You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在PHP中配置应用为SAML SP对接企业集中式IdP

Hey there! Let's tackle your two questions about setting up SimpleSAMLphp as a Service Provider (SP) for your custom PHP app. I’ve worked through this exact setup multiple times, so here’s a practical breakdown:

1. Redirecting Users to the IdP Login Page & Handling the Return Flow

SimpleSAMLphp handles most of the heavy lifting with generating SAML Requests and managing the authentication flow—you don’t need to manually construct the XML request yourself. Here’s how to implement it:

Step 1: Initialize the SP Authentication Instance

First, make sure you’ve included the SimpleSAMLphp autoloader in your app, then create an instance of the SP auth handler:

require_once '/path/to/simplesamlphp/lib/_autoload.php';
$as = new SimpleSAML\Auth\Simple('default-sp');

(Note: default-sp refers to the SP identifier you’ll define in your SimpleSAMLphp config—more on that in question 2.)

Step 2: Trigger the Authentication Flow

Check if the user is already authenticated. If not, initiate the redirect to the IdP:

if (!$as->isAuthenticated()) {
    // This method automatically generates the SAML AuthnRequest,
    // redirects the user to the IdP's login page, and handles the return
    $as->requireAuth();
    // Execution stops here until the user returns from the IdP
}

When you call requireAuth(), SimpleSAMLphp does all the work:

  • It generates a valid SAML 2.0 AuthnRequest XML (signed if you configured certificates)
  • It wraps this request in an HTML form and auto-submits it to the IdP’s Single Sign-On (SSO) endpoint (pulled from the IdP’s metadata you imported)

Step 3: Handle the Return from IdP

Once the user authenticates successfully, the IdP sends a SAML Response to your SP’s Assertion Consumer Service (ACS) endpoint (configured in your SP metadata). SimpleSAMLphp automatically processes this response:

  • Validates the signature and assertion
  • Establishes a session for the user in your app
  • Redirects the user back to the page they initiated the login from (or a default URL you specify)

To access the user’s attributes (like email, username) after authentication, use:

$userAttributes = $as->getAttributes();
// Example: Get the user's email
$userEmail = $userAttributes['email'][0];

2. Configuring SimpleSAMLphp Only as a Service Provider

Disabling the IdP functionality and focusing solely on SP setup is straightforward—just tweak a few config files:

Step 1: Disable IdP Functionality

Edit simplesamlphp/config/config.php and set the following to turn off IdP capabilities:

'enable.saml20-idp' => false,
'enable.shib13-idp' => false, // If you don't need Shibboleth 1.3 support

Step 2: Define Your SP in Auth Sources

Open simplesamlphp/config/authsources.php and add your SP configuration. Here’s a template to adapt:

'default-sp' => [
    'saml:SP',
    // Unique identifier for your SP (should match the entityID in your metadata)
    'entityID' => 'https://your-app-domain.com/simplesaml/module.php/saml/sp/metadata.php/default-sp',
    // The entityID of your IdP (from the metadata they provided)
    'idp' => 'https://your-idp-domain.com/idp/shibboleth',
    // Path to your SP's private key (for signing requests)
    'privatekey' => 'sp.pem',
    // Path to your SP's public certificate (shared with IdP)
    'certificate' => 'sp.crt',
    // ACS endpoint URL (where IdP sends responses)
    'assertionConsumerService' => [
        'url' => 'https://your-app-domain.com/simplesaml/module.php/saml/sp/saml2-acs.php/default-sp',
    ],
    // Optional: Single Logout Service endpoint
    'singleLogoutService' => [
        'url' => 'https://your-app-domain.com/simplesaml/module.php/saml/sp/saml2-logout.php/default-sp',
    ],
],

Step 3: Import the IdP Metadata

You need to tell SimpleSAMLphp about your IdP’s configuration. The IdP should have provided you a metadata XML file. You can:

  • Paste the metadata into simplesamlphp/metadata/saml20-idp-remote.php (follow the existing format in that file)
  • Or use the SimpleSAMLphp web interface: navigate to /simplesaml, go to Federation > Add SAML 2.0 IdP metadata, and paste the XML or URL for the IdP’s metadata.

Step 4: Verify SP Configuration

To confirm your SP is set up correctly, visit the SP metadata URL (the entityID value from your config) in a browser. It should display valid XML metadata that you can share with the IdP if needed.


内容的提问来源于stack exchange,提问作者Barry Chapman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 08:56:32