<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" validUntil="2019-07-26T13:24:33.608Z" entityID="https://dsi-back-shibboleth-ew1-b01-a/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">icm-institute.org</shibmd:Scope>
<!--
    Fill in the details for your IdP here 

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">A Name for the IdP at dsi-back-shibboleth-ew1-b01-a</mdui:DisplayName>
                <mdui:Description xml:lang="en">Enter a description of your IdP at dsi-back-shibboleth-ew1-b01-a</mdui:Description>
                <mdui:Logo height="80" width="80">https://dsi-back-shibboleth-ew1-b01-a/Path/To/Logo.png</mdui:Logo>
            </mdui:UIInfo>
-->
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDYTCCAkmgAwIBAgIVAKAC5N+LbAxxbxaPoS5rN2nA1Xp1MA0GCSqGSIb3DQEB
CwUAMCgxJjAkBgNVBAMMHWRzaS1iYWNrLXNoaWJib2xldGgtZXcxLWIwMS1hMB4X
DTE5MDcyNjEzMjQzMloXDTM5MDcyNjEzMjQzMlowKDEmMCQGA1UEAwwdZHNpLWJh
Y2stc2hpYmJvbGV0aC1ldzEtYjAxLWEwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
ggEKAoIBAQDVICLfrpf6H3EnDVXww7KxxTgS2FokwyucYXUBJmWlap/QbKST6UKR
b4U50jo6lFL4J8N7Rhg42nKmrmTs5nSc7PRwIHQVrwQyElz6MIM/GslnbH8jEteZ
8d862QBbjMv0a5VHmIIr3NiWBLVzTlwXcEjLv8sTuHvP6lwituhKrCNzqmjQmHEO
gALc9+aHlvWMDzjLSokKnRPz3apoCABPSpyQCo0su3ha4DtKLc9fRODTAu/o0dl0
j+NqImO6qIf1FwecxqYaXH+AauW0cImF12G+pfTKwAAzumrDblu68S36ymZTrp0M
lztCuNXtFonaxpa8dKi9Hy1TY7dF3rXPAgMBAAGjgYEwfzAdBgNVHQ4EFgQUaJME
4Vao7dITTf2vVIadhr9BEkgwXgYDVR0RBFcwVYIdZHNpLWJhY2stc2hpYmJvbGV0
aC1ldzEtYjAxLWGGNGh0dHBzOi8vZHNpLWJhY2stc2hpYmJvbGV0aC1ldzEtYjAx
LWEvaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBAMYjxJkQqC22DB87
px1TXiHpF/Mb0dbj6FhWPwFEoOWXO4cr6K7htw5ejrOj8uyAQQD3niUsUpSdAj2e
h+9uJ4Z6Q4IE/RvV8NdaRreoVOs3Vn/1ASvQj7JlzAF1Yy27ar19MdqIxFPz7Gyj
YBMpBlrBXVo8iYSAMatwUGFAEBR/qeRsiNdRB4aJN9sxiltIErJ8MJKf7hlVLh+F
yJaQQGaW6pHLvqYyt067thQ7K0JRZQ8pOKJ7mIZAMGTenhGFMNRoEZJwdU2Qfbyg
o5kQgYoUr90yJIwY3H+21+Hhzx5clwFFkvv1EECoZY+B1UhKUYuisekOjSt01OPS
B0LKCwc=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDYTCCAkmgAwIBAgIVANbJS1BotR6NcMLHW5QnoZgxcxoCMA0GCSqGSIb3DQEB
CwUAMCgxJjAkBgNVBAMMHWRzaS1iYWNrLXNoaWJib2xldGgtZXcxLWIwMS1hMB4X
DTE5MDcyNjEzMjQzMloXDTM5MDcyNjEzMjQzMlowKDEmMCQGA1UEAwwdZHNpLWJh
Y2stc2hpYmJvbGV0aC1ldzEtYjAxLWEwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
ggEKAoIBAQCVeRPJLfdDeHPHyBqOzHdB17dtYJWgAmONcVxEshbqJjY7tClVOr8p
