<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" validUntil="2019-10-29T09:01:13.425Z" entityID="https://idp.lab.fi/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">lab.fi</shibmd:Scope>
<!--
    Fill in the details for your IdP here 

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">A Name for the IdP at idp.lab.fi</mdui:DisplayName>
                <mdui:Description xml:lang="en">Enter a description of your IdP at idp.lab.fi</mdui:Description>
                <mdui:Logo height="80" width="80">https://idp.lab.fi/Path/To/Logo.png</mdui:Logo>
            </mdui:UIInfo>
-->
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEEzCCAnugAwIBAgIUayI8wur4qAUfq0r0EaTHnDVo6VYwDQYJKoZIhvcNAQEL
BQAwFTETMBEGA1UEAwwKaWRwLmxhYi5maTAeFw0xOTEwMjkwOTAxMTFaFw0zOTEw
MjkwODAxMTFaMBUxEzARBgNVBAMMCmlkcC5sYWIuZmkwggGiMA0GCSqGSIb3DQEB
AQUAA4IBjwAwggGKAoIBgQCtczJ5ge2TYKHKLa0RzqKgwZunTR0LOlfB23YBU9NF
OB1BbHWALHAh7bPRcf+qb5FDiQd63XbiK6JfQSWx3u3cJdKpSkbpzzY94hABe5LH
6cLzD5xxKKFcdrF+M9Atkll7r+ozzFtGW4PpR/2ZRalGMhlwKvvwHu3l3a4lWf/h
wcSsyw9jYxsdRs96e0CTQ6B3OoX/X8QpE4XQLNR/EEIsm9NWd3sf0yNxaVfMspA7
d+7JNecrO8lbHVDO7PZh9qECDJgIWBBIiAzNACuw7N9YNMLhirgWK7EqDQGVnOMz
33S8tnRbDnSq/Jf0cYdzE4giJpM61s4QlOlOjMRq2xtfw/sQOC/z0sOSYddqVAXv
FxxrBZOEFXtBOVtI5WOFGaTC3Rw2LhsV7pceYpHd21j74v7XwpQJZnGZcwGZV3bp
RvKqw84BZclHb1sBAxkk/ZBx/aC+c4WtxXDbfctnjrA+DemdD/xsqADn7qJ6JZC2
Xa+T+/viiyFvPWFpd0W7Bl0CAwEAAaNbMFkwHQYDVR0OBBYEFNUWIAva3vetc0iX
KFG2aaSXwrPnMDgGA1UdEQQxMC+CCmlkcC5sYWIuZmmGIWh0dHBzOi8vaWRwLmxh
Yi5maS9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAYEAX40VfQaWPa3q
OAXGBJJjn58DmJE+uketcK52+2Y26DPZ2AfrOcb3UhMisMo72XOM/tbt0m8nUefP
JgLbCrD7uSLRe8Jg5s2PexHorVz9ewleX2fAhvkWtfDCkY2QOFN367sqlzrYq7d1
9V+fYqJfeewsn/7yWl/JhBQVgBQZHLCLHBTS4K5auYPOkIFJaphYFs8K5aFZ/wBL
oTEEhLnO4PG8H+xMqqASmqHA6iLHHSq7YK6bcCxxQUQsaDL3UUfnZAWpo+krhjEQ
D+lOkcoCzP/8x8TT20KLJGKs14jfIilYrCSt0H6jDr1AS6915UPcEwh3rw8nC1Z5
lkJPqVBuC2N9GT79eS6y8HrGaSQclojtF5Ps19xVkT6G1JSbnIS26BzDsAVjO0A4
eovPQ1uqJQ+cz09HcOz3KAvnW/gBF2ChSXTLvmr+i7Dj5jmJ8zoBZY1BMgezzJt7
QnoO61jJqOo/vuRkE6CkWbwGSHPwluQvW8LhcAv+dAnXsC2Dhz+R
                         </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.lab.fi:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.lab.fi:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>

