Introduction

This guide describes how to publish SAML metadata in Lösning för federerad åtkomst till Klassa.

This guide is for non-municipal organizations access to Klassa. If you represent a Swedish municipality (kommun), please use this guide instead: Technical Metadata Connection Guide (Fedkom)

Choose the section that matches the entity you want to upload:

Prerequisites

The organization must have signed the membership agreement for federated access to Klassa.

Only entities correctly processed according to this guide are included in the Klassa metadata feed.

Mandatory Entity Attribute 

To be included in the Klassa metadata feed, an entity attribute must be included in metadata. For information about the entity attribute, see the Klassa federation policy.

Metadata validator

A metadata validator for Klassa is available here: https://validator.openfed.se/fedkom. Use it to check that your SAML metadata conforms to the technical profile and federation policy before submitting or publishing it.

Note that metadata opting-in via Skolfederation or Sambi need to follow the Fedkom/Klassa technical profile and policy to be accepted. If you intend to opt-in via one of these federations, please use the validator above as well.

Metadata example

Example metadata for SAML 2.0 Identity Provider and Service Provider are available at the link below.

https://md.openfed.se/metadata-example/

The metadata are conformant to SAML 2.0 WebSSO Technology Profile and the examples show what elements in metadata relate to which requirement from the technology profile.

You want to upload an Identity Provider (IdP)

Edit your metadata

Choose your publication path

A. Not a member of Skolfederation/Sambi

No access to Federationsadmin.

Action

If compliant, the IdP is published in the Klassa metadata feed.

B. Member of Skolfederation/Sambi – manual submission

Use this path if:

Action

If compliant, the IdP is published in the Klassa metadata feed.

C. Member of Skolfederation/Sambi – Via Federationsadmin

Use this path only if the IdP belongs within the scope of Skolfederation or Sambi. If the IdP is not intended to be used to represent users in Skolfederation or Sambi as well, it is NOT permitted to upload it via Federationsadmin.

Action

  1. Edit the metadata locally.

  2. Add the mandatory Klassa entity attribute (see below).

  3. Validate your metadata with the metadata validator and correct your metadata if any errors are present.
  4. Log in to Federationsadmin.

  5. Upload the updated metadata.

Publication flow

Federationsadmin → Skolfederation/Sambi → Klassa metadata feed.

Only correctly marked IdPs are included.

Manual submission instructions

Validate your metadata with the metadata validator and correct your metadata if any errors are present.

Send an email to:

info@svenskafederationer.se

Include:

If the metadata is valid, the federation operator will contact the organization’s Technical Contact to validate the file checksum by phone. After successful validation, the entity is published in the Klassa metadata feed.

Additional steps for access to KLASSA

Publishing your Identity Provider (IdP) in the metadata feed is only one part of enabling access to KLASSA.

You must also configure your IdP for the KLASSA Service Provider (SP) in accordance with Adda’s guidance documents Åtkomstvägledning för KLASSA 5 and Vägledning för administratörer av KLASSA 5. The documents are available on the KLASSA 5 guidance page.