A0RgpQkvIe2D4tUZ5c+z2d4cbnFORlcBN1ytwmbHPxE+elVrLXzcSwiyKoH3IZ2J
+tZrKN7YYlj69SVlUtsVGuvvCTAMcMysEhilxIq9LhD3JPnPAUajWcNPQy+GKk3e
werYdSTAFBBjQElfFxvXaFLbubx7EjFRJY9sCIYEY51lKF9k4uCECExRECN1KMax
hXsZpbnwxL7XzC9Ow9fHayvA4maLJG+mqxW9bOeVcO8mN34Z5M9OGXWr5IiNVofI
8vaDmt1Uv9omf8+w7ro7N6hGZjam++5rAgMBAAGjgYEwfzAdBgNVHQ4EFgQUNi9N
0wDsy+a4kv7WUFNF+8/WevAwXgYDVR0RBFcwVYIdZHNpLWJhY2stc2hpYmJvbGV0
aC1ldzEtYjAxLWGGNGh0dHBzOi8vZHNpLWJhY2stc2hpYmJvbGV0aC1ldzEtYjAx
LWEvaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBAIT1vEeJLERZg+oi
bUeAWNuc43tRcrG5zi2IRkReJFMiz0+OQvKVYrLU7RiNOXoMnFMbjmmEokYs9Wg/
yhNQUxjOj488C8eZf7NcoNmPuMhiSetMmnXCGdefVhgR7hxzk9MTbMr8+wnkHiR7
qLlHqUQXwt82J1xS3tlu1roVli3VPjEBeHyg1CXLe+MybGWlWktbvYVw56zWbL0M
jOYQjuQFeYidrpsHmVkuDdL/DDrBSeR83WuoJuI2FLwZ7uL/lCBip8zeVI6xvrMo
qf+n+LhEICgT79SE34tgAal8WiM7FUphn4zTo7m4iUICs8nbhBp28OcYMFepklYJ
z7L4w/g=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDYDCCAkigAwIBAgIUHkJjCpGHTOvCOyOw9wtVfTYLKa8wDQYJKoZIhvcNAQEL
BQAwKDEmMCQGA1UEAwwdZHNpLWJhY2stc2hpYmJvbGV0aC1ldzEtYjAxLWEwHhcN
MTkwNzI2MTMyNDMyWhcNMzkwNzI2MTMyNDMyWjAoMSYwJAYDVQQDDB1kc2ktYmFj
ay1zaGliYm9sZXRoLWV3MS1iMDEtYTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCC
AQoCggEBAKS7nP/Glcb7LzlSRSTRWLfM4yRHEB3yv44nBHYJAM/yIfkhlqJpKKhS
cjDimH+5/l4lEybCmE7oc2fJLk6i8Ew7nkzy+CY9B3HCQAcuQ5lYg6PwUbRMzeKL
0a8Dsz2ULZIQ0qpufk3NBI5FZ7JgdBruoRnqBZVaKz9+Vz+n3+RaUJD2LNzxV8XA
Q3vKV6CTyATSjys5QE/x+g9+EZc0eUcDYeaV/AsU47diTweg19Dbcp+SqCn8bpN2
bnfXXBhH/+fQRTC5FS2GLNEwGa0Dag8xN5H8D/Ng36hDdbDdYKHKAdMt5pV6rWV8
cK/Vlz8usUZzglNw2fjxVrdVMljGpIkCAwEAAaOBgTB/MB0GA1UdDgQWBBRO3Stk
roEuYUvJ+PFMlBxP1wjOEjBeBgNVHREEVzBVgh1kc2ktYmFjay1zaGliYm9sZXRo
LWV3MS1iMDEtYYY0aHR0cHM6Ly9kc2ktYmFjay1zaGliYm9sZXRoLWV3MS1iMDEt
YS9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAdXtdV90lNhW6+2vb
DUxDiQ/gdVkV7N5j2M84zmr6e7C687C8se3QTMhkvvNIYk9UvDga7TO1XjlZHZmF
vO8s7kxS/gB5jS5ZZ88BD9VFBHoiQFZ0gXukcMR+7Oy7bZF0sec/LhgngydDvMG6
s9roWIpMDcVNWkD6JKyXpjxjoBaJBBn7vs+T/iUUkgXLCkd2TPlyzCTPKh517kro
VHhkv3F2+f32UvZCHL2pqSaMtiWElTA6YQ0q/yvTmVCRNfC66HywfZOZNRqUgRxH
qgWJiszWV1TV6xIO8n3lD9O7APks5FPvcmuT8HqhYmoyowIW87ie4PZL3s4nllXM
3BTrdg==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://dsi-back-shibboleth-ew1-b01-a:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://dsi-back-shibboleth-ew1-b01-a:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>

