You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SimpleSAMLPHP配置报错:无法找到saml20-idp-hosted默认元数据实体

问题描述

我有一个2009年基于PHP 5开发的原生PHP项目,需适配PHP 8.2并部署在Cloudways DigitalOcean服务器上。更新SimpleSAMLPHP配置SSO时出现报错:

SimpleSAML\Error\Error: UNHANDLEDEXCEPTION
根因:Exception: Could not find any default metadata entities in set [saml20-idp-hosted] for host [cfgroup.com : cfgroup.com/synovus/third_party/saml/public]

以下是我的配置文件:

1. config/config.php

<?php
  $httpUtils = new \SimpleSAML\Utils\HTTP();
   $config = [
  'baseurlpath' => 'https://cfgroup.com/synovus/third_party/saml/public',

2. saml20-idp-remote.php

$metadata['https://cfgroup.com/synovus/third_party/saml/public'] = array(
'entityid' => 'https://cfgroup.com/synovus/third_party/saml/public',
'SingleSignOnService' =>
    'https://cfgroup.com/synovus/third_party/saml/public/saml2/idp/SSOService.php',
'SingleLogoutService' =>
    'https://cfgroup.com/synovus/third_party/saml/public/saml2/idp/SingleLogoutService.php',);

3. authsources.php

'default-sp' => [
    'saml:SP',
    'entityID' => 'https://cfgroup.com/synovus/third_party/saml/public/saml2/idp/metadata.php',
    'idp' => 'https://cfgroup.com',
    'discoURL' => null,
    'proxymode.passAuthnContextClassRef' => false,
],

测试链接:https://cfgroup.com/synovus/third_party/saml/public/saml2/idp/SSOService.php?spentityid=federate.ipipeline.com:saml2&RelayState=https://formspipe.ipipeline.com/?GAID=7276

third_party目录包含SimpleSAMLPHP库,路径为/synovus/third_party/saml/public/saml2


解决方案

这个错误的核心是SimpleSAMLPHP找不到你的IDP托管元数据配置,当前配置存在几个关键问题,逐一修正即可:

1. 补全saml20-idp-hosted.php配置

报错中提到的saml20-idp-hosted集合是用于定义本地IDP服务的元数据,你目前仅配置了远程IDP(saml20-idp-remote.php),缺少本地IDP的托管配置。

在SimpleSAMLPHP的metadata目录下创建saml20-idp-hosted.php,添加以下内容:

<?php
$metadata['https://cfgroup.com/synovus/third_party/saml/public'] = [
    'host' => '__DEFAULT__', // 标记为默认IDP实体,解决"找不到默认元数据"问题
    'privatekey' => 'server.pem', // 确保cert目录下存在对应私钥文件
    'certificate' => 'server.crt', // 对应公钥证书文件
    'SingleSignOnService' => [
        'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect' => 'https://cfgroup.com/synovus/third_party/saml/public/saml2/idp/SSOService.php',
    ],
    'SingleLogoutService' => [
        'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect' => 'https://cfgroup.com/synovus/third_party/saml/public/saml2/idp/SingleLogoutService.php',
    ],
    'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient',
];

提示:如果没有server.pem和server.crt,可以用OpenSSL生成自签名证书,命令如下:

openssl req -x509 -newkey rsa:4096 -keyout server.pem -out server.crt -days 365 -nodes

生成后将文件放入SimpleSAMLPHP的cert目录。

2. 修正authsources.php的错误配置

  • entityID设置错误:SP的entityID是服务提供者的唯一标识,不能指向metadata.php文件,改为专属的SP实体地址
  • idp参数错误:此处应填写远程IDP的entityID(即saml20-idp-remote.php中定义的地址),而非根域名

修正后的配置:

'default-sp' => [
    'saml:SP',
    'entityID' => 'https://cfgroup.com/synovus/third_party/saml/public/sp',
    'idp' => 'https://cfgroup.com/synovus/third_party/saml/public',
    'discoURL' => null,
    'proxymode.passAuthnContextClassRef' => false,
],

3. 完善config.php的必要配置

当前的config.php不完整,需要补全核心配置项,确保SimpleSAMLPHP正常运行:

<?php
$httpUtils = new \SimpleSAML\Utils\HTTP();
$config = [
    'baseurlpath' => 'https://cfgroup.com/synovus/third_party/saml/public/',
    'secretsalt' => 'your-32-character-random-secret-here', // 必须生成随机字符串,用于加密
    'technicalcontact_name' => 'Your Technical Contact',
    'technicalcontact_email' => 'tech@cfgroup.com',
    'timezone' => 'UTC',
    'enable.saml20-idp' => true, // 显式启用SAML 2.0 IDP服务
];

4. PHP 8.2兼容性适配

由于项目从PHP 5升级到8.2,需确保:

  • 使用支持PHP 8.2的SimpleSAMLPHP版本(推荐v2.2.x及以上)
  • 替换项目中废弃的mysql_*函数,改用PDO或mysqli
  • 修复PHP 8.0+严格类型检查导致的错误(比如隐式类型转换、未定义变量)
  • 调整错误处理逻辑,捕获PHP 8.0+抛出的Error异常

验证配置

完成修改后,访问SimpleSAMLPHP管理页面,检查元数据是否正常加载,再测试SSO流程。


内容的提问来源于stack exchange,提问作者afnan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.25 13:29:53