Afrikaans | Čeština | Dansk | Deutsch | ελληνικά | English | Español | eesti keel | Euskara | Suomeksi | Français | עִבְרִית | Hrvatski | Magyar | Bahasa Indonesia | Italiano | 日本語 | Lëtzebuergesch | Lietuvių kalba | Latviešu | Nederlands | Nynorsk | Bokmål | Język polski | Português | Português brasileiro | Românește | русский язык | Sámegiella | Slovenščina | Srpski | Svenska | Türkçe | 简体中文 | 繁體中文

SAML 2.0 IdP Metadata

Here is the metadata that SimpleSAMLphp has generated for you. You may send this metadata document to trusted partners to setup a trusted federation.

You can get the metadata xml on a dedicated URL:

https://account.diocesan.com/simplesaml/saml2/idp/metadata.php

Metadata

In SAML 2.0 Metadata XML format:

<?xml version="1.0"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://account.diocesan.com/simplesaml/saml2/idp/metadata.php">
  <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
    <md:KeyDescriptor use="signing">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:X509Data>
          <ds:X509Certificate>MIIDYDCCAkigAwIBAgIJALcCHR1CDnmxMA0GCSqGSIb3DQEBCwUAMEUxCzAJBgNVBAYTAkFVMRMwEQYDVQQIDApTb21lLVN0YXRlMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQwHhcNMTgwOTA2MjA1NjU1WhcNMjgwOTA1MjA1NjU1WjBFMQswCQYDVQQGEwJBVTETMBEGA1UECAwKU29tZS1TdGF0ZTEhMB8GA1UECgwYSW50ZXJuZXQgV2lkZ2l0cyBQdHkgTHRkMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzvLnwTMUF8vrPLmbxbVIOyWrAF0iOhTngJFSeXjhJD5aGo3aqjyOW6FbQh9wV5plnb8gxXzXpkfJLDZYKsFpou1+u2+V4fXtU9/kFddTk7H2Nu6iuljLDhHYBFVvcHqAd8ueyGKhsD29YsJ8ZnLco5jV1MVCBH+aXWYdjyZrjL+TqQdYr460H4xWwK2KL5laQsYcxi8WXCx4XtAvkZ3pfP4iXWsM5u04c9+7RrKnXqtOCgwqXhg/VrmDlBCfxGJF1W4zh+cESLPUATE1obug+uPqVyMskUp7oSEFBxLPDszAwXINcIDfjKs6ydkDv2wK4wvb5FFSp6MmiKtWNbnlgwIDAQABo1MwUTAdBgNVHQ4EFgQUGSDPec3Hg9f4xyY1w9Ydf1eEOpgwHwYDVR0jBBgwFoAUGSDPec3Hg9f4xyY1w9Ydf1eEOpgwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAFROpShhTWEPtzsbVNlyGVahbh4SiFEdOxNJk2OT6sWhURM9WMOH31EobtpdjWkNKWtmbBOGFGvX6fE9366jJBogAOw0IesOBPFWgXH1njdprpQxQJ4JeszlZ1PjdcpPjvxzySTmaWSn9gPa3evHfLTZY+hPSV0WnVTEJQycy9UyKA6z4Ug8/dw5a6vjSZb893OjuUJav5cGqOEr2TnqUipdDszhPuG8qt64HXdjt8EZ5cwbFuzttO2qHpRFVnRYiL0pn7ZiD17fvdPpuUU+mpMAkYfIsChr2bFzCd76yyzGPMS6/UOtWpR68XG4/8UTnqxg5AUEklmr6GmftMrg2gg==</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:KeyDescriptor use="encryption">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:X509Data>
          <ds:X509Certificate>MIIDYDCCAkigAwIBAgIJALcCHR1CDnmxMA0GCSqGSIb3DQEBCwUAMEUxCzAJBgNVBAYTAkFVMRMwEQYDVQQIDApTb21lLVN0YXRlMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQwHhcNMTgwOTA2MjA1NjU1WhcNMjgwOTA1MjA1NjU1WjBFMQswCQYDVQQGEwJBVTETMBEGA1UECAwKU29tZS1TdGF0ZTEhMB8GA1UECgwYSW50ZXJuZXQgV2lkZ2l0cyBQdHkgTHRkMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzvLnwTMUF8vrPLmbxbVIOyWrAF0iOhTngJFSeXjhJD5aGo3aqjyOW6FbQh9wV5plnb8gxXzXpkfJLDZYKsFpou1+u2+V4fXtU9/kFddTk7H2Nu6iuljLDhHYBFVvcHqAd8ueyGKhsD29YsJ8ZnLco5jV1MVCBH+aXWYdjyZrjL+TqQdYr460H4xWwK2KL5laQsYcxi8WXCx4XtAvkZ3pfP4iXWsM5u04c9+7RrKnXqtOCgwqXhg/VrmDlBCfxGJF1W4zh+cESLPUATE1obug+uPqVyMskUp7oSEFBxLPDszAwXINcIDfjKs6ydkDv2wK4wvb5FFSp6MmiKtWNbnlgwIDAQABo1MwUTAdBgNVHQ4EFgQUGSDPec3Hg9f4xyY1w9Ydf1eEOpgwHwYDVR0jBBgwFoAUGSDPec3Hg9f4xyY1w9Ydf1eEOpgwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAFROpShhTWEPtzsbVNlyGVahbh4SiFEdOxNJk2OT6sWhURM9WMOH31EobtpdjWkNKWtmbBOGFGvX6fE9366jJBogAOw0IesOBPFWgXH1njdprpQxQJ4JeszlZ1PjdcpPjvxzySTmaWSn9gPa3evHfLTZY+hPSV0WnVTEJQycy9UyKA6z4Ug8/dw5a6vjSZb893OjuUJav5cGqOEr2TnqUipdDszhPuG8qt64HXdjt8EZ5cwbFuzttO2qHpRFVnRYiL0pn7ZiD17fvdPpuUU+mpMAkYfIsChr2bFzCd76yyzGPMS6/UOtWpR68XG4/8UTnqxg5AUEklmr6GmftMrg2gg==</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://account.diocesan.com/simplesaml/saml2/idp/SingleLogoutService.php"/>
    <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
    <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://account.diocesan.com/simplesaml/saml2/idp/SSOService.php"/>
  </md:IDPSSODescriptor>
  <md:ContactPerson contactType="technical">
    <md:GivenName>Administrator</md:GivenName>
    <md:EmailAddress>mailto:e.kontsevoi@intetics.com</md:EmailAddress>
  </md:ContactPerson>
</md:EntityDescriptor>

