After publishing your own metadata, you need to identify others within eduGAIN, such as other Identity Providers to allow access to your service. SURFconext provides an aggregate of the metadata of eduGAIN IdPs through SURFconext on this location:

https://metadata.surfconext.nl/edugain-downstream-idp.xml (40+ MB)

It contains all eduGAIN IdPs. This file serves as input for you Service Provider software, so it knows about the available identity providers and for instance to build a Discovery Page where users can select their Identity Provider to be used for logging in. You need to regularly fetch and update this metadata to make sure changes are processed in a timely manner. We recommend to fetch it at least daily.

The metadata can be verified via the HTTPS certificate of metadata.surfconext.nl. If you need to use a certificate to verify the retreived XML after downloading, see the version at https://metadata.surfconext.nl/signed.html. Please make sure you properly verify the above mentioned metadata via either of the two methods.

Using this metadata, you can continue to the next step, Deploy discovery page.