SAML 2.0 SP Metadata
Here is the metadata that SimpleSAMLphp has generated for you. You may send this metadata document to trusted partners to setup a trusted federation.
You can get the metadata xml on a dedicated URL:
https://procure.dig.at/simplesaml/module.php/saml/sp/metadata.php/bilfinger-sp
Metadata
In SAML 2.0 Metadata XML format:
<?xml version="1.0"?> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://procure.dig.at"> <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol"> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIEkjCCA3qgAwIBAgIJAORTBkzMupezMA0GCSqGSIb3DQEBBQUAMIGMMQswCQYDVQQGEwJBVDEMMAoGA1UECBMDT09FMQ0wCwYDVQQHEwRMaW56MREwDwYDVQQKEwhESUcgR21iSDESMBAGA1UECxMJZVByb2NUZXN0MRUwEwYDVQQDEwxkaWdlcGNvcnRlc3QxIjAgBgkqhkiG9w0BCQEWE2VyaWNoLnNlbWxha0BkaWcuYXQwHhcNMTcwNjAxMDg0NTUzWhcNMjcwNjAxMDg0NTUzWjCBjDELMAkGA1UEBhMCQVQxDDAKBgNVBAgTA09PRTENMAsGA1UEBxMETGluejERMA8GA1UEChMIRElHIEdtYkgxEjAQBgNVBAsTCWVQcm9jVGVzdDEVMBMGA1UEAxMMZGlnZXBjb3J0ZXN0MSIwIAYJKoZIhvcNAQkBFhNlcmljaC5zZW1sYWtAZGlnLmF0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyWgCN3TTc6wuKjYStJb2O8o9MVdUCfHcwOYejXeHla063Qee9wvYW+2TrEg95R6xrZmzxU6IFZ0kMSZkhl1apYkG4WW1i0BHSO9hwIv3CCm1fQI4QoH6/dFpExRdHVipzrc1HrrwHIwN+HuQUunv8Glg5eXVMhqyH+LzeQhRA8dvL+cnWjIVHij60+uS6LWl+QpT2H7kgPtPLnB2R8sMfpeo+Bk8cDjcbw1joqZAJs6VWctxNLHwZALDxo5gM/AhcCQefRoXwI/2YOyL/Lxe95us34UYwucC1dGBmN/hSOdtXWZ6PcVAmZU1gKmeOwukcjnp/dfk2EGF4MrxVMCMgQIDAQABo4H0MIHxMB0GA1UdDgQWBBSJqkmkT1zEQu7qTlL5HFT5y8F3BTCBwQYDVR0jBIG5MIG2gBSJqkmkT1zEQu7qTlL5HFT5y8F3BaGBkqSBjzCBjDELMAkGA1UEBhMCQVQxDDAKBgNVBAgTA09PRTENMAsGA1UEBxMETGluejERMA8GA1UEChMIRElHIEdtYkgxEjAQBgNVBAsTCWVQcm9jVGVzdDEVMBMGA1UEAxMMZGlnZXBjb3J0ZXN0MSIwIAYJKoZIhvcNAQkBFhNlcmljaC5zZW1sYWtAZGlnLmF0ggkA5FMGTMy6l7MwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQUFAAOCAQEAnpnd+J+ZWJqXH4TF+Bk/tpKFP7n40rNIi5VYHBD9KqTxga6caZ42I4yj2lJioD9ZaT8iaIgOC+MbbwyR7NnOU7XjLlj4zoE67YbWPFQr9KTvyLKtRO7sqqB2yTt5SbmKDnmsTvC/wvfF3gDoaUiYbFjCr125fFBSU9udgGo3LX8rf9DW+C760bIGzP5uQ22w6/exSU3f1wapJmzTNj7KuncAkCJp04M77pVoZJYKJHeWeik1d1+PqpeWKvG2E1mGwFfZEj1LjSmj1PkJ0BYv/ENX4Hbq6v7FN+psukD4epAlSGkkBHX+/VwAGrtpHo063hhJw2KZDlqmoSp0TtPqVg==</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIEkjCCA3qgAwIBAgIJAORTBkzMupezMA0GCSqGSIb3DQEBBQUAMIGMMQswCQYDVQQGEwJBVDEMMAoGA1UECBMDT09FMQ0wCwYDVQQHEwRMaW56MREwDwYDVQQKEwhESUcgR21iSDESMBAGA1UECxMJZVByb2NUZXN0MRUwEwYDVQQDEwxkaWdlcGNvcnRlc3QxIjAgBgkqhkiG9w0BCQEWE2VyaWNoLnNlbWxha0BkaWcuYXQwHhcNMTcwNjAxMDg0NTUzWhcNMjcwNjAxMDg0NTUzWjCBjDELMAkGA1UEBhMCQVQxDDAKBgNVBAgTA09PRTENMAsGA1UEBxMETGluejERMA8GA1UEChMIRElHIEdtYkgxEjAQBgNVBAsTCWVQcm9jVGVzdDEVMBMGA1UEAxMMZGlnZXBjb3J0ZXN0MSIwIAYJKoZIhvcNAQkBFhNlcmljaC5zZW1sYWtAZGlnLmF0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyWgCN3TTc6wuKjYStJb2O8o9MVdUCfHcwOYejXeHla063Qee9wvYW+2TrEg95R6xrZmzxU6IFZ0kMSZkhl1apYkG4WW1i0BHSO9hwIv3CCm1fQI4QoH6/dFpExRdHVipzrc1HrrwHIwN+HuQUunv8Glg5eXVMhqyH+LzeQhRA8dvL+cnWjIVHij60+uS6LWl+QpT2H7kgPtPLnB2R8sMfpeo+Bk8cDjcbw1joqZAJs6VWctxNLHwZALDxo5gM/AhcCQefRoXwI/2YOyL/Lxe95us34UYwucC1dGBmN/hSOdtXWZ6PcVAmZU1gKmeOwukcjnp/dfk2EGF4MrxVMCMgQIDAQABo4H0MIHxMB0GA1UdDgQWBBSJqkmkT1zEQu7qTlL5HFT5y8F3BTCBwQYDVR0jBIG5MIG2gBSJqkmkT1zEQu7qTlL5HFT5y8F3BaGBkqSBjzCBjDELMAkGA1UEBhMCQVQxDDAKBgNVBAgTA09PRTENMAsGA1UEBxMETGluejERMA8GA1UEChMIRElHIEdtYkgxEjAQBgNVBAsTCWVQcm9jVGVzdDEVMBMGA1UEAxMMZGlnZXBjb3J0ZXN0MSIwIAYJKoZIhvcNAQkBFhNlcmljaC5zZW1sYWtAZGlnLmF0ggkA5FMGTMy6l7MwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQUFAAOCAQEAnpnd+J+ZWJqXH4TF+Bk/tpKFP7n40rNIi5VYHBD9KqTxga6caZ42I4yj2lJioD9ZaT8iaIgOC+MbbwyR7NnOU7XjLlj4zoE67YbWPFQr9KTvyLKtRO7sqqB2yTt5SbmKDnmsTvC/wvfF3gDoaUiYbFjCr125fFBSU9udgGo3LX8rf9DW+C760bIGzP5uQ22w6/exSU3f1wapJmzTNj7KuncAkCJp04M77pVoZJYKJHeWeik1d1+PqpeWKvG2E1mGwFfZEj1LjSmj1PkJ0BYv/ENX4Hbq6v7FN+psukD4epAlSGkkBHX+/VwAGrtpHo063hhJw2KZDlqmoSp0TtPqVg==</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://procure.dig.at/simplesaml/module.php/saml/sp/saml2-logout.php/bilfinger-sp"/> <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</md:NameIDFormat> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://procure.dig.at/simplesaml/module.php/saml/sp/saml2-acs.php/bilfinger-sp" index="0"/> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://procure.dig.at/simplesaml/module.php/saml/sp/saml1-acs.php/bilfinger-sp" index="1"/> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://procure.dig.at/simplesaml/module.php/saml/sp/saml2-acs.php/bilfinger-sp" index="2"/> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://procure.dig.at/simplesaml/module.php/saml/sp/saml1-acs.php/bilfinger-sp/artifact" index="3"/> </md:SPSSODescriptor> <md:ContactPerson contactType="technical"> <md:GivenName>Administrator</md:GivenName> <md:EmailAddress>mailto:helpdesk@dig.at</md:EmailAddress> </md:ContactPerson> </md:EntityDescriptor>
In SimpleSAMLphp flat file format - use this if you are using a SimpleSAMLphp entity on the other side:
