5wq2ikaVnBQjhNntdEQ0pIQst0GdAgMBAAEwDQYJKoZIhvcNAQELBQADgYEAXdyDzYVdTHWBMmEY0+M3/2bRaU8szsxgBEk17uKMENrs6He9bOKHaHDyyYiyPwlm6y39F/gBLC/bwuklTcj+BqnpHGcZCRTeOrKa9U5ju/kaVNlTYb0HZBWWT6nqpw/Jc7fZnuAjPSkPWIgCRFlzJ5TnBV+Yfk35USi4nSXt+UE=',
    'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient',
    'OrganizationName' => [
        'en' => 'Rocstar S.A.',
    ],
    'OrganizationDisplayName' => [
        'en' => 'Rocstar S.A.',
    ],
    'OrganizationURL' => [
        'en' => 'https://idp.rocstar.tv',
    ],
    'contacts' => [
        [
            'emailAddress' => 'operaciones@rocstar.tv',
            'contactType' => 'technical',
            'givenName' => 'Administrator',
        ],
    ],
];

Sertifikaadid

Lae alla X509 sertifikaadid PEM kodeeringus failidena.