SAML 2.0 IdP Metadata

Here is the metadata that SimpleSAMLphp has generated for you. You may send this metadata document to trusted partners to setup a trusted federation.

You can get the metadata xml on a dedicated URL:

https://ssp.cs.uchicago.edu/simplesaml/saml2/idp/metadata.php

Metadata

In SAML 2.0 Metadata XML format:

<?xml version="1.0"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://ssp.cs.uchicago.edu/simplesaml/saml2/idp/metadata.php">
  <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
    <md:KeyDescriptor use="signing">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:X509Data>
          <ds:X509Certificate>MIIFJTCCA42gAwIBAgIUHvx2wGXfT6d/+j93gE9fWXMh1KkwDQYJKoZIhvcNAQELBQAwgaExCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhJbGxpbm9pczEQMA4GA1UEBwwHQ2hpY2FnbzEiMCAGA1UECgwZVGhlIFVuaXZlcnNpdHkgb2YgQ2hpY2FnbzErMCkGA1UECwwiVGhlIERlcGFydG1lbnQgb2YgQ29tcHV0ZXIgU2NpZW5jZTEcMBoGA1UEAwwTc3NwLmNzLnVjaGljYWdvLmVkdTAeFw0yMjAyMTkwMTQyNTZaFw0zMjAyMTkwMTQyNTZaMIGhMQswCQYDVQQGEwJVUzERMA8GA1UECAwISWxsaW5vaXMxEDAOBgNVBAcMB0NoaWNhZ28xIjAgBgNVBAoMGVRoZSBVbml2ZXJzaXR5IG9mIENoaWNhZ28xKzApBgNVBAsMIlRoZSBEZXBhcnRtZW50IG9mIENvbXB1dGVyIFNjaWVuY2UxHDAaBgNVBAMME3NzcC5jcy51Y2hpY2Fnby5lZHUwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQDTl/bNBi3YiUWXacfQ5BPqrGLXGyVYTLQRzkR0/xG2R00dR3/LKRumwwDLRYBXKTD/pY+wUOaHLYYXpvphSkp5owXlOOZqCnaTU5nhY7IqaYm/B1n/LwSqolJYFgWJ5odW9Dq9E3qxgSlyPw6nVWhE8Q43lmZy6msC5k20apooDX3xqTN/aGpcvpFZoBU5ALOPPSiJYSHSif8Y+YeE3UhPELB5Yd+c6b3JO0cdL+2fg1ILUp5SZmaRhWNtFbw5i98QahWt6ElpJ4JwF9/l0D2T7Kuuqh93YtsSPRPJ14HYUoE8hBPaUgAqwI8LhP+J99Bqg1Zj9JmIlV3x2bQshNj/HhFuykLYuTLXZ+2O26p+s/52oW1lLr9AjhnVeCfMN4mnoC9Pgtimhd9ThXE0JnEqpUJOFxQek2MFtFmSWdDDW6GSRVryEdtO5ydoge6GisGKuevRmrxoRxp8kCO42GZIPFzMJAuRuwOykoW22dn7d3raLUEaahIKLmNicZg7AEsCAwEAAaNTMFEwHQYDVR0OBBYEFHHeMHV7ca1xOoOQGils5wDawL1KMB8GA1UdIwQYMBaAFHHeMHV7ca1xOoOQGils5wDawL1KMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggGBAMTEPLLc/8lP8dh/d71ntPrwTN1t8lv2vcG/m1xWxJHgiBICvM8Opb4wj7Q4DATN4IFNXDRNMALsm9dluSNgV/JD5yp0hbTvYTIwfkh+ne5/LnfWtdH44JknKxFwU0AalnCHQrAU8BrwM2qi8br2OgLo2Ut2w0D1/E0LxI4V89ZUI4OA/epbezV1W/mnp7WYXQhIl43+pp9BI0qqs3F0AVA7uGNGQzDkvlgXr8yo6G/ka7PY5tBkddyxmJ29dtAce7UV8GaJfjIgjYfOUjglzVzICFhZPGsdeotBpYlAQNrS4Lw+S6+SYeRH976/DU+6VjfmCLERYCN2a6nKJUSSeDqCePp+JZ70Z4Nmf9mrslekx2jRBagx9NhIXCLcbRH/EyVJs1cxZNgErEvMYe1bkO6P4Q2zV4XNTS506GcdXe4Ky/Fhg6DOzHciZwDugHqJF/a1h5PDRB5Pw52fNTJEkL0Ld5Uu9Tfzrscv/pDaE7NrzwoSHF+XxDRZhijAlK55bQ==</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:KeyDescriptor use="encryption">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:X509Data>