$metadata['https://procure.dig.at'] = [ 'SingleLogoutService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://procure.dig.at/simplesaml/module.php/saml/sp/saml2-logout.php/bilfinger-sp', ], ], 'AssertionConsumerService' => [ [ 'index' => 0, 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST', 'Location' => 'https://procure.dig.at/simplesaml/module.php/saml/sp/saml2-acs.php/bilfinger-sp', ], [ 'index' => 1, 'Binding' => 'urn:oasis:names:tc:SAML:1.0:profiles:browser-post', 'Location' => 'https://procure.dig.at/simplesaml/module.php/saml/sp/saml1-acs.php/bilfinger-sp', ], [ 'index' => 2, 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact', 'Location' => 'https://procure.dig.at/simplesaml/module.php/saml/sp/saml2-acs.php/bilfinger-sp', ], [ 'index' => 3, 'Binding' => 'urn:oasis:names:tc:SAML:1.0:profiles:artifact-01', 'Location' => 'https://procure.dig.at/simplesaml/module.php/saml/sp/saml1-acs.php/bilfinger-sp/artifact', ], ], 'NameIDFormat' => 'urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified', 'contacts' => [ [ 'emailAddress' => 'helpdesk@dig.at', 'contactType' => 'technical', 'givenName' => 'Administrator', ], ], 'certData' => 'MIIEkjCCA3qgAwIBAgIJAORTBkzMupezMA0GCSqGSIb3DQEBBQUAMIGMMQswCQYDVQQGEwJBVDEMMAoGA1UECBMDT09FMQ0wCwYDVQQHEwRMaW56MREwDwYDVQQKEwhESUcgR21iSDESMBAGA1UECxMJZVByb2NUZXN0MRUwEwYDVQQDEwxkaWdlcGNvcnRlc3QxIjAgBgkqhkiG9w0BCQEWE2VyaWNoLnNlbWxha0BkaWcuYXQwHhcNMTcwNjAxMDg0NTUzWhcNMjcwNjAxMDg0NTUzWjCBjDELMAkGA1UEBhMCQVQxDDAKBgNVBAgTA09PRTENMAsGA1UEBxMETGluejERMA8GA1UEChMIRElHIEdtYkgxEjAQBgNVBAsTCWVQcm9jVGVzdDEVMBMGA1UEAxMMZGlnZXBjb3J0ZXN0MSIwIAYJKoZIhvcNAQkBFhNlcmljaC5zZW1sYWtAZGlnLmF0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyWgCN3TTc6wuKjYStJb2O8o9MVdUCfHcwOYejXeHla063Qee9wvYW+2TrEg95R6xrZmzxU6IFZ0kMSZkhl1apYkG4WW1i0BHSO9hwIv3CCm1fQI4QoH6/dFpExRdHVipzrc1HrrwHIwN+HuQUunv8Glg5eXVMhqyH+LzeQhRA8dvL+cnWjIVHij60+uS6LWl+QpT2H7kgPtPLnB2R8sMfpeo+Bk8cDjcbw1joqZAJs6VWctxNLHwZALDxo5gM/AhcCQefRoXwI/2YOyL/Lxe95us34UYwucC1dGBmN/hSOdtXWZ6PcVAmZU1gKmeOwukcjnp/dfk2EGF4MrxVMCMgQIDAQABo4H0MIHxMB0GA1UdDgQWBBSJqkmkT1zEQu7qTlL5HFT5y8F3BTCBwQYDVR0jBIG5MIG2gBSJqkmkT1zEQu7qTlL5HFT5y8F3BaGBkqSBjzCBjDELMAkGA1UEBhMCQVQxDDAKBgNVBAgTA09PRTENMAsGA1UEBxMETGluejERMA8GA1UEChMIRElHIEdtYkgxEjAQBgNVBAsTCWVQcm9jVGVzdDEVMBMGA1UEAxMMZGlnZXBjb3J0ZXN0MSIwIAYJKoZIhvcNAQkBFhNlcmljaC5zZW1sYWtAZGlnLmF0ggkA5FMGTMy6l7MwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQUFAAOCAQEAnpnd+J+ZWJqXH4TF+Bk/tpKFP7n40rNIi5VYHBD9KqTxga6caZ42I4yj2lJioD9ZaT8iaIgOC+MbbwyR7NnOU7XjLlj4zoE67YbWPFQr9KTvyLKtRO7sqqB2yTt5SbmKDnmsTvC/wvfF3gDoaUiYbFjCr125fFBSU9udgGo3LX8rf9DW+C760bIGzP5uQ22w6/exSU3f1wapJmzTNj7KuncAkCJp04M77pVoZJYKJHeWeik1d1+PqpeWKvG2E1mGwFfZEj1LjSmj1PkJ0BYv/ENX4Hbq6v7FN+psukD4epAlSGkkBHX+/VwAGrtpHo063hhJw2KZDlqmoSp0TtPqVg==', ];