Warning | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
| ||||||||||
We have exciting news! An updated InCommon Federation wiki is now available. Please visit the new InCommon Federation Library for updated content. This wiki is preserved for historical records only. It will no longer be updated. We invite you to come check out the new Library. Don't forget to update your bookmarks accordingly.
|
Metadata Administration
This page is for site administrators responsible for creating and maintaining SAML metadata on behalf of their organization. For a high-level overview of InCommon Federation metadata, please visit our web site.
Web Interface
The metadata submitted by the site administrator is vetted and approved by the InCommon Registration Authority (RA). Since the SAML protocol depends on the proper use of metadata, the RA checks the correctness and integrity of what is submitted by the site administrator. In particular, the RA checks that the entity ID and endpoints in metadata meet certain basic requirements.
InCommon also incorporates metadata administered by other federations. See Interfederation and eduGAIN for more information.
Federation Manager
A web interface called the Federation Manager A web interface is used to administer InCommon metadata. The interface supports both IdP and SP metadata. The elements of each are referenced in the following sections.
For convenience, a sample interface for new IdPs is attached to this wiki page. Likewise a sample interface for new SPs is attached. To actually create metadata for a new IdP or SP, or to edit the metadata for an existing IdP or SP, login to the web interface with the credentials that were issued to you when your organization joined InCommon.
IdP Metadata Elements
Div | ||
---|---|---|
| ||
|
...
The following elements are called out in IdP metadata.
- Entity ID
- Scope
- X.509 Certificates
- User Interface Elements
- Error Handling URL
- SAML Protocol Endpoints
- Contacts
For IdP deployments based on the Shibboleth software, there is valuable information in the Shibboleth wiki regarding metadata for the Shibboleth IdP.
For a discussion of the desirability of registering test IdPs in metadata, see Test IdPs in Metadata.
SP Metadata Elements
Div | ||
---|---|---|
| ||
|
The following elements are called out in SP metadata.
- Entity ID
- X.509 Certificates
- User Interface Elements
- Requested Attributes
- SAML Protocol Endpoints
- Contacts
For SP deployments based on the Shibboleth software, there is valuable information in the Shibboleth wiki regarding metadata for the Shibboleth SP.
...
Attachments |
---|