Metadatos IdP SAML 2.0
Aquí están los metadatos que SimpleSAMLphp ha generado. Puede enviar este documento de metadatos a sus socios de confianza para configurar una federación.
Puede obtener una URL con los metadatos xml:
https://www.cnic.es/sir2/saml2/idp/metadata.php
Metadatos
En formato xml de metadatos SAML 2.0:
<?xml version="1.0"?> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="idp-www.cnic.es"> <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIDKjCCApOgAwIBAgIJAPvQVm09aDrrMA0GCSqGSIb3DQEBCwUAMIGtMRMwEQYKCZImiZPyLGQBGRYDd3d3MRQwEgYKCZImiZPyLGQBGRYEY25pYzESMBAGCgmSJomT8ixkARkWAmVzMTwwOgYDVQQKDDNDRU5UUk8gTkFDSU9OQUwgREUgSU5WRVNUSUdBQ0lPTkVTIENBUkRJT1ZBU0NVTEFSRVMxGDAWBgNVBAsMD0NlcnRpZmljYWRvIFNQVDEUMBIGA1UEAwwLd3d3LmNuaWMuZXMwHhcNMTYwNjE1MTMyMDU2WhcNMjYwNjE1MTMyMDU2WjCBrTETMBEGCgmSJomT8ixkARkWA3d3dzEUMBIGCgmSJomT8ixkARkWBGNuaWMxEjAQBgoJkiaJk/IsZAEZFgJlczE8MDoGA1UECgwzQ0VOVFJPIE5BQ0lPTkFMIERFIElOVkVTVElHQUNJT05FUyBDQVJESU9WQVNDVUxBUkVTMRgwFgYDVQQLDA9DZXJ0aWZpY2FkbyBTUFQxFDASBgNVBAMMC3d3dy5jbmljLmVzMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCmOvMMjCIOlBz17TVx/nmZHBkwT2zbPfA2N8JqjC/L7pIGG4tGPPkqFB2+kHH4rXBpfRW/SzVH/vtB/pF6HPtNDq1y0AmlUjZ8J2NVRpvXLS0VOSnoOUfbiyypSbHiO3p0aqSxw+T13zdHb6LapYniWMz1rG5fvWavMuxWjkpm6wIDAQABo1AwTjAdBgNVHQ4EFgQU1h07MQ/hCDA7gZIP6vPYUOqdaGMwHwYDVR0jBBgwFoAU1h07MQ/hCDA7gZIP6vPYUOqdaGMwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQsFAAOBgQAJcisxG7vpm5aYPPcgv1Q7b54R+XRndYSgMoPnGbSUJcKb1u759LjBOsiOUVW5zNBJsX67i9Mhjyl3Nygt3LzETcc+p472B5FwV6wKRWyxnnIXTAgV1+gqWQ90UO/w6jh8QMByN7DUhJ3pTAbPg12B3jwElf4ydvG/UDSMq3h/jA==</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIDKjCCApOgAwIBAgIJAPvQVm09aDrrMA0GCSqGSIb3DQEBCwUAMIGtMRMwEQYKCZImiZPyLGQBGRYDd3d3MRQwEgYKCZImiZPyLGQBGRYEY25pYzESMBAGCgmSJomT8ixkARkWAmVzMTwwOgYDVQQKDDNDRU5UUk8gTkFDSU9OQUwgREUgSU5WRVNUSUdBQ0lPTkVTIENBUkRJT1ZBU0NVTEFSRVMxGDAWBgNVBAsMD0NlcnRpZmljYWRvIFNQVDEUMBIGA1UEAwwLd3d3LmNuaWMuZXMwHhcNMTYwNjE1MTMyMDU2WhcNMjYwNjE1MTMyMDU2WjCBrTETMBEGCgmSJomT8ixkARkWA3d3dzEUMBIGCgmSJomT8ixkARkWBGNuaWMxEjAQBgoJkiaJk/IsZAEZFgJlczE8MDoGA1UECgwzQ0VOVFJPIE5BQ0lPTkFMIERFIElOVkVTVElHQUNJT05FUyBDQVJESU9WQVNDVUxBUkVTMRgwFgYDVQQLDA9DZXJ0aWZpY2FkbyBTUFQxFDASBgNVBAMMC3d3dy5jbmljLmVzMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCmOvMMjCIOlBz17TVx/nmZHBkwT2zbPfA2N8JqjC/L7pIGG4tGPPkqFB2+kHH4rXBpfRW/SzVH/vtB/pF6HPtNDq1y0AmlUjZ8J2NVRpvXLS0VOSnoOUfbiyypSbHiO3p0aqSxw+T13zdHb6LapYniWMz1rG5fvWavMuxWjkpm6wIDAQABo1AwTjAdBgNVHQ4EFgQU1h07MQ/hCDA7gZIP6vPYUOqdaGMwHwYDVR0jBBgwFoAU1h07MQ/hCDA7gZIP6vPYUOqdaGMwