<?xml version="1.0" encoding="UTF-8"?>

<!-- Ansible managed -->

<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" validUntil="2023-02-07T12:55:33.492Z" entityID="https://login.slub-dresden.de/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">slub-dresden.de</shibmd:Scope>
            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">SLUB Dresden IdP</mdui:DisplayName>
                <mdui:DisplayName xml:lang="de">SLUB Dresden IdP</mdui:DisplayName>
                <mdui:Description xml:lang="en">Identity Provider SLUB Dresden</mdui:Description>
                <mdui:Description xml:lang="de">Identity Provider SLUB Dresden</mdui:Description>
                <mdui:Logo height="16" width="16">https://login.slub-dresden.de/idp/images/favicon.ico</mdui:Logo>
                <mdui:Logo height="80" width="80">https://login.slub-dresden.de/idp/images/logo.png</mdui:Logo>
                <mdui:InformationURL xml:lang="de">https://www.slub-dresden.de</mdui:InformationURL>
                <mdui:InformationURL xml:lang="en">https://www.slub-dresden.de</mdui:InformationURL>
                <mdui:PrivacyStatementURL xml:lang="de">https://www.slub-dresden.de/datenschutzerklaerung</mdui:PrivacyStatementURL>
            </mdui:UIInfo>
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
                        /opt/shibboleth-idp/credentials/login-saml.crt
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>

        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
                        /opt/shibboleth-idp/credentials/login-saml.crt
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://login.slub-dresden.de:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>

        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://login.slub-dresden.de/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://login.slub-dresden.de/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://login.slub-dresden.de/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://login.slub-dresden.de:8443/idp/profile/SAML2/SOAP/SLO"/>

        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://login.slub-dresden.de/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://login.slub-dresden.de/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://login.slub-dresden.de/idp/profile/SAML2/Redirect/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://login.slub-dresden.de/idp/profile/SAML2/SOAP/ECP"/>

    </IDPSSODescriptor>

    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">slub-dresden.de</shibmd:Scope>
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
                        /opt/shibboleth-idp/credentials/login-saml.crt
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>

        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
                        /opt/shibboleth-idp/credentials/login-saml.crt
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://login.slub-dresden.de:8443/idp/profile/SAML2/SOAP/AttributeQuery"/>

    </AttributeAuthorityDescriptor>

    <ContactPerson contactType="administrative">
      <GivenName>Falk</GivenName>
      <SurName>Niederlein</SurName>
      <EmailAddress>falk.niederlein@slub-dresden.de</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
      <GivenName>Falk</GivenName>
      <SurName>Niederlein</SurName>
      <EmailAddress>falk.niederlein@slub-dresden.de</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="support">
      <GivenName>Falk</GivenName>
      <SurName>Niederlein</SurName>
      <EmailAddress>falk.niederlein@slub-dresden.de</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security">
      <GivenName>Falk</GivenName>
      <SurName>Niederlein</SurName>
      <EmailAddress>falk.niederlein@slub-dresden.de</EmailAddress>
    </ContactPerson>

</EntityDescriptor>
