Актуальную версию документа см. на сайте Министерства цифрового развития, связи и массовых коммуникаций Российской Федерации по адресу https://digital.gov.ru/ru/documents/6186/.

А.9 Пример AuthnResponse

<?xml version="1.0" encoding="UTF-8"?>

<saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"

ID="_f634a1edd5a52c852641c0943475edd7" IssueInstant="2012-03-01T06:30:00.307Z" Version="2.0"

xmlns:xs="http://www.w3.org/2001/XMLSchema">

<saml2:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">https://esia-

portal1.test.gosuslugi.ru/idp/shibboleth</saml2:Issuer>

<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">

<ds:SignedInfo>

<ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>

<ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>

<ds:Reference URI="#_f634a1edd5a52c852641c0943475edd7">

<ds:Transforms>

<ds:Transform

Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>

<ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#">

<ec:InclusiveNamespaces

xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="xs"/>

</ds:Transform>

</ds:Transforms>

<ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>

<ds:DigestValue>6p7pdI3FulCoSG2kZbGOtW1GCag=</ds:DigestValue>

</ds:Reference>

</ds:SignedInfo>

<ds:SignatureValue>

</ds:SignatureValue>

<ds:KeyInfo>

<ds:X509Data>

<ds:X509Certificate>

</ds:X509Certificate>

</ds:X509Data>

</ds:KeyInfo>

</ds:Signature>

<saml2:Subject>

<saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-

format:transient">_a8e8800fa174f41782184cbbd21ee05f</saml2:NameID>

<saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">

<saml2:SubjectConfirmationData Address="127.0.0.1" InResponseTo="_34efa5b7-47e6-

41bb-b51b-fcb57b7a3f87" NotOnOrAfter="2012-03-01T06:35:00.307Z" Recipient="https://atc-

504:7002/oiosaml/saml/SAMLAssertionConsumer"/>

</saml2:SubjectConfirmation>

</saml2:Subject>

<saml2:Conditions NotBefore="2012-03-01T06:30:00.307Z" NotOnOrAfter="2012-03-01T06:35:00.307Z">

<saml2:AudienceRestriction>

<saml2:Audience>sia_test</saml2:Audience>

</saml2:AudienceRestriction>

</saml2:Conditions>

<saml2:AuthnStatement AuthnInstant="2012-03-01T06:30:00.182Z"

SessionIndex="211f42f443924066aec4d5bc8740bce17a93ba3358d9e7003333db957540116b">

<saml2:SubjectLocality Address="127.0.0.1"/>

<saml2:AuthnContext>

<saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</

saml2:AuthnContextClassRef>

</saml2:AuthnContext>

</saml2:AuthnStatement>

<saml2:AttributeStatement>

<saml2:Attribute FriendlyName="personSNILS" Name="urn:esia:personSNILS"

NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">

<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xsi:type="xs:string">000-000-000 00</saml2:AttributeValue>

</saml2:Attribute>

<saml2:Attribute FriendlyName="userId" Name="urn:mace:dir:attribute:userId"

NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">

<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xsi:type="xs:string">2006101</saml2:AttributeValue>

</saml2:Attribute>

<saml2:Attribute FriendlyName="snils" Name="urn:mace:dir:attribute:snils"

NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">

<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xsi:type="xs:string">000-000-000 00</saml2:AttributeValue>

</saml2:Attribute>

<saml2:Attribute FriendlyName="authnMethod" Name="urn:esia:authnMethod"

NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">

<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xsi:type="xs:string">PWD</saml2:AttributeValue>

</saml2:Attribute>

<saml2:Attribute FriendlyName="principalStatus"

Name="urn:mace:dir:attribute:principalStatus" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-

format:uri">

<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xsi:type="xs:string">A</saml2:AttributeValue>

</saml2:Attribute>

<saml2:Attribute FriendlyName="globalRole" Name="urn:esia:globalRole"

NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">

<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xsi:type="xs:string">P</saml2:AttributeValue>

</saml2:Attribute>

<saml2:Attribute FriendlyName="personEMail" Name="urn:esia:personEMail"

NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">

<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xsi:type="xs:string">sdf@ddd.ru</saml2:AttributeValue>

</saml2:Attribute>

<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xsi:type="xs:string">SNILS</saml2:AttributeValue>

</saml2:Attribute>

<saml2:Attribute FriendlyName="personType" Name="urn:esia:personType"

NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">

<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xsi:type="xs:string">R</saml2:AttributeValue>

</saml2:Attribute>

<saml2:Attribute FriendlyName="authToken" Name="urn:mace:dir:attribute:authToken"

NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">

<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xsi:type="xs:string">b0db6fd1-d674-47bb-8f22-9f8291e59255</saml2:AttributeValue>

</saml2:Attribute>

<saml2:Attribute FriendlyName="userName" Name="urn:esia:userName"

NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">

<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xsi:type="xs:string">000-000-000 00</saml2:AttributeValue>

</saml2:Attribute>

<saml2:Attribute FriendlyName="middleName" Name="urn:mace:dir:attribute:middleName"

NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">

<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xsi:type="xs:string">Дмитриевич</saml2:AttributeValue>

</saml2:Attribute>

<saml2:Attribute FriendlyName="attachedToOrg" Name="urn:esia:attachedToOrg"

NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">

<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xsi:type="xs:string">1</saml2:AttributeValue>

</saml2:Attribute>

<saml2:Attribute FriendlyName="firstName" Name="urn:mace:dir:attribute:firstName"

NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">

<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xsi:type="xs:string">Дмитрий</saml2:AttributeValue>

</saml2:Attribute>

<saml2:Attribute FriendlyName="lastName" Name="urn:mace:dir:attribute:lastName"

NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">

<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xsi:type="xs:string">Дмитриев</saml2:AttributeValue>

</saml2:Attribute>

<saml2:Attribute FriendlyName="portalVersion"

Name="urn:mace:dir:attribute:portalVersion" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-

format:uri">

<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xsi:type="xs:string">P</saml2:AttributeValue>

</saml2:Attribute>

<saml2:Attribute FriendlyName="userType" Name="urn:mace:dir:attribute:userType"

NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">

<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

xsi:type="xs:string">P</saml2:AttributeValue>

</saml2:Attribute>

</saml2:AttributeStatement>

</saml2:Assertion>