如何在SimpleSAMLphp IDP的SubjectConfirmationData中启用Address属性?
解决SimpleSAMLphp IDP中SubjectConfirmationData的Address属性配置问题
要在SimpleSAMLphp生成的SAML断言的SubjectConfirmationData中启用Address属性,只需通过以下两种方式配置:
针对单个SP启用
打开metadata/saml20-sp-remote.php,找到目标SP的配置数组,添加'assertion.address' => true配置项:$metadata['https://target-sp.example.com/saml/metadata'] = [ 'AssertionConsumerService' => 'https://target-sp.example.com/saml/acs', 'SingleLogoutService' => 'https://target-sp.example.com/saml/slo', // 启用SubjectConfirmationData中的Address属性 'assertion.address' => true, ];全局所有SP启用
若要对所有接入的SP生效,修改config/config.php中的saml20.idp配置块,添加对应配置:'saml20.idp' => [ 'entityID' => 'https://your-idp.example.com/saml/idp/metadata', 'privatekey' => 'idp.pem', 'certificate' => 'idp.crt', // 全局启用SubjectConfirmationData中的Address属性 'assertion.address' => true, ];
启用该配置后,SimpleSAMLphp会自动将发起认证请求的客户端IP地址填充到SubjectConfirmationData的<Address>元素中,完全符合SAML规范中对该属性的定义。
内容的提问来源于stack exchange,提问作者Dave Rager
相关产品推荐
相关产品推荐