        <!--
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.lab.fi/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.lab.fi/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.lab.fi/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.lab.fi:8443/idp/profile/SAML2/SOAP/SLO"/>
        -->

        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.lab.fi/idp/profile/Shibboleth/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://idp.lab.fi/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://idp.lab.fi/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://idp.lab.fi/idp/profile/SAML2/Redirect/SSO"/>

    </IDPSSODescriptor>


    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">lab.fi</shibmd:Scope>
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEEzCCAnugAwIBAgIUayI8wur4qAUfq0r0EaTHnDVo6VYwDQYJKoZIhvcNAQEL
BQAwFTETMBEGA1UEAwwKaWRwLmxhYi5maTAeFw0xOTEwMjkwOTAxMTFaFw0zOTEw
MjkwODAxMTFaMBUxEzARBgNVBAMMCmlkcC5sYWIuZmkwggGiMA0GCSqGSIb3DQEB
AQUAA4IBjwAwggGKAoIBgQCtczJ5ge2TYKHKLa0RzqKgwZunTR0LOlfB23YBU9NF
OB1BbHWALHAh7bPRcf+qb5FDiQd63XbiK6JfQSWx3u3cJdKpSkbpzzY94hABe5LH
6cLzD5xxKKFcdrF+M9Atkll7r+ozzFtGW4PpR/2ZRalGMhlwKvvwHu3l3a4lWf/h
wcSsyw9jYxsdRs96e0CTQ6B3OoX/X8QpE4XQLNR/EEIsm9NWd3sf0yNxaVfMspA7
d+7JNecrO8lbHVDO7PZh9qECDJgIWBBIiAzNACuw7N9YNMLhirgWK7EqDQGVnOMz
33S8tnRbDnSq/Jf0cYdzE4giJpM61s4QlOlOjMRq2xtfw/sQOC/z0sOSYddqVAXv
FxxrBZOEFXtBOVtI5WOFGaTC3Rw2LhsV7pceYpHd21j74v7XwpQJZnGZcwGZV3bp
RvKqw84BZclHb1sBAxkk/ZBx/aC+c4WtxXDbfctnjrA+DemdD/xsqADn7qJ6JZC2
Xa+T+/viiyFvPWFpd0W7Bl0CAwEAAaNbMFkwHQYDVR0OBBYEFNUWIAva3vetc0iX
KFG2aaSXwrPnMDgGA1UdEQQxMC+CCmlkcC5sYWIuZmmGIWh0dHBzOi8vaWRwLmxh
Yi5maS9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAYEAX40VfQaWPa3q
OAXGBJJjn58DmJE+uketcK52+2Y26DPZ2AfrOcb3UhMisMo72XOM/tbt0m8nUefP
JgLbCrD7uSLRe8Jg5s2PexHorVz9ewleX2fAhvkWtfDCkY2QOFN367sqlzrYq7d1
9V+fYqJfeewsn/7yWl/JhBQVgBQZHLCLHBTS4K5auYPOkIFJaphYFs8K5aFZ/wBL
oTEEhLnO4PG8H+xMqqASmqHA6iLHHSq7YK6bcCxxQUQsaDL3UUfnZAWpo+krhjEQ
D+lOkcoCzP/8x8TT20KLJGKs14jfIilYrCSt0H6jDr1AS6915UPcEwh3rw8nC1Z5
lkJPqVBuC2N9GT79eS6y8HrGaSQclojtF5Ps19xVkT6G1JSbnIS26BzDsAVjO0A4
eovPQ1uqJQ+cz09HcOz3KAvnW/gBF2ChSXTLvmr+i7Dj5jmJ8zoBZY1BMgezzJt7
QnoO61jJqOo/vuRkE6CkWbwGSHPwluQvW8LhcAv+dAnXsC2Dhz+R
                         </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.lab.fi:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
        <!-- <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.lab.fi:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> -->
        <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->

    </AttributeAuthorityDescriptor>

</EntityDescriptor>
