Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

ArtifactResponse

Das Beispiel zeigt die Antowrt auf einen gültigen ArtifactResolve-Request. Teil der ArtifactResolve Ist auch die Assertion, welche im EPD Kontext für nachfolgende Traksationen verwendet wird.

<SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/">
    <SOAP-ENV:Header />
    <SOAP-ENV:Body>
        <samlp:ArtifactResponse xmlns="urn:oasis:names:tc:SAML:2.0:assertion"
            xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
            xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
            ID="ID_9d27e4b7-2b0f-4d84-a161-9f1cc8515844"
            InResponseTo="_e3593cfd37504206ba79fc141b172a1c" IssueInstant="2026-06-29T14:21:02.520Z"
            Version="2.0">
            <saml:Issuer>https://idp.id.hin.ch/auth/realms/hinid-dev</saml:Issuer>
            <dsig:Signature xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
                <dsig:SignedInfo>
                    <dsig:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
                    <dsig:SignatureMethod
                        Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" />
                    <dsig:Reference URI="#ID_9d27e4b7-2b0f-4d84-a161-9f1cc8515844">
                        <dsig:Transforms>
                            <dsig:Transform
                                Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" />
                            <dsig:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
                        </dsig:Transforms>
                        <dsig:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" />
                        <dsig:DigestValue>j/IH+kjlNEjwlvEbGq6oq600uwLjefqPqIz3yvOS0ME=</dsig:DigestValue>
                    </dsig:Reference>
                </dsig:SignedInfo>
                <dsig:SignatureValue>
                    As...Y=
                </dsig:SignatureValue>
                <dsig:KeyInfo>
                    <dsig:KeyName>cSwuXJQqfGWT091-zA3jS5WqjxEMaBa17K34XJdFiXg</dsig:KeyName>
                    <dsig:X509Data>
                        <dsig:X509Certificate>
                        MI...YQ==
                        </dsig:X509Certificate>
                    </dsig:X509Data>
                </dsig:KeyInfo>
            </dsig:Signature>
            <samlp:Status>
                <samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success" />
            </samlp:Status>
            <samlp:Response Destination="https://example.com/"
                ID="ID_95805684-d2ab-435d-a8bc-54afc2b0e4a2"
                InResponseTo="hin-checker-36fe7b82-3623-4855-b2e1-5bf2242980ec"
                IssueInstant="2026-06-29T14:21:02.520Z" Version="2.0">
                <saml:Issuer>https://idp.id.hin.ch/auth/realms/hinid-dev</saml:Issuer>
                <samlp:Status>
                    <samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success" />
                </samlp:Status>
                <saml:Assertion ID="ID_92e35e2f-d105-4748-ad0d-96ba8c9ae7da"
                    IssueInstant="2026-06-29T14:21:02.520Z" Version="2.0">
                    <saml:Issuer>https://idp.id.hin.ch/auth/realms/hinid-dev</saml:Issuer>
                    <dsig:Signature xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
                        <dsig:SignedInfo>
                            <dsig:CanonicalizationMethod
                                Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
                            <dsig:SignatureMethod
                                Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" />
                            <dsig:Reference URI="#ID_92e35e2f-d105-4748-ad0d-96ba8c9ae7da">
                                <dsig:Transforms>
                                    <dsig:Transform
                                        Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" />
                                    <dsig:Transform
                                        Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
                                </dsig:Transforms>
                                <dsig:DigestMethod
                                    Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" />
                                <dsig:DigestValue>ttVspe87LiDCnpohZCCOyV9PpMZZTU1HnIXxvD0P5Sc=</dsig:DigestValue>
                            </dsig:Reference>
                        </dsig:SignedInfo>
                        <dsig:SignatureValue>
                            BPd...r644=
                        </dsig:SignatureValue>
                        <dsig:KeyInfo>
                            <dsig:KeyName>cSwuXJQqfGWT091-zA3jS5WqjxEMaBa17K34XJdFiXg</dsig:KeyName>
                            <dsig:X509Data>
                                <dsig:X509Certificate>
                                    MIII...vRpYQ==
                                </dsig:X509Certificate>
                            </dsig:X509Data>
                        </dsig:KeyInfo>
                    </dsig:Signature>
                    <saml:Subject>
                        <saml:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent">
                            HIN_2bccb1493ea605b4094f6eb85c1a63791bf724b67aadbacb512ab5b023ce0099</saml:NameID>
                        <saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
                            <saml:SubjectConfirmationData
                                InResponseTo="hin-checker-36fe7b82-3623-4855-b2e1-5bf2242980ec"
                                NotOnOrAfter="2026-06-29T14:26:00.520Z"
                                Recipient="https://example.com/" />
                        </saml:SubjectConfirmation>
                    </saml:Subject>
                    <saml:Conditions NotBefore="2026-06-29T14:21:00.520Z"
                        NotOnOrAfter="2026-06-29T14:26:00.520Z">
                        <saml:AudienceRestriction>
                            <saml:Audience>https://example.com/</saml:Audience>
                        </saml:AudienceRestriction>
                    </saml:Conditions>
                    <saml:AuthnStatement AuthnInstant="2026-06-29T14:21:02.520Z"
                        SessionIndex="61f59169-50eb-4d59-a48f-ad14dc007e5a::a821b99b-af11-4df6-bad3-70402386a033"
                        SessionNotOnOrAfter="2026-06-30T06:21:02.520Z">
                        <saml:AuthnContext>
                            <saml:AuthnContextClassRef>
                                urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified</saml:AuthnContextClassRef>
                        </saml:AuthnContext>
                    </saml:AuthnStatement>
                    <saml:AttributeStatement>
                        <saml:Attribute FriendlyName="givenname"
                            Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname"
                            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
                            <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema"
                                xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
                                xsi:type="xs:string">Hans</saml:AttributeValue>
                        </saml:Attribute>
                        <saml:Attribute FriendlyName="Global Location Number" Name="GLN"
                            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
                            <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema"
                                xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
                                xsi:type="xs:string">1245678910</saml:AttributeValue>
                        </saml:Attribute>
                        <saml:Attribute FriendlyName="gender" Name="gender"
                            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified">
                            <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema"
                                xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
                                xsi:type="xs:string">MALE</saml:AttributeValue>
                        </saml:Attribute>
                        <saml:Attribute FriendlyName="dateofbirth" Name="dateofbirth"
                            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified">
                            <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema"
                                xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
                                xsi:type="xs:string">1990-01-01+01:00</saml:AttributeValue>
                        </saml:Attribute>
                        <saml:Attribute FriendlyName="surname"
                            Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname"
                            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
                            <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema"
                                xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
                                xsi:type="xs:string">Mustermann</saml:AttributeValue>
                        </saml:Attribute>
                    </saml:AttributeStatement>
                </saml:Assertion>
            </samlp:Response>
        </samlp:ArtifactResponse>
    </SOAP-ENV:Body>
</SOAP-ENV:Envelope>