        <!--
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://dsi-back-shibboleth-ew1-b01-a/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://dsi-back-shibboleth-ew1-b01-a/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://dsi-back-shibboleth-ew1-b01-a/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://dsi-back-shibboleth-ew1-b01-a:8443/idp/profile/SAML2/SOAP/SLO"/>
        -->

        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://dsi-back-shibboleth-ew1-b01-a/idp/profile/Shibboleth/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://dsi-back-shibboleth-ew1-b01-a/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://dsi-back-shibboleth-ew1-b01-a/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://dsi-back-shibboleth-ew1-b01-a/idp/profile/SAML2/Redirect/SSO"/>

    </IDPSSODescriptor>


    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">icm-institute.org</shibmd:Scope>
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDYTCCAkmgAwIBAgIVAKAC5N+LbAxxbxaPoS5rN2nA1Xp1MA0GCSqGSIb3DQEB
CwUAMCgxJjAkBgNVBAMMHWRzaS1iYWNrLXNoaWJib2xldGgtZXcxLWIwMS1hMB4X
DTE5MDcyNjEzMjQzMloXDTM5MDcyNjEzMjQzMlowKDEmMCQGA1UEAwwdZHNpLWJh
Y2stc2hpYmJvbGV0aC1ldzEtYjAxLWEwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
ggEKAoIBAQDVICLfrpf6H3EnDVXww7KxxTgS2FokwyucYXUBJmWlap/QbKST6UKR
b4U50jo6lFL4J8N7Rhg42nKmrmTs5nSc7PRwIHQVrwQyElz6MIM/GslnbH8jEteZ
8d862QBbjMv0a5VHmIIr3NiWBLVzTlwXcEjLv8sTuHvP6lwituhKrCNzqmjQmHEO
gALc9+aHlvWMDzjLSokKnRPz3apoCABPSpyQCo0su3ha4DtKLc9fRODTAu/o0dl0
j+NqImO6qIf1FwecxqYaXH+AauW0cImF12G+pfTKwAAzumrDblu68S36ymZTrp0M
lztCuNXtFonaxpa8dKi9Hy1TY7dF3rXPAgMBAAGjgYEwfzAdBgNVHQ4EFgQUaJME
4Vao7dITTf2vVIadhr9BEkgwXgYDVR0RBFcwVYIdZHNpLWJhY2stc2hpYmJvbGV0
aC1ldzEtYjAxLWGGNGh0dHBzOi8vZHNpLWJhY2stc2hpYmJvbGV0aC1ldzEtYjAx
LWEvaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBAMYjxJkQqC22DB87
px1TXiHpF/Mb0dbj6FhWPwFEoOWXO4cr6K7htw5ejrOj8uyAQQD3niUsUpSdAj2e
h+9uJ4Z6Q4IE/RvV8NdaRreoVOs3Vn/1ASvQj7JlzAF1Yy27ar19MdqIxFPz7Gyj
YBMpBlrBXVo8iYSAMatwUGFAEBR/qeRsiNdRB4aJN9sxiltIErJ8MJKf7hlVLh+F
yJaQQGaW6pHLvqYyt067thQ7K0JRZQ8pOKJ7mIZAMGTenhGFMNRoEZJwdU2Qfbyg
o5kQgYoUr90yJIwY3H+21+Hhzx5clwFFkvv1EECoZY+B1UhKUYuisekOjSt01OPS
B0LKCwc=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDYTCCAkmgAwIBAgIVANbJS1BotR6NcMLHW5QnoZgxcxoCMA0GCSqGSIb3DQEB
CwUAMCgxJjAkBgNVBAMMHWRzaS1iYWNrLXNoaWJib2xldGgtZXcxLWIwMS1hMB4X
DTE5MDcyNjEzMjQzMloXDTM5MDcyNjEzMjQzMlowKDEmMCQGA1UEAwwdZHNpLWJh
Y2stc2hpYmJvbGV0aC1ldzEtYjAxLWEwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
ggEKAoIBAQCVeRPJLfdDeHPHyBqOzHdB17dtYJWgAmONcVxEshbqJjY7tClVOr8p
A0RgpQkvIe2D4tUZ5c+z2d4cbnFORlcBN1ytwmbHPxE+elVrLXzcSwiyKoH3IZ2J
+tZrKN7YYlj69SVlUtsVGuvvCTAMcMysEhilxIq9LhD3JPnPAUajWcNPQy+GKk3e
werYdSTAFBBjQElfFxvXaFLbubx7EjFRJY9sCIYEY51lKF9k4uCECExRECN1KMax
hXsZpbnwxL7XzC9Ow9fHayvA4maLJG+mqxW9bOeVcO8mN34Z5M9OGXWr5IiNVofI
8vaDmt1Uv9omf8+w7ro7N6hGZjam++5rAgMBAAGjgYEwfzAdBgNVHQ4EFgQUNi9N
0wDsy+a4kv7WUFNF+8/WevAwXgYDVR0RBFcwVYIdZHNpLWJhY2stc2hpYmJvbGV0
aC1ldzEtYjAxLWGGNGh0dHBzOi8vZHNpLWJhY2stc2hpYmJvbGV0aC1ldzEtYjAx
LWEvaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBAIT1vEeJLERZg+oi
bUeAWNