# Where Do I Find the SAML Metadata of the Identity Federations?

**URL:** <https://forum.clarin.eu/t/where-do-i-find-the-saml-metadata-of-the-identity-federations/417>\
**Category:** Service Provider Federation\
**Created:** [20 August 2024 10:54 UTC](https://forum.clarin.eu/t/where-do-i-find-the-saml-metadata-of-the-identity-federations/417 "2024-08-20T10:54:14Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![alekoe](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.clarin.eu/alekoe/32/4_2.png) [@alekoe](https://forum.clarin.eu/u/alekoe)\
**Post date:** [20 August 2024 10:54 UTC](https://forum.clarin.eu/t/where-do-i-find-the-saml-metadata-of-the-identity-federations/417/1 "2024-08-20T10:54:14Z")

</div>

**Please note:** if you are administering a Service Provider, we recommend to use only 2 metadata sources:

- [The aggregated SPF Identity Providers](https://infra.clarin.eu/aai/prod_md_about_spf_idps.xml) (= all IdPs for all [participating](https://www.clarin.eu/content/participating-consortia) countries)
- [The CLARIN Identity Provider](https://infra.clarin.eu/aai/prod_md_about_clarin_erics_idp.xml)

Alternatively, if you also want to include all eduGAIN IdPs, please use the following 2 sources:

- [The aggregated SPF and eduGAIN Identity Providers](https://infra.clarin.eu/aai/prod_md_about_edugain_idps.xml) (= all IdPs in the world)
- [The CLARIN Identity Provider](https://infra.clarin.eu/aai/prod_md_about_clarin_erics_idp.xml)

If you do so, you can safely ignore all of the information below.

| Identity Federation | Official URL to SAML metadata about IdP(s) | Website with details |
| --- | --- | --- |
| SURFconext (The Netherlands) | (See SURFconext particulars below this table.) | [https://wiki.surfnet.nl/display/surfconextdev/Get+Conexted](https://wiki.surfnet.nl/display/surfconextdev/Get+Conexted) |
| DFN-AAI (Germany) | [https://www.aai.dfn.de/fileadmin/metadata/DFN-AAI-metadata.xml](https://www.aai.dfn.de/fileadmin/metadata/DFN-AAI-metadata.xml) | [https://www.aai.dfn.de/teilnahme/metadaten/](https://www.aai.dfn.de/teilnahme/metadaten/) |
| Haka (Finland) | [https://haka.funet.fi/metadata/haka-metadata.xml](https://haka.funet.fi/metadata/haka-metadata.xml) | [https://confluence.csc.fi/x/9IIUAg](https://confluence.csc.fi/x/9IIUAg) |
| Kalmar Union (Nordic Countries) | [https://kalmar2.org/simplesaml/module.php/aggregator/?id=kalmarcentral2&set=saml2](https://kalmar2.org/simplesaml/module.php/aggregator/?id=kalmarcentral2&set=saml2) | [https://www.kalmar2.org/kalmar2web/tech\_info.html](https://www.kalmar2.org/kalmar2web/tech_info.html) |
| Belnet (Belgium) | [https://federation.belnet.be/federation-metadata.xml](https://federation.belnet.be/federation-metadata.xml) | [http://federation.belnet.be/](http://federation.belnet.be/) |
| eduID.cz (Czech Republic) | [https://metadata.eduid.cz/entities/eduid+idp](https://metadata.eduid.cz/entities/eduid+idp) | [Technical overview [eduID.cz]](http://eduid.cz/en/tech/summary) |
| RCTSaai (Portugal) | [https://rctsaai-rr.fccn.pt/rr/signedmetadata/federation/UkNUU2FhaQ~~/metadata.xml](https://rctsaai-rr.fccn.pt/rr/signedmetadata/federation/UkNUU2FhaQ~~/metadata.xml) | [https://confluence.fccn.pt/display/RCTSAAI/RCTSaai](https://confluence.fccn.pt/display/RCTSAAI/RCTSaai) |
| CLARIN ERIC’s own IdP | [https://infra.clarin.eu/aai/prod\_md\_about\_clarin\_erics\_idp.xml](https://infra.clarin.eu/aai/prod_md_about_clarin_erics_idp.xml) | [CLARIN Identity Provider | CLARIN ERIC](https://www.clarin.eu/content/clarin-identity-provider) |

**SURFconext Particulars**

The following is relevant to Dutch IdPs only (SURFconext).

- To verify whether an SPF production SP is registered with SURFconext, access a URL of the form:
- [https://engine.surfconext.nl/authentication/proxy/idps-metadata?sp-entity-id= **https://ufal-point.mff.cuni.cz/shibboleth/eduid/sp**](https://engine.surfconext.nl/authentication/proxy/idps-metadata?sp-entity-id=https://ufal-point.mff.cuni.cz/shibboleth/eduid/sp)  
_Note that the_ sp-entity-id _parameter’s value (in bold) has be set to the entity ID of your SPF production SP!_
- Because SURFconext is a [hub-and-spoke federation](https://wiki.surfnet.nl/display/surfconextdev/Get+Conexted) only a subset of all Dutch Identity Providers has access to the SPF production SPs.
- To view this subset, one can simply look over the Dutch IdPs in the [CLARIN Discovery Service](http://catalog.clarin.eu/discojuice/idp.html).
- Alternatively, users that have an IdP within SURFconext can check these access rules [here](https://wayf.surfnet.nl/federate/attributes) (requires login).
- We have observed that SURFconext is releasing SAML2 attributes in both the _urn:mace_ and the _urn:oid_ namespaces. If you are mapping these attributes into the same server variable, you have to pay special attention to processing the multi value-server variable.