In SimpleSAMLphp flat file format - use this if you are using a SimpleSAMLphp entity on the other side:

$metadata['https://account.diocesan.com/simplesaml/saml2/idp/metadata.php'] = [
    'metadata-set' => 'saml20-idp-remote',
    'entityid' => 'https://account.diocesan.com/simplesaml/saml2/idp/metadata.php',
    'SingleSignOnService' => [
        [
            'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
            'Location' => 'https://account.diocesan.com/simplesaml/saml2/idp/SSOService.php',
        ],
    ],
    'SingleLogoutService' => [
        [
            'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
            'Location' => 'https://account.diocesan.com/simplesaml/saml2/idp/SingleLogoutService.php',
        ],
    ],
    'certData' => 'MIIDYDCCAkigAwIBAgIJALcCHR1CDnmxMA0GCSqGSIb3DQEBCwUAMEUxCzAJBgNVBAYTAkFVMRMwEQYDVQQIDApTb21lLVN0YXRlMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQwHhcNMTgwOTA2MjA1NjU1WhcNMjgwOTA1MjA1NjU1WjBFMQswCQYDVQQGEwJBVTETMBEGA1UECAwKU29tZS1TdGF0ZTEhMB8GA1UECgwYSW50ZXJuZXQgV2lkZ2l0cyBQdHkgTHRkMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzvLnwTMUF8vrPLmbxbVIOyWrAF0iOhTngJFSeXjhJD5aGo3aqjyOW6FbQh9wV5plnb8gxXzXpkfJLDZYKsFpou1+u2+V4fXtU9/kFddTk7H2Nu6iuljLDhHYBFVvcHqAd8ueyGKhsD29YsJ8ZnLco5jV1MVCBH+aXWYdjyZrjL+TqQdYr460H4xWwK2KL5laQsYcxi8WXCx4XtAvkZ3pfP4iXWsM5u04c9+7RrKnXqtOCgwqXhg/VrmDlBCfxGJF1W4zh+cESLPUATE1obug+uPqVyMskUp7oSEFBxLPDszAwXINcIDfjKs6ydkDv2wK4wvb5FFSp6MmiKtWNbnlgwIDAQABo1MwUTAdBgNVHQ4EFgQUGSDPec3Hg9f4xyY1w9Ydf1eEOpgwHwYDVR0jBBgwFoAUGSDPec3Hg9f4xyY1w9Ydf1eEOpgwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAFROpShhTWEPtzsbVNlyGVahbh4SiFEdOxNJk2OT6sWhURM9WMOH31EobtpdjWkNKWtmbBOGFGvX6fE9366jJBogAOw0IesOBPFWgXH1njdprpQxQJ4JeszlZ1PjdcpPjvxzySTmaWSn9gPa3evHfLTZY+hPSV0WnVTEJQycy9UyKA6z4Ug8/dw5a6vjSZb893OjuUJav5cGqOEr2TnqUipdDszhPuG8qt64HXdjt8EZ5cwbFuzttO2qHpRFVnRYiL0pn7ZiD17fvdPpuUU+mpMAkYfIsChr2bFzCd76yyzGPMS6/UOtWpR68XG4/8UTnqxg5AUEklmr6GmftMrg2gg==',
    'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient',
    'contacts' => [
        [
            'emailAddress' => 'e.kontsevoi@intetics.com',
            'contactType' => 'technical',
            'givenName' => 'Administrator',
        ],
    ],
];

Certificates

Download the X509 certificates as PEM-encoded files.