Creating a Metadata file for your Service Provider (SP)

tip If you've gotten this far, you have probably already chosen an Entity ID. If you have not, please see the Choosing your Shibboleth Entity ID topic.

What you should have finished so far

tip Before you continue with this page, you should have your shibboleth2.xml file created and configured.

You should also have your application server Apache or IIS configured for shibboleth.

Downloading the Metadata template for your server

When creating your metadata file, it's best to start with the SP generated Metadata and then customize it with your settings. The SP auto-generated metadata file will not work as is. You must customize this.

To get a copy of the file, you can use wget, curl, or a browser. Be sure that you use the protocol (http or https) and server name that browsers will access. The Shibboleth SP uses these values when generating the endpoint URLs in the metadata.

  • Download the generated metadata from apache using wget
    wget -O metadata.xml https://www.servername.umn.edu/Shibboleth.sso/Metadata
  • Download the generated metadata from apache using curl
    curl https://www.servername.umn.edu/Shibboleth.sso/Metadata > metadata.xml
  • From Windows, you'll have to open a web browser, type in the URL in the location bar, and choose File -> Save as... to save the file.
  • warning If this step fails, your application server is not configured properly for shibboleth. Please go back over the installation guides.

Customizing the Metadata file By adding Contact Information

To customize the metadata XML file, add the following information after the <md:SPSSODescriptor> section. Usually this is right before the second to the last line.

NOTE: If your organization contains reserved XML characters such as ampersand (&), greater than (>), or less than (<), be sure to escape them (&amp; &gt; or &lt; respectively).

      <md:OrganizationName xml:lang="en">University of Minnesota, Department of Long Nomenclature</md:OrganizationName> 
      <md:OrganizationDisplayName xml:lang="en">Department of Long Nomenclature</md:OrganizationDisplayName> 
      <md:OrganizationURL xml:lang="en">http://www.dept.umn.edu/</md:OrganizationURL> 
   <md:ContactPerson contactType="support"> 
      <md:GivenName>Authentication Support</md:GivenName> 
   <md:ContactPerson contactType="administrative"> 

If you want to enable the guest account link on the login page, see the UMN IdP documention for Guest Accounts.

Adding additional servers

If you have more than one virtual (or physical) host sharing this entityID, you'll need to add endpoints for the other hostnames or you'll get the dreading Application Configuration Error from the IdP when you try to access them. See AddAdditionalServersToMetadata for details.

Publishing your metadata

tip After you have your metadata file created, you may want to publish it to the Entity ID URL that you chose at the beginning of this process.

Example real live metadata file

You may browse these actual metadata files for reference. They are available here:


They contain examples of additional virtual hosts in a single entityID.

