SAML 2.0 IdP Metadata
Here is the metadata that simpleSAMLphp has generated for you. You may send this metadata document to trusted partners to setup a trusted federation.
You can get the metadata xml on a dedicated URL:
Metadata
In SAML 2.0 Metadata XML format:
<?xml version="1.0"?> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="smp.ukm.my"> <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIEPTCCAyWgAwIBAgIJALC33UVb+vaDMA0GCSqGSIb3DQEBBQUAMIG0MQswCQYDVQQGEwJNWTERMA8GA1UECAwIU0VMQU5HT1IxEjAQBgNVBAcMCVVLTSBCQU5HSTEnMCUGA1UECgweVU5JVkVSU0lUSSBLRUJBTkdTQUFOIE1BTEFZU0lBMSEwHwYDVQQLDBhQVVNBVCBURUtOT0xPR0kgTUFLTFVNQVQxEzARBgNVBAMMCnNzby51a20ubXkxHTAbBgkqhkiG9w0BCQEWDmJwZEBwdG0udWttLm15MB4XDTE0MDQyMTA0MDI0N1oXDTI0MDQyMDA0MDI0N1owgbQxCzAJBgNVBAYTAk1ZMREwDwYDVQQIDAhTRUxBTkdPUjESMBAGA1UEBwwJVUtNIEJBTkdJMScwJQYDVQQKDB5VTklWRVJTSVRJIEtFQkFOR1NBQU4gTUFMQVlTSUExITAfBgNVBAsMGFBVU0FUIFRFS05PTE9HSSBNQUtMVU1BVDETMBEGA1UEAwwKc3NvLnVrbS5teTEdMBsGCSqGSIb3DQEJARYOYnBkQHB0bS51a20ubXkwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCuMCOPbkaT1fBOoKCLjDtMCFs2QXNIZn6n6OmRW+HOAv3HQGzK27wOtaXeR419HGrldA0VQCx6YPCsPRGgls6i5a6Sp3ifZgPW1hS0tKj6ZFLBttD/ilpadyuTr1HeKkxAR8pvFnddV/XskL7uQWU6m1Fhzc/G0dUByXjtmmaJqzjZi6BWxlXn3gmEVzMShrxGoiRlevLC2h4W7t+HQ8nWTTXsSdwCGoNoZgFGRe6SqsVz1dG4ElhgevaENKPj7WzDZAW0BITWO8fLphrv9CACiM02WUaNfZkzvpTmR27Ojfi3zkuJfD5K2wYkxIgItD4i9bEAMf6t4Kh5zRnM3EYLAgMBAAGjUDBOMB0GA1UdDgQWBBQBhNCc8MozDot07auEqlzPIe4sSjAfBgNVHSMEGDAWgBQBhNCc8MozDot07auEqlzPIe4sSjAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBBQUAA4IBAQAGY9PLbm6V1enkYiVH3tDA9yT9tlaTLCbGk7/a6u8PiVwj1wKhB/169gtFnEinkDeTtv+WG+pL+gaQXiWAP2VfOllQf7CiiITfrXZrCsp/O1q5Xk9qGhw3+m/+L3KUEDFcKNlSHQflJtVNx/BskLOVxT+R4YImf8J9qWIu9clokcRXM/POj8O6cMqWKoKAgH3UoPgl9SLaSDIsXHXrUxCS2vvrgj4gR8b+lmSLVfgj9+Xfwili+vTEFZnebIFiTvbmmmaGCq84jMrYu/t5tDpkAnHYJ9YcyXISd3vRm80bzKGc3KyvOF9CKGEIJMHttrxrF7E6n2UKFh6QQfvOwJ35</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIEPTCCAyWgAwIBAgIJALC33UVb+vaDMA0GCSqGSIb3DQEBBQUAMIG0MQswCQYDVQQGEwJNWTERMA8GA1UECAwIU0VMQU5HT1IxEjAQBgNVBAcMCVVLTSBCQU5HSTEnMCUGA1UECgweVU5JVkVSU0lUSSBLRUJBTkdTQUFOIE1BTEFZU0lBMSEwHwYDVQQLDBhQVVNBVCBURUtOT0xPR0kgTUFLTFVNQVQxEzARBgNVBAMMCnNzby51a20ubXkxHTAbBgkqhkiG9w0BCQEWDmJwZEBwdG0udWttLm15MB4XDTE0MDQyMTA0MDI0N1oXDTI0MDQyMDA0MDI0N1owgbQxCzAJBgNVBAYTAk1ZMREwDwYDVQQIDAhTRUxBTkdPUjESMBAGA1UEBwwJVUtNIEJBTkdJMScwJQYDVQQKDB5VTklWRVJTSVRJIEtFQkFOR1NBQU4gTUFMQVlTSUExITAfBgNVBAsMGFBVU0FUIFRFS05PTE9HSSBNQUtMVU1BVDETMBEGA1UEAwwKc3NvLnVrbS5teTEdMBsGCSqGSIb3DQEJARYOYnBkQHB0bS51a20ubXkwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCuMCOPbkaT1fBOoKCLjDtMCFs2QXNIZn6n6OmRW+HOAv3HQGzK27wOtaXeR419HGrldA0VQCx6YPCsPRGgls6i5a6Sp3ifZgPW1hS0tKj6ZFLBttD/ilpadyuTr1HeKkxAR8pvFnddV/XskL7uQWU6m1Fhzc/G0dUByXjtmmaJqzjZi6BWxlXn3gmEVzMShrxGoiRlevLC2h4W7t+HQ8nWTTXsSdwCGoNoZgFGRe6SqsVz1dG4ElhgevaENKPj7WzDZAW0BITWO8fLphrv9CACiM02WUaNfZkzvpTmR27Ojfi3zkuJfD5K2wYkxIgItD4i9bEAMf6t4Kh5zRnM3EYLAgMBAAGjUDBOMB0GA1UdDgQWBBQBhNCc8MozDot07auEqlzPIe4sSjAfBgNVHSMEGDAWgBQBhNCc8MozDot07