{"id":4412,"date":"2025-03-27T11:42:33","date_gmt":"2025-03-27T11:42:33","guid":{"rendered":"https:\/\/geekmungus.co.uk\/?p=4412"},"modified":"2025-03-27T11:42:34","modified_gmt":"2025-03-27T11:42:34","slug":"verify-fingerprint-of-x509-certificate-from-saml2-xml-metadata","status":"publish","type":"post","link":"https:\/\/geekmungus.co.uk\/?p=4412","title":{"rendered":"Verify Fingerprint of x509 Certificate from SAML2 XML Metadata"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">We needed to determine the &#8220;fingerprint&#8221; of a x509 certificate which was present within SAML2 XML Metadata as part of an update of the metadata during a swap from using Shibboleth IdP as our IdP with using OpenAthens IdP instead.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The body of &lt;X509Certificate> is the DER-encoded data of X509 certificate within the SAML2 XML Metadata.<\/li>\n\n\n\n<li>We want to extract this certificate and obtain the SHA-256 fingerprint of it.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">You&#8217;ll need to have your own source Metadata from which you want to extract the X509 certificate from, but to illustrate here is an example.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\" id=\"VerifyFingerprintofx509CertificatefromSAML2XMLMetadata-Step1-GettheX509Certificate\">Step 1 &#8211; Get the X509 Certificate<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">We want to extract the X509Certificate string (highlighted) below, copy this really long string out.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"329\" src=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/03\/image-18-1024x329.png\" alt=\"\" class=\"wp-image-4413\" srcset=\"https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/03\/image-18-1024x329.png 1024w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/03\/image-18-300x96.png 300w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/03\/image-18-768x247.png 768w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/03\/image-18-1536x494.png 1536w, https:\/\/geekmungus.co.uk\/wp-content\/uploads\/2025\/03\/image-18.png 1900w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h1 class=\"wp-block-heading\" id=\"VerifyFingerprintofx509CertificatefromSAML2XMLMetadata-Step2-AddtheBEGINandENDStatements\">Step 2 &#8211; Add the BEGIN and END Statements<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Paste this really long string into a file, with the extension .crt (as its DER encoded), we&#8217;ll call our file&nbsp;<strong>x509cert.crt<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then add the BEGIN and END statements, these need to be exactly as shown, five hyphens before and after.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>-----BEGIN CERTIFICATE-----\n \n-----END CERTIFICATE-----<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Don&#8217;t worry that its one massive line.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\" id=\"VerifyFingerprintofx509CertificatefromSAML2XMLMetadata-Step3-FoldtheCertificateinto64CharacterBlocks(Optional)\">Step 3 &#8211; Fold the Certificate into 64 Character Blocks (Optional)<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Although you don&#8217;t strictly need to do this for Step 4 and 5 to work, its nice to have a file formatted into a nice certificate block.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>fold -w 64 x509cert.crt >x509cert.pem<\/code><\/pre>\n\n\n\n<h1 class=\"wp-block-heading\" id=\"VerifyFingerprintofx509CertificatefromSAML2XMLMetadata-Step4-GettheInformation(Optional)\">Step 4 &#8211; Get the Information (Optional)<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Run the following command to see the information about the certificate which includes things like the CN, expiry dates and so forth.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>openssl x509 -in x509cert.pem -noout -text<\/code><\/pre>\n\n\n\n<h1 class=\"wp-block-heading\" id=\"VerifyFingerprintofx509CertificatefromSAML2XMLMetadata-Step5-ObtaintheFingerprint\">Step 5 &#8211; Obtain the Fingerprint<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">To get the fingerprint for the certificate using the following command:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>openssl x509 -noout -fingerprint -sha256 -inform pem -in x509cert.pem<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">And we&#8217;ll then get the SHA256 fingerprint for the certificate, something like the following:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sha256 Fingerprint=4A:7A:87:12:E6:CC:DD:28:B0:FF:5F:70:F9:9D:1E:0B:33:EB:D7:F8:59:AB:B3:95:91:EA:63:32:AB:5A:3F:35<\/code><\/pre>\n\n\n\n<h1 class=\"wp-block-heading\" id=\"VerifyFingerprintofx509CertificatefromSAML2XMLMetadata-AdditionalInformation\">Additional Information<\/h1>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/megamorf.gitlab.io\/cheat-sheets\/openssl\/\">https:\/\/megamorf.gitlab.io\/cheat-sheets\/openssl\/<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/community.rsa.com\/s\/article\/How-to-view-a-certificate-fingerprint-as-SHA-256-SHA-1-or-MD5-using-OpenSSL-for-RSA-Authentication-Manager\">https:\/\/community.rsa.com\/s\/article\/How-to-view-a-certificate-fingerprint-as-SHA-256-SHA-1-or-MD5-using-OpenSSL-for-RSA-Authentication-Manager<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/serverfault.com\/questions\/391396\/how-to-split-a-pem-file\">https:\/\/serverfault.com\/questions\/391396\/how-to-split-a-pem-file<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/support.hcl-software.com\/csm?id=kb_article&amp;sysparm_article=KB0109904\">https:\/\/support.hcl-software.com\/csm?id=kb_article&amp;sysparm_article=KB0109904<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>We needed to determine the &#8220;fingerprint&#8221; of a x509 certificate which was present within SAML2 XML Metadata as part of an update of the metadata during a swap from using Shibboleth IdP as our IdP with using OpenAthens IdP instead. You&#8217;ll need to have your own source Metadata from which you want to extract the &#8230; <a title=\"Verify Fingerprint of x509 Certificate from SAML2 XML Metadata\" class=\"read-more\" href=\"https:\/\/geekmungus.co.uk\/?p=4412\" aria-label=\"Read more about Verify Fingerprint of x509 Certificate from SAML2 XML Metadata\">Read more<\/a><\/p>\n","protected":false},"author":4,"featured_media":4415,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[53],"tags":[],"class_list":["post-4412","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-saml"],"_links":{"self":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/4412","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4412"}],"version-history":[{"count":1,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/4412\/revisions"}],"predecessor-version":[{"id":4414,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/4412\/revisions\/4414"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=\/wp\/v2\/media\/4415"}],"wp:attachment":[{"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4412"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4412"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/geekmungus.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4412"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}