keycloak-saml.xml

57 lines | 1.979 kB Blame History Raw Download
<keycloak-saml-adapter xmlns="urn:keycloak:saml:adapter">
    <SP entityID="sp"
        sslPolicy="ssl"
        nameIDPolicyFormat="format"
        forceAuthentication="true"
        isPassive="true">
        <Keys>
            <Key signing="true" >
                <KeyStore file="file" resource="cp" password="pw">
                    <PrivateKey alias="private alias" password="private pw"/>
                    <Certificate alias="cert alias"/>
                </KeyStore>
            </Key>
            <Key encryption="true">
                <PrivateKeyPem>
                    private pem
                </PrivateKeyPem>
                <PublicKeyPem>
                    public pem
                </PublicKeyPem>
            </Key>
        </Keys>
        <PrincipalNameMapping policy="policy" attribute="attribute"/>
        <RoleIdentifiers>
            <Attribute name="member"/>
        </RoleIdentifiers>
        <IDP entityID="idp"
             signatureAlgorithm="RSA"
             signatureCanonicalizationMethod="canon"
             signaturesRequired="true"
                >
            <SingleSignOnService signRequest="true"
                                 validateResponseSignature="true"
                                 requestBinding="post"
                                 bindingUrl="url"
                    />

            <SingleLogoutService
                    validateRequestSignature="true"
                    validateResponseSignature="true"
                    signRequest="true"
                    signResponse="true"
                    requestBinding="redirect"
                    responseBinding="post"
                    postBindingUrl="posturl"
                    redirectBindingUrl="redirecturl"
                    />
            <Keys>
                <Key signing="true">
                    <CertificatePem>
                        cert pem
                    </CertificatePem>
                </Key>
            </Keys>
        </IDP>
    </SP>
</keycloak-saml-adapter>