          <ds:X509Certificate>MIIFJTCCA42gAwIBAgIUHvx2wGXfT6d/+j93gE9fWXMh1KkwDQYJKoZIhvcNAQELBQAwgaExCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhJbGxpbm9pczEQMA4GA1UEBwwHQ2hpY2FnbzEiMCAGA1UECgwZVGhlIFVuaXZlcnNpdHkgb2YgQ2hpY2FnbzErMCkGA1UECwwiVGhlIERlcGFydG1lbnQgb2YgQ29tcHV0ZXIgU2NpZW5jZTEcMBoGA1UEAwwTc3NwLmNzLnVjaGljYWdvLmVkdTAeFw0yMjAyMTkwMTQyNTZaFw0zMjAyMTkwMTQyNTZaMIGhMQswCQYDVQQGEwJVUzERMA8GA1UECAwISWxsaW5vaXMxEDAOBgNVBAcMB0NoaWNhZ28xIjAgBgNVBAoMGVRoZSBVbml2ZXJzaXR5IG9mIENoaWNhZ28xKzApBgNVBAsMIlRoZSBEZXBhcnRtZW50IG9mIENvbXB1dGVyIFNjaWVuY2UxHDAaBgNVBAMME3NzcC5jcy51Y2hpY2Fnby5lZHUwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQDTl/bNBi3YiUWXacfQ5BPqrGLXGyVYTLQRzkR0/xG2R00dR3/LKRumwwDLRYBXKTD/pY+wUOaHLYYXpvphSkp5owXlOOZqCnaTU5nhY7IqaYm/B1n/LwSqolJYFgWJ5odW9Dq9E3qxgSlyPw6nVWhE8Q43lmZy6msC5k20apooDX3xqTN/aGpcvpFZoBU5ALOPPSiJYSHSif8Y+YeE3UhPELB5Yd+c6b3JO0cdL+2fg1ILUp5SZmaRhWNtFbw5i98QahWt6ElpJ4JwF9/l0D2T7Kuuqh93YtsSPRPJ14HYUoE8hBPaUgAqwI8LhP+J99Bqg1Zj9JmIlV3x2bQshNj/HhFuykLYuTLXZ+2O26p+s/52oW1lLr9AjhnVeCfMN4mnoC9Pgtimhd9ThXE0JnEqpUJOFxQek2MFtFmSWdDDW6GSRVryEdtO5ydoge6GisGKuevRmrxoRxp8kCO42GZIPFzMJAuRuwOykoW22dn7d3raLUEaahIKLmNicZg7AEsCAwEAAaNTMFEwHQYDVR0OBBYEFHHeMHV7ca1xOoOQGils5wDawL1KMB8GA1UdIwQYMBaAFHHeMHV7ca1xOoOQGils5wDawL1KMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggGBAMTEPLLc/8lP8dh/d71ntPrwTN1t8lv2vcG/m1xWxJHgiBICvM8Opb4wj7Q4DATN4IFNXDRNMALsm9dluSNgV/JD5yp0hbTvYTIwfkh+ne5/LnfWtdH44JknKxFwU0AalnCHQrAU8BrwM2qi8br2OgLo2Ut2w0D1/E0LxI4V89ZUI4OA/epbezV1W/mnp7WYXQhIl43+pp9BI0qqs3F0AVA7uGNGQzDkvlgXr8yo6G/ka7PY5tBkddyxmJ29dtAce7UV8GaJfjIgjYfOUjglzVzICFhZPGsdeotBpYlAQNrS4Lw+S6+SYeRH976/DU+6VjfmCLERYCN2a6nKJUSSeDqCePp+JZ70Z4Nmf9mrslekx2jRBagx9NhIXCLcbRH/EyVJs1cxZNgErEvMYe1bkO6P4Q2zV4XNTS506GcdXe4Ky/Fhg6DOzHciZwDugHqJF/a1h5PDRB5Pw52fNTJEkL0Ld5Uu9Tfzrscv/pDaE7NrzwoSHF+XxDRZhijAlK55bQ==</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://ssp.cs.uchicago.edu/simplesaml/saml2/idp/SingleLogoutService.php"/>
    <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:attrname-format:uri</md:NameIDFormat>
    <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://ssp.cs.uchicago.edu/simplesaml/saml2/idp/SSOService.php"/>
  </md:IDPSSODescriptor>
  <md:ContactPerson contactType="technical">
    <md:GivenName>CS</md:GivenName>
    <md:SurName>Techstaff</md:SurName>
    <md:EmailAddress>mailto:chudler@cs.uchicago.edu</md:EmailAddress>
  </md:ContactPerson>
</md:EntityDescriptor>

