Edit WYSIWYGattachfile Attach PDF Raw View►More Actions▼More Actions

Restore topic to revision: You will be able to review the topic before saving it to a new revision

Copy text and form data to a new topic (no attachments will be copied though).
Name of copy:
You will be able to review the copied topic before saving

Rename/move topic... scans links in all public webs (recommended)
Rename/move topic... scans links in ShibAuth web only
Delete topic... scans links in all public webs (recommended)
Delete topic... scans links in ShibAuth web only

Revision Date Username Comment
515 Jul 2014 - 13:12ChristopherBongaartsadd additional servers step 
420 Dec 2011 - 09:48CraigGjerdingen 
315 Dec 2011 - 15:53ChristopherBongaarts 
223 Aug 2011 - 16:02ChristopherBongaartsUse FQDN instead of localhost and HTTPS instead of HTTP for curl/wget examples, and add explanatory note. 
118 Oct 2010 - 12:57AaronZirbes 

Render style:     Context:

 History: r5 < r4 < r3 < r2 < r1
[X] Hide this message.
Notice: On June 30, 2016, UMWiki service will be decommissioned. If you have information in UMWIki that needs to be preserved, you should make plans to move it before that date. Google Sites is anticipated to be the most popular and appropriate alternative for users because it offers a more modern and user-friendly interface and unlimited capacity. To learn more about the features of Google Sites and other alternatives, and to identify which one best fits your needs, see the University’s Website Solution Selection Guide. If you have concerns or would like help regarding this change and your options, please contact Technology Help at help@umn.edu
You are here: UMWiki>ShibAuth Web>ShibbolethMetadataForServiceProviders (15 Jul 2014, ChristopherBongaarts)

Creating a Metadata file for your Service Provider (SP)

tip If you've gotten this far, you have probably already chosen an Entity ID. If you have not, please see the Choosing your Shibboleth Entity ID topic.

What you should have finished so far

tip Before you continue with this page, you should have your shibboleth2.xml file created and configured.

You should also have your application server Apache or IIS configured for shibboleth.

Downloading the Metadata template for your server

When creating your metadata file, it's best to start with the SP generated Metadata and then customize it with your settings. The SP auto-generated metadata file will not work as is. You must customize this.

To get a copy of the file, you can use wget, curl, or a browser. Be sure that you use the protocol (http or https) and server name that browsers will access. The Shibboleth SP uses these values when generating the endpoint URLs in the metadata.

  • Download the generated metadata from apache using wget
    wget -O metadata.xml https://www.servername.umn.edu/Shibboleth.sso/Metadata
  • Download the generated metadata from apache using curl
    curl https://www.servername.umn.edu/Shibboleth.sso/Metadata > metadata.xml
  • From Windows, you'll have to open a web browser, type in the URL in the location bar, and choose File -> Save as... to save the file.
  • warning If this step fails, your application server is not configured properly for shibboleth. Please go back over the installation guides.

Customizing the Metadata file By adding Contact Information

To customize the metadata XML file, add the following information after the <md:SPSSODescriptor> section. Usually this is right before the second to the last line.

NOTE: If your organization contains reserved XML characters such as ampersand (&), greater than (>), or less than (<), be sure to escape them (&amp; &gt; or &lt; respectively).

      <md:OrganizationName xml:lang="en">University of Minnesota, Department of Long Nomenclature</md:OrganizationName> 
      <md:OrganizationDisplayName xml:lang="en">Department of Long Nomenclature</md:OrganizationDisplayName> 
      <md:OrganizationURL xml:lang="en">http://www.dept.umn.edu/</md:OrganizationURL> 
   <md:ContactPerson contactType="support"> 
      <md:GivenName>Authentication Support</md:GivenName> 
   <md:ContactPerson contactType="administrative"> 

If you want to enable the guest account link on the login page, see the UMN IdP documention for Guest Accounts.

Adding additional servers

If you have more than one virtual (or physical) host sharing this entityID, you'll need to add endpoints for the other hostnames or you'll get the dreading Application Configuration Error from the IdP when you try to access them. See AddAdditionalServersToMetadata for details.

Publishing your metadata

tip After you have your metadata file created, you may want to publish it to the Entity ID URL that you chose at the beginning of this process.

Example real live metadata file

You may browse these actual metadata files for reference. They are available here:


They contain examples of additional virtual hosts in a single entityID.

Topic revision: r5 - 15 Jul 2014 - 13:12:36 - ChristopherBongaarts
UMWiki UMWiki
This site is powered by FoswikiCopyright © by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding UMWiki? Send feedback