Both sides previous revision Previous revision Next revision | Previous revision Next revisionBoth sides next revision |
en:metadata [2017/03/13 10:23] – Wolfgang Pempe | en:metadata [2023/02/01 13:54] – [Metadata] Wolfgang Pempe |
---|
====== Metadata ====== | ====== Metadata ====== |
\\ | <callout type="danger" title="Changes Federation Metadata from 20. Mai 2022!"> |
==== Certificate for Signature Validation - DFN-PKI Generation 2 (new)==== | Please note the information on [[en:aai:assurance|the changes concerning the DFN-AAI federation metadata from 20. Mai 2022]]! |
| </callout> |
| <callout type="primary" title="Important Notes"> |
| * These URLs are case-sensitive, i.e. lower case is important! |
| * HTTPS is supported. |
| * Please refer to [[en:production#metadataprovider|this page]] for configuration examples for Shibboleth IdP und SP. |
| </callout> |
| |
The signed metadata of the **DFN-AAI Test Federation:** \\ https://www.aai.dfn.de/fileadmin/metadata/dfn-aai-test-metadata.xml | The signed metadata of the **DFN-AAI Test Federation:** \\ |
| [[http://www.aai.dfn.de/metadata/dfn-aai-test-metadata.xml|http://www.aai.dfn.de/metadata/dfn-aai-test-metadata.xml]] |
| |
The signed metadata of the **DFN-AAI Basic Federation:** (file comprises all DFN-AAI IdPs)\\ https://www.aai.dfn.de/fileadmin/metadata/dfn-aai-basic-metadata.xml | Signed metadata file with all production **Service Providers in DFN-AAI (for IdPs):** \\ |
| [[http://www.aai.dfn.de/metadata/dfn-aai-sp-metadata.xml|http://www.aai.dfn.de/metadata/dfn-aai-sp-metadata.xml]] |
| |
The signed metadata of the **DFN-AAI Advanced Federation:** \\ https://www.aai.dfn.de/fileadmin/metadata/dfn-aai-metadata.xml | Signed metadata file with all production **Identity Providers in DFN-AAI (for SPs):** \\ |
| [[http://www.aai.dfn.de/metadata/dfn-aai-idp-metadata.xml|http://www.aai.dfn.de/metadata/dfn-aai-idp-metadata.xml]] |
| |
Signed metadata file with all **Service Providers in DFN-AAI (for IdPs):** \\ https://www.aai.dfn.de/fileadmin/metadata/dfn-aai-sp-metadata.xml | The signed metadata for participation of **IdPs in [[:de:edugain|eduGAIN]]** (file comprises all SPs available via eduGAIN):\\ |
| [[http://www.aai.dfn.de/metadata/dfn-aai-edugain+sp-metadata.xml|http://www.aai.dfn.de/metadata/dfn-aai-edugain+sp-metadata.xml]] |
| |
The signed metadata for participation of **IdPs in [[https://www.aai.dfn.de/teilnahme/interfederation/|eduGAIN]]** (file comprises all SPs available via eduGAIN): \\ https://www.aai.dfn.de/fileadmin/metadata/dfn-aai-edugain+sp-metadata.xml | The signed metadata for participation of **SPs in [[:de:edugain|eduGAIN]]** (file comprises all IdPs available via eduGAIN):\\ |
| [[http://www.aai.dfn.de/metadata/dfn-aai-edugain+idp-metadata.xml|http://www.aai.dfn.de/metadata/dfn-aai-edugain+idp-metadata.xml]] |
| |
The signed metadata for participation of **SPs in [[https://www.aai.dfn.de/teilnahme/interfederation/|eduGAIN]]** (file comprises all IdPs available via eduGAIN): \\ https://www.aai.dfn.de/fileadmin/metadata/dfn-aai-edugain+idp-metadata.xml | **Local metadata:** [[http://www.aai.dfn.de/metadata/dfn-aai-local-999-metadata.xml|http://www.aai.dfn.de/metadata/dfn-aai-local-999-metadata.xml]] ("999" has to be replaced with an organization-specific number. Please refer to [[:en:metadata_local|Local Metadata]]) |
| |
The **DFN-AAI certificate** (PEM format) for validating the signature(s) of DFN-AAI metadata (SHA256 fingerprint: D4:1A:66:79:E0:2A:05:BF:8A:2C:CA:24:6D:97:C1:CB:29:B8:53:ED:30:D8:C9:70:91:4F:92:E2:70:C2:8D:36): \\ https://www.aai.dfn.de/fileadmin/metadata/dfn-aai.g2.pem | **Certificate for validating the signature(s) of DFN-AAI metadata** (PEM format) \\ |
| SHA256 Fingerprint: 77:2D:24:F6:3F:5F:76:DD:F8:B5:7E:69:59:8D:25:33:BA:99:BB:15:01:CB:6C:B3:5D:A9:1A:85:2E:AB:EE:5F \\ |
| https://www.aai.dfn.de/metadata/dfn-aai.pem |
| |
\\ | <callout type="primary" title="New Certificate for signature validation as of February, 7th, 2023, 14:00 CET"> |
| SHA256 Fingerprint 4D:DA:3F:88:EF:E9:E1:AA:E6:E3:EE:3C:B0:63:8A:ED:51:3C:A8:9A:03:AD:94:96:A2:2E:B5:F1:75:FB:21:48 \\ |
| https://download.aai.dfn.de/tmp/dfn-aai.pem (temporary location) |
| </callout> |
| |
==== Zertifikat zur Signaturvalidierung aus DFN-PKI Generation 1 (alt)==== | ==== Additional Information ==== |
| |
Die signierten Metadaten der **DFN-AAI-Test-Föderation:** \\ https://www.aai.dfn.de/fileadmin/metadata/DFN-AAI-Test-metadata.xml | For configuration examples cf. [[:en:production|'Production Environment']], [[de:shibidp:config-metadata|Shib IdP]] (de) and [[de:shibsp#shibboleth_sp_3x|Shib SP 3.x]] metadata configuration. |
| |
Die signierten Metadaten der **DFN-AAI-Basic-Föderation:** (alle produktiven IdPs enthalten)\\ https://www.aai.dfn.de/fileadmin/metadata/DFN-AAI-Basic-metadata.xml | |
| |
Die signierten Metadaten der **DFN-AAI-Advanced-Föderation:** \\ https://www.aai.dfn.de/fileadmin/metadata/DFN-AAI-metadata.xml | |
| |
Signierter Metadatensatz, der alle **produktiven Service Provider der DFN-AAI enthält (für IdPs):** \\ https://www.aai.dfn.de/fileadmin/metadata/DFN-AAI-sp-metadata.xml | |
| |
Die signierten Metadaten für die Teilnahme von **IdPs in [[https://www.aai.dfn.de/teilnahme/interfederation/|eduGAIN]]** (enthalten die über eduGAIN verfügbaren SPs): \\ https://www.aai.dfn.de/fileadmin/metadata/DFN-AAI-eduGAIN+sp-metadata.xml | |
| |
Die signierten Metadaten für die Teilnahme von **SPs in [[https://www.aai.dfn.de/teilnahme/interfederation/|eduGAIN]]** (enthalten die über eduGAIN verfügbaren IdPs): \\ https://www.aai.dfn.de/fileadmin/metadata/DFN-AAI-eduGAIN+idp-metadata.xml | |
| |
Das **DFN-AAI Zertifikat** im PEM-Format zur Überprüfung der Signatur der DFN-AAI Metadaten (SHA256 Fingerprint: D3:3E:0F:3C:C9:43:1F:A0:0C:14:97:86:30:E3:5F:72:39:56:2C:98:85:69:2D:52:63:1C:86:78:35:90:4F:5C): \\ https://www.aai.dfn.de/fileadmin/metadata/dfn-aai.pem | |
\\ Fingerprint ab 20. März 2017: 7B:44:E1:64:B4:6C:46:7D:82:07:BC:C1:BB:30:B8:64:11:2B:D2:73:09:47:32:CC:B2:20:2E:4A:33:5C:92:64 | |
| |
\\ | |
| |
==== Additional Information ==== | |
| |
Zur Unterscheidung zwischen "Advanced" und "Basic" siehe die Erläuterungen zu den [[https://www.aai.dfn.de/der-dienst/verlaesslichkeitsklassen/|Verlässlichkeitsklassen]], zur Konfiguration vgl. die Anmerkungen und Beispiele unter [[https://www.aai.dfn.de/teilnahme/produktionsbetrieb/|Produktionsbetrieb]]; für [[de:shibidp3config#foederationsmetadaten|Shib IdP 3.x siehe hier]]. | {{tag>lokale-metadaten metadata}} |