auEqlzPIe4sSjAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBBQUAA4IBAQAGY9PLbm6V1enkYiVH3tDA9yT9tlaTLCbGk7/a6u8PiVwj1wKhB/169gtFnEinkDeTtv+WG+pL+gaQXiWAP2VfOllQf7CiiITfrXZrCsp/O1q5Xk9qGhw3+m/+L3KUEDFcKNlSHQflJtVNx/BskLOVxT+R4YImf8J9qWIu9clokcRXM/POj8O6cMqWKoKAgH3UoPgl9SLaSDIsXHXrUxCS2vvrgj4gR8b+lmSLVfgj9+Xfwili+vTEFZnebIFiTvbmmmaGCq84jMrYu/t5tDpkAnHYJ9YcyXISd3vRm80bzKGc3KyvOF9CKGEIJMHttrxrF7E6n2UKFh6QQfvOwJ35</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://smp.ukm.my/simplesaml/saml2/idp/SingleLogoutService.php"/> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://smp.ukm.my/simplesaml/saml2/idp/SSOService.php"/> </md:IDPSSODescriptor> <md:ContactPerson contactType="technical"> <md:SurName>Administrator</md:SurName> <md:EmailAddress>adminsso@ptm.ukm.my</md:EmailAddress> </md:ContactPerson> </md:EntityDescriptor>
In simpleSAMLphp flat file format - use this if you are using a simpleSAMLphp entity on the other side:
$metadata['smp.ukm.my'] = array ( 'metadata-set' => 'saml20-idp-remote', 'entityid' => 'smp.ukm.my', 'SingleSignOnService' => array ( 0 => array ( 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://smp.ukm.my/simplesaml/saml2/idp/SSOService.php', ), ), 'SingleLogoutService' => array ( 0 => array ( 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://smp.ukm.my/simplesaml/saml2/idp/SingleLogoutService.php', ), ), 'certData' => 'MIIEPTCCAyWgAwIBAgIJALC33UVb+vaDMA0GCSqGSIb3DQEBBQUAMIG0MQswCQYDVQQGEwJNWTERMA8GA1UECAwIU0VMQU5HT1IxEjAQBgNVBAcMCVVLTSBCQU5HSTEnMCUGA1UECgweVU5JVkVSU0lUSSBLRUJBTkdTQUFOIE1BTEFZU0lBMSEwHwYDVQQLDBhQVVNBVCBURUtOT0xPR0kgTUFLTFVNQVQxEzARBgNVBAMMCnNzby51a20ubXkxHTAbBgkqhkiG9w0BCQEWDmJwZEBwdG0udWttLm15MB4XDTE0MDQyMTA0MDI0N1oXDTI0MDQyMDA0MDI0N1owgbQxCzAJBgNVBAYTAk1ZMREwDwYDVQQIDAhTRUxBTkdPUjESMBAGA1UEBwwJVUtNIEJBTkdJMScwJQYDVQQKDB5VTklWRVJTSVRJIEtFQkFOR1NBQU4gTUFMQVlTSUExITAfBgNVBAsMGFBVU0FUIFRFS05PTE9HSSBNQUtMVU1BVDETMBEGA1UEAwwKc3NvLnVrbS5teTEdMBsGCSqGSIb3DQEJARYOYnBkQHB0bS51a20ubXkwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCuMCOPbkaT1fBOoKCLjDtMCFs2QXNIZn6n6OmRW+HOAv3HQGzK27wOtaXeR419HGrldA0VQCx6YPCsPRGgls6i5a6Sp3ifZgPW1hS0tKj6ZFLBttD/ilpadyuTr1HeKkxAR8pvFnddV/XskL7uQWU6m1Fhzc/G0dUByXjtmmaJqzjZi6BWxlXn3gmEVzMShrxGoiRlevLC2h4W7t+HQ8nWTTXsSdwCGoNoZgFGRe6SqsVz1dG4ElhgevaENKPj7WzDZAW0BITWO8fLphrv9CACiM02WUaNfZkzvpTmR27Ojfi3zkuJfD5K2wYkxIgItD4i9bEAMf6t4Kh5zRnM3EYLAgMBAAGjUDBOMB0GA1UdDgQWBBQBhNCc8MozDot07auEqlzPIe4sSjAfBgNVHSMEGDAWgBQBhNCc8MozDot07auEqlzPIe4sSjAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBBQUAA4IBAQAGY9PLbm6V1enkYiVH3tDA9yT9tlaTLCbGk7/a6u8PiVwj1wKhB/169gtFnEinkDeTtv+WG+pL+gaQXiWAP2VfOllQf7CiiITfrXZrCsp/O1q5Xk9qGhw3+m/+L3KUEDFcKNlSHQflJtVNx/BskLOVxT+R4YImf8J9qWIu9clokcRXM/POj8O6cMqWKoKAgH3UoPgl9SLaSDIsXHXrUxCS2vvrgj4gR8b+lmSLVfgj9+Xfwili+vTEFZnebIFiTvbmmmaGCq84jMrYu/t5tDpkAnHYJ9YcyXISd3vRm80bzKGc3KyvOF9CKGEIJMHttrxrF7E6n2UKFh6QQfvOwJ35', 'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient', );
Certificates
Download the X509 certificates as PEM-encoded files.