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQsFAAOBgQAJcisxG7vpm5aYPPcgv1Q7b54R+XRndYSgMoPnGbSUJcKb1u759LjBOsiOUVW5zNBJsX67i9Mhjyl3Nygt3LzETcc+p472B5FwV6wKRWyxnnIXTAgV1+gqWQ90UO/w6jh8QMByN7DUhJ3pTAbPg12B3jwElf4ydvG/UDSMq3h/jA==</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://www.cnic.es/sir2/saml2/idp/SingleLogoutService.php"/> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://www.cnic.es/sir2/saml2/idp/SSOService.php"/> </md:IDPSSODescriptor> <md:ContactPerson contactType="technical"> <md:GivenName>Administrator</md:GivenName> <md:EmailAddress>mailto:administradores@cnic.es</md:EmailAddress> </md:ContactPerson> </md:EntityDescriptor>
En un fichero de formato SimpleSAMLphp - utilice esta opción si está usando una entidad SimpleSAMLphp en el otro extremo:
$metadata['idp-www.cnic.es'] = [ 'metadata-set' => 'saml20-idp-remote', 'entityid' => 'idp-www.cnic.es', 'SingleSignOnService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://www.cnic.es/sir2/saml2/idp/SSOService.php', ], ], 'SingleLogoutService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://www.cnic.es/sir2/saml2/idp/SingleLogoutService.php', ], ], 'certData' => 'MIIDKjCCApOgAwIBAgIJAPvQVm09aDrrMA0GCSqGSIb3DQEBCwUAMIGtMRMwEQYKCZImiZPyLGQBGRYDd3d3MRQwEgYKCZImiZPyLGQBGRYEY25pYzESMBAGCgmSJomT8ixkARkWAmVzMTwwOgYDVQQKDDNDRU5UUk8gTkFDSU9OQUwgREUgSU5WRVNUSUdBQ0lPTkVTIENBUkRJT1ZBU0NVTEFSRVMxGDAWBgNVBAsMD0NlcnRpZmljYWRvIFNQVDEUMBIGA1UEAwwLd3d3LmNuaWMuZXMwHhcNMTYwNjE1MTMyMDU2WhcNMjYwNjE1MTMyMDU2WjCBrTETMBEGCgmSJomT8ixkARkWA3d3dzEUMBIGCgmSJomT8ixkARkWBGNuaWMxEjAQBgoJkiaJk/IsZAEZFgJlczE8MDoGA1UECgwzQ0VOVFJPIE5BQ0lPTkFMIERFIElOVkVTVElHQUNJT05FUyBDQVJESU9WQVNDVUxBUkVTMRgwFgYDVQQLDA9DZXJ0aWZpY2FkbyBTUFQxFDASBgNVBAMMC3d3dy5jbmljLmVzMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCmOvMMjCIOlBz17TVx/nmZHBkwT2zbPfA2N8JqjC/L7pIGG4tGPPkqFB2+kHH4rXBpfRW/SzVH/vtB/pF6HPtNDq1y0AmlUjZ8J2NVRpvXLS0VOSnoOUfbiyypSbHiO3p0aqSxw+T13zdHb6LapYniWMz1rG5fvWavMuxWjkpm6wIDAQABo1AwTjAdBgNVHQ4EFgQU1h07MQ/hCDA7gZIP6vPYUOqdaGMwHwYDVR0jBBgwFoAU1h07MQ/hCDA7gZIP6vPYUOqdaGMwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQsFAAOBgQAJcisxG7vpm5aYPPcgv1Q7b54R+XRndYSgMoPnGbSUJcKb1u759LjBOsiOUVW5zNBJsX67i9Mhjyl3Nygt3LzETcc+p472B5FwV6wKRWyxnnIXTAgV1+gqWQ90UO/w6jh8QMByN7DUhJ3pTAbPg12B3jwElf4ydvG/UDSMq3h/jA==', 'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient', 'contacts' => [ [ 'emailAddress' => 'administradores@cnic.es', 'contactType' => 'technical', 'givenName' => 'Administrator', ], ], ];
Certificados
Descargar los certificados X509 en formato PEM.