SAML 2.0 IdP Metadata
Here is the metadata that SimpleSAMLphp has generated for you. You may send this metadata document to trusted partners to setup a trusted federation.
You can get the metadata xml on a dedicated URL:
http://3.112.103.94/simplesaml/saml2/idp/metadata.php
Metadata
In SAML 2.0 Metadata XML format:
<?xml version="1.0" encoding="UTF-8"?> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="http://3.112.103.94/simplesaml/saml2/idp/metadata.php"> <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIC6jCCAdICCQDLPAZFV85ZJTANBgkqhkiG9w0BAQsFADA3MQswCQYDVQQGEwJKUDEOMAwGA1UECAwFVE9LWU8xGDAWBgNVBAMMD2lkcC5leGFtcGxlLmNvbTAeFw0yMjA5MDgwMzA5MjVaFw0zMjA5MDcwMzA5MjVaMDcxCzAJBgNVBAYTAkpQMQ4wDAYDVQQIDAVUT0tZTzEYMBYGA1UEAwwPaWRwLmV4YW1wbGUuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3vHTqlfTb8q58nicgrSHdgPdOXSUgxXos7zkHf2B0PEU0RgisAma9x76UjVsHwHJ2ZP5vGhlRl1fzXp0n11rpcbZtJwL/kE2ITwrC5IQ0IaCHm2ws338WTSIbMX5vpgmlTMWvfPw2eN9SoJ/VGP8rskAz7F4IY+IBf9cZa9TwBMg7PoXL8i9BXTjL4TbVe+4rDc79ONIiOM5Dy4KHgDzk4MyjxtemF6Eehktk+k4/LVlYdPeV0kUjv6bxc07aVw83JXvViDhfMlPJXqpNjU6w4VPfEAQvP/Z4a5JxjkuOkHiBa6TMOQ9XZCrleBfMQNUllBT/kuhfj+JHxVlIlStQQIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQBneT815KJu3EHLlxOGsnrxrFUtLsuKIVyk0pCm3A86T6q9SEcF5NEnZvSILDFbKaCFIbMuilaDC4DPscvGUtzU/tUB+gWZtWTwOidYlAQzcpT6w4YWEl5hCw+XfORj4ppmbDoGEYb2KJbFk92S7ggdRR+8NqEmhOFt+cJDhDfZBFD6KoUFhLJKKyMC09vMMp6LH+FnCELUZDZ9ovUvFj5ibPH4tWzavXNpI69wYTkcfaQ+9n5IjnqsjMfs1UNo8KXf272KzP8j9wEtLbP4pF92/fdzGM5tKobBD5FkMeHvWlH9xq6fXQ9Lnvo4mDBrEvq2iw1fW8klTVr54GU/iO6F</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIC6jCCAdICCQDLPAZFV85ZJTANBgkqhkiG9w0BAQsFADA3MQswCQYDVQQGEwJKUDEOMAwGA1UECAwFVE9LWU8xGDAWBgNVBAMMD2lkcC5leGFtcGxlLmNvbTAeFw0yMjA5MDgwMzA5MjVaFw0zMjA5MDcwMzA5MjVaMDcxCzAJBgNVBAYTAkpQMQ4wDAYDVQQIDAVUT0tZTzEYMBYGA1UEAwwPaWRwLmV4YW1wbGUuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3vHTqlfTb8q58nicgrSHdgPdOXSUgxXos7zkHf2B0PEU0RgisAma9x76UjVsHwHJ2ZP5vGhlRl1fzXp0n11rpcbZtJwL/kE2ITwrC5IQ0IaCHm2ws338WTSIbMX5vpgmlTMWvfPw2eN9SoJ/VGP8rskAz7F4IY+IBf9cZa9TwBMg7PoXL8i9BXTjL4TbVe+4rDc79ONIiOM5Dy4KHgDzk4MyjxtemF6Eehktk+k4/LVlYdPeV0kUjv6bxc07aVw83JXvViDhfMlPJXqpNjU6w4VPfEAQvP/Z4a5JxjkuOkHiBa6TMOQ9XZCrleBfMQNUllBT/kuhfj+JHxVlIlStQQIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQBneT815KJu3EHLlxOGsnrxrFUtLsuKIVyk0pCm3A86T6q9SEcF5NEnZvSILDFbKaCFIbMuilaDC4DPscvGUtzU/tUB+gWZtWTwOidYlAQzcpT6w4YWEl5hCw+XfORj4ppmbDoGEYb2KJbFk92S7ggdRR+8NqEmhOFt+cJDhDfZBFD6KoUFhLJKKyMC09vMMp6LH+FnCELUZDZ9ovUvFj5ibPH4tWzavXNpI69wYTkcfaQ+9n5IjnqsjMfs1UNo8KXf272KzP8j9wEtLbP4pF92/fdzGM5tKobBD5FkMeHvWlH9xq6fXQ9Lnvo4mDBrEvq2iw1fW8klTVr54GU/iO6F</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="http://3.112.103.94/simplesaml/saml2/idp/SingleLogoutService.php"/> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="http://3.112.103.94/simplesaml/saml2/idp/SSOService.php"/> </md:IDPSSODescriptor> <md:ContactPerson contactType="technical"> <md:GivenName>Administrator</md:GivenName> <md:EmailAddress>mailto:na@example.com</md:EmailAddress> </md:ContactPerson> </md:EntityDescriptor>
In SimpleSAMLphp flat file format - use this if you are using a SimpleSAMLphp entity on the other side:
$metadata['http://3.112.103.94/simplesaml/saml2/idp/metadata.php'] = [ 'metadata-set' => 'saml20-idp-remote', 'entityid' => 'http://3.112.103.94/simplesaml/saml2/idp/metadata.php', 'SingleSignOnService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'http://3.112.103.94/simplesaml/saml2/idp/SSOService.php', ], ], 'SingleLogoutService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'http://3.112.103.94/simplesaml/saml2/idp/SingleLogoutService.php', ], ], 'certData' => 'MIIC6jCCAdICCQDLPAZFV85ZJTANBgkqhkiG9w0BAQsFADA3MQswCQYDVQQGEwJKUDEOMAwGA1UECAwFVE9LWU8xGDAWBgNVBAMMD2lkcC5leGFtcGxlLmNvbTAeFw0yMjA5MDgwMzA5MjVaFw0zMjA5MDcwMzA5MjVaMDcxCzAJBgNVBAYTAkpQMQ4wDAYDVQQIDAVUT0tZTzEYMBYGA1UEAwwPaWRwLmV4YW1wbGUuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3vHTqlfTb8q58nicgrSHdgPdOXSUgxXos7zkHf2B0PEU0RgisAma9x76UjVsHwHJ2ZP5vGhlRl1fzXp0n11rpcbZtJwL/kE2ITwrC5IQ0IaCHm2ws338WTSIbMX5vpgmlTMWvfPw2eN9SoJ/VGP8rskAz7F4IY+IBf9cZa9TwBMg7PoXL8i9BXTjL4TbVe+4rDc79ONIiOM5Dy4KHgDzk4MyjxtemF6Eehktk+k4/LVlYdPeV0kUjv6bxc07aVw83JXvViDhfMlPJXqpNjU6w4VPfEAQvP/Z4a5JxjkuOkHiBa6TMOQ9XZCrleBfMQNUllBT/kuhfj+JHxVlIlStQQIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQBneT815KJu3EHLlxOGsnrxrFUtLsuKIVyk0pCm3A86T6q9SEcF5NEnZvSILDFbKaCFIbMuilaDC4DPscvGUtzU/tUB+gWZtWTwOidYlAQzcpT6w4YWEl5hCw+XfORj4ppmbDoGEYb2KJbFk92S7ggdRR+8NqEmhOFt+cJDhDfZBFD6KoUFhLJKKyMC09vMMp6LH+FnCELUZDZ9ovUvFj5ibPH4tWzavXNpI69wYTkcfaQ+9n5IjnqsjMfs1UNo8KXf272KzP8j9wEtLbP4pF92/fdzGM5tKobBD5FkMeHvWlH9xq6fXQ9Lnvo4mDBrEvq2iw1fW8klTVr54GU/iO6F', 'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient', 'contacts' => [ [ 'emailAddress' => 'na@example.com', 'contactType' => 'technical', 'givenName' => 'Administrator', ], ], ];
Certificates
Download the X509 certificates as PEM-encoded files.