SAML 2.0 IdP Metadata
Here is the metadata that SimpleSAMLphp has generated for you. You may send this metadata document to trusted partners to setup a trusted federation.
You can get the metadata xml on a dedicated URL:
https://saml.nspes.ca/simplesaml/saml2/idp/metadata.php
Metadata
In SAML 2.0 Metadata XML format:
<?xml version="1.0"?> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://saml.nspes.ca/simplesaml/saml2/idp/metadata.php"> <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIID+zCCAuOgAwIBAgIJALsjcZUK33ClMA0GCSqGSIb3DQEBBQUAMIGTMQswCQYDVQQGEwJDQTEUMBIGA1UECAwLTm92YSBTY290aWExEDAOBgNVBAcMB0hhbGlmYXgxETAPBgNVBAoMCE5zIERFRUNEMQwwCgYDVQQLDANJVFMxFjAUBgNVBAMMDXNhbWwubnNwZXMuY2ExIzAhBgkqhkiG9w0BCQEWFG1hY2xlYWpiQGVkbmV0Lm5zLmNhMB4XDTE0MDgyOTEyMzkyOFoXDTI0MDgyODEyMzkyOFowgZMxCzAJBgNVBAYTAkNBMRQwEgYDVQQIDAtOb3ZhIFNjb3RpYTEQMA4GA1UEBwwHSGFsaWZheDERMA8GA1UECgwITnMgREVFQ0QxDDAKBgNVBAsMA0lUUzEWMBQGA1UEAwwNc2FtbC5uc3Blcy5jYTEjMCEGCSqGSIb3DQEJARYUbWFjbGVhamJAZWRuZXQubnMuY2EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC+whQTGbfifsP8bWXstkMIerbhEfMxlpXHOFl+xbvfzeMWMb+iv+Z9gZ6VCbht4P/I3xQ0VllUzhcHvGOLgfwPiKCwWSfCYKQPDmW/1rZmOOiNT3clOq4AVtNvZUnYaKuOeO54VommHnaVT7m0Od+0RBoYGIq98XlecRBugmMtxMfL+BWqGgeLcD0xerwvRdncYHoKy6msD0+q1jg7dXcWkpPveBX02GU6E//HxVCrvutBFrMDqwurHhnvPxKb/B8mNU43ZiJiYgswq/Zyl4m9FAQ7fNvkgRoutTlhkXcAA2zfv2u+6RojzBO03Gs/nyChx6gujO7gn7euD4xaASsZAgMBAAGjUDBOMB0GA1UdDgQWBBTnlg4nqbdz43XoBI5ZE76/NhegazAfBgNVHSMEGDAWgBTnlg4nqbdz43XoBI5ZE76/NhegazAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBBQUAA4IBAQAG9y7YwbZPFBcNuJ4hBSISnMbvJ0rbPAvE1j8mYTjND/a8UGO9U1u/a4QPnC/3QP+bSoECW10mio/kCNx2ohfifmAlZC7GhMMtqSu3IgP3mcDaVUuak9qPh7YhFpxweNNiw762aP1+K4L3YhWfyef59uuUiHXLNVStvE4DTZV2opY+6pngIqMS16/f9dsjd0XYvGLRQbEb+RBCM3jVwWBSOaS8Cw4266Lj1jpLn4Yf9xyxPyA6aRuiL+gDjFTYb2Pb955wwuu6MG3zNBsKnZjIm3CKbiOsUzKFGC9xxwxLyJnqqK2ioKYA0MJ8g2N9IBnDlvDzAjjMiAN8j/A9BUNB</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIID+zCCAuOgAwIBAgIJALsjcZUK33ClMA0GCSqGSIb3DQEBBQUAMIGTMQswCQYDVQQGEwJDQTEUMBIGA1UECAwLTm92YSBTY290aWExEDAOBgNVBAcMB0hhbGlmYXgxETAPBgNVBAoMCE5zIERFRUNEMQwwCgYDVQQLDANJVFMxFjAUBgNVBAMMDXNhbWwubnNwZXMuY2ExIzAhBgkqhkiG9w0BCQEWFG1hY2xlYWpiQGVkbmV0Lm5zLmNhMB4XDTE0MDgyOTEyMzkyOFoXDTI0MDgyODEyMzkyOFowgZMxCzAJBgNVBAYTAkNBMRQwEgYDVQQIDAtOb3ZhIFNjb3RpYTEQMA4GA1UEBwwHSGFsaWZheDERMA8GA1UECgwITnMgREVFQ0QxDDAKBgNVBAsMA0lUUzEWMBQGA1UEAwwNc2FtbC5uc3Blcy5jYTEjMCEGCSqGSIb3DQEJARYUbWFjbGVhamJAZWRuZXQubnMuY2EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC+whQTGbfifsP8bWXstkMIerbhEfMxlpXHOFl+xbvfzeMWMb+iv+Z9gZ6VCbht4P/I3xQ0VllUzhcHvGOLgfwPiKCwWSfCYKQPDmW/1rZmOOiNT3clOq4AVtNvZUnYaKuOeO54VommHnaVT7m0Od+0RBoYGIq98XlecRBugmMtxMfL+BWqGgeLcD0xerwvRdncYHoKy6msD0+q1jg7dXcWkpPveBX02GU6E//HxVCrvutBFrMDqwurHhnvPxKb/B8mNU43ZiJiYgswq/Zyl4m9FAQ7fNvkgRoutTlhkXcAA2zfv2u+6RojzBO03Gs/nyChx6gujO7gn7euD4xaASsZAgMBAAGjUDBOMB0GA1UdDgQWBBTnlg4nqbdz43XoBI5ZE76/NhegazAfBgNVHSMEGDAWgBTnlg4nqbdz43XoBI5ZE76/NhegazAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBBQUAA4IBAQAG9y7YwbZPFBcNuJ4hBSISnMbvJ0rbPAvE1j8mYTjND/a8UGO9U1u/a4QPnC/3QP+bSoECW10mio/kCNx2ohfifmAlZC7GhMMtqSu3IgP3mcDaVUuak9qPh7YhFpxweNNiw762aP1+K4L3YhWfyef59uuUiHXLNVStvE4DTZV2opY+6pngIqMS16/f9dsjd0XYvGLRQbEb+RBCM3jVwWBSOaS8Cw4266Lj1jpLn4Yf9xyxPyA6aRuiL+gDjFTYb2Pb955wwuu6MG3zNBsKnZjIm3CKbiOsUzKFGC9xxwxLyJnqqK2ioKYA0MJ8g2N9IBnDlvDzAjjMiAN8j/A9BUNB</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://saml.nspes.ca/simplesaml/saml2/idp/SingleLogoutService.php"/> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://saml.nspes.ca/simplesaml/saml2/idp/SSOService.php"/> </md:IDPSSODescriptor> <md:ContactPerson contactType="technical"> <md:GivenName>DOEAdmin</md:GivenName> <md:EmailAddress>mailto:saml@ednet.ns.ca</md:EmailAddress> </md:ContactPerson> </md:EntityDescriptor>
In SimpleSAMLphp flat file format - use this if you are using a SimpleSAMLphp entity on the other side:
$metadata['https://saml.nspes.ca/simplesaml/saml2/idp/metadata.php'] = [ 'metadata-set' => 'saml20-idp-remote', 'entityid' => 'https://saml.nspes.ca/simplesaml/saml2/idp/metadata.php', 'SingleSignOnService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://saml.nspes.ca/simplesaml/saml2/idp/SSOService.php', ], ], 'SingleLogoutService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://saml.nspes.ca/simplesaml/saml2/idp/SingleLogoutService.php', ], ], 'certData' => 'MIID+zCCAuOgAwIBAgIJALsjcZUK33ClMA0GCSqGSIb3DQEBBQUAMIGTMQswCQYDVQQGEwJDQTEUMBIGA1UECAwLTm92YSBTY290aWExEDAOBgNVBAcMB0hhbGlmYXgxETAPBgNVBAoMCE5zIERFRUNEMQwwCgYDVQQLDANJVFMxFjAUBgNVBAMMDXNhbWwubnNwZXMuY2ExIzAhBgkqhkiG9w0BCQEWFG1hY2xlYWpiQGVkbmV0Lm5zLmNhMB4XDTE0MDgyOTEyMzkyOFoXDTI0MDgyODEyMzkyOFowgZMxCzAJBgNVBAYTAkNBMRQwEgYDVQQIDAtOb3ZhIFNjb3RpYTEQMA4GA1UEBwwHSGFsaWZheDERMA8GA1UECgwITnMgREVFQ0QxDDAKBgNVBAsMA0lUUzEWMBQGA1UEAwwNc2FtbC5uc3Blcy5jYTEjMCEGCSqGSIb3DQEJARYUbWFjbGVhamJAZWRuZXQubnMuY2EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC+whQTGbfifsP8bWXstkMIerbhEfMxlpXHOFl+xbvfzeMWMb+iv+Z9gZ6VCbht4P/I3xQ0VllUzhcHvGOLgfwPiKCwWSfCYKQPDmW/1rZmOOiNT3clOq4AVtNvZUnYaKuOeO54VommHnaVT7m0Od+0RBoYGIq98XlecRBugmMtxMfL+BWqGgeLcD0xerwvRdncYHoKy6msD0+q1jg7dXcWkpPveBX02GU6E//HxVCrvutBFrMDqwurHhnvPxKb/B8mNU43ZiJiYgswq/Zyl4m9FAQ7fNvkgRoutTlhkXcAA2zfv2u+6RojzBO03Gs/nyChx6gujO7gn7euD4xaASsZAgMBAAGjUDBOMB0GA1UdDgQWBBTnlg4nqbdz43XoBI5ZE76/NhegazAfBgNVHSMEGDAWgBTnlg4nqbdz43XoBI5ZE76/NhegazAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBBQUAA4IBAQAG9y7YwbZPFBcNuJ4hBSISnMbvJ0rbPAvE1j8mYTjND/a8UGO9U1u/a4QPnC/3QP+bSoECW10mio/kCNx2ohfifmAlZC7GhMMtqSu3IgP3mcDaVUuak9qPh7YhFpxweNNiw762aP1+K4L3YhWfyef59uuUiHXLNVStvE4DTZV2opY+6pngIqMS16/f9dsjd0XYvGLRQbEb+RBCM3jVwWBSOaS8Cw4266Lj1jpLn4Yf9xyxPyA6aRuiL+gDjFTYb2Pb955wwuu6MG3zNBsKnZjIm3CKbiOsUzKFGC9xxwxLyJnqqK2ioKYA0MJ8g2N9IBnDlvDzAjjMiAN8j/A9BUNB', 'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient', 'contacts' => [ [ 'emailAddress' => 'saml@ednet.ns.ca', 'contactType' => 'technical', 'givenName' => 'DOEAdmin', ], ], ];
Certificates
Download the X509 certificates as PEM-encoded files.