In SimpleSAMLphp flat file format - use this if you are using a SimpleSAMLphp entity on the other side:

$metadata['https://ssp.cs.uchicago.edu/simplesaml/saml2/idp/metadata.php'] = [
    'metadata-set' => 'saml20-idp-remote',
    'entityid' => 'https://ssp.cs.uchicago.edu/simplesaml/saml2/idp/metadata.php',
    'SingleSignOnService' => [
        [
            'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST',
            'Location' => 'https://ssp.cs.uchicago.edu/simplesaml/saml2/idp/SSOService.php',
        ],
    ],
    'SingleLogoutService' => [
        [
            'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
            'Location' => 'https://ssp.cs.uchicago.edu/simplesaml/saml2/idp/SingleLogoutService.php',
        ],
    ],
    'certData' => 'MIIFJTCCA42gAwIBAgIUHvx2wGXfT6d/+j93gE9fWXMh1KkwDQYJKoZIhvcNAQELBQAwgaExCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhJbGxpbm9pczEQMA4GA1UEBwwHQ2hpY2FnbzEiMCAGA1UECgwZVGhlIFVuaXZlcnNpdHkgb2YgQ2hpY2FnbzErMCkGA1UECwwiVGhlIERlcGFydG1lbnQgb2YgQ29tcHV0ZXIgU2NpZW5jZTEcMBoGA1UEAwwTc3NwLmNzLnVjaGljYWdvLmVkdTAeFw0yMjAyMTkwMTQyNTZaFw0zMjAyMTkwMTQyNTZaMIGhMQswCQYDVQQGEwJVUzERMA8GA1UECAwISWxsaW5vaXMxEDAOBgNVBAcMB0NoaWNhZ28xIjAgBgNVBAoMGVRoZSBVbml2ZXJzaXR5IG9mIENoaWNhZ28xKzApBgNVBAsMIlRoZSBEZXBhcnRtZW50IG9mIENvbXB1dGVyIFNjaWVuY2UxHDAaBgNVBAMME3NzcC5jcy51Y2hpY2Fnby5lZHUwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQDTl/bNBi3YiUWXacfQ5BPqrGLXGyVYTLQRzkR0/xG2R00dR3/LKRumwwDLRYBXKTD/pY+wUOaHLYYXpvphSkp5owXlOOZqCnaTU5nhY7IqaYm/B1n/LwSqolJYFgWJ5odW9Dq9E3qxgSlyPw6nVWhE8Q43lmZy6msC5k20apooDX3xqTN/aGpcvpFZoBU5ALOPPSiJYSHSif8Y+YeE3UhPELB5Yd+c6b3JO0cdL+2fg1ILUp5SZmaRhWNtFbw5i98QahWt6ElpJ4JwF9/l0D2T7Kuuqh93YtsSPRPJ14HYUoE8hBPaUgAqwI8LhP+J99Bqg1Zj9JmIlV3x2bQshNj/HhFuykLYuTLXZ+2O26p+s/52oW1lLr9AjhnVeCfMN4mnoC9Pgtimhd9ThXE0JnEqpUJOFxQek2MFtFmSWdDDW6GSRVryEdtO5ydoge6GisGKuevRmrxoRxp8kCO42GZIPFzMJAuRuwOykoW22dn7d3raLUEaahIKLmNicZg7AEsCAwEAAaNTMFEwHQYDVR0OBBYEFHHeMHV7ca1xOoOQGils5wDawL1KMB8GA1UdIwQYMBaAFHHeMHV7ca1xOoOQGils5wDawL1KMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggGBAMTEPLLc/8lP8dh/d71ntPrwTN1t8lv2vcG/m1xWxJHgiBICvM8Opb4wj7Q4DATN4IFNXDRNMALsm9dluSNgV/JD5yp0hbTvYTIwfkh+ne5/LnfWtdH44JknKxFwU0AalnCHQrAU8BrwM2qi8br2OgLo2Ut2w0D1/E0LxI4V89ZUI4OA/epbezV1W/mnp7WYXQhIl43+pp9BI0qqs3F0AVA7uGNGQzDkvlgXr8yo6G/ka7PY5tBkddyxmJ29dtAce7UV8GaJfjIgjYfOUjglzVzICFhZPGsdeotBpYlAQNrS4Lw+S6+SYeRH976/DU+6VjfmCLERYCN2a6nKJUSSeDqCePp+JZ70Z4Nmf9mrslekx2jRBagx9NhIXCLcbRH/EyVJs1cxZNgErEvMYe1bkO6P4Q2zV4XNTS506GcdXe4Ky/Fhg6DOzHciZwDugHqJF/a1h5PDRB5Pw52fNTJEkL0Ld5Uu9Tfzrscv/pDaE7NrzwoSHF+XxDRZhijAlK55bQ==',
    'NameIDFormat' => [
        'urn:oasis:names:tc:SAML:2.0:attrname-format:uri',
    ],
    'contacts' => [
        [
            'emailAddress' => 'chudler@cs.uchicago.edu',
            'contactType' => 'technical',
            'givenName' => 'CS',
            'surName' => 'Techstaff',
        ],
    ],
];

Certificates

Download the X509 certificates as PEM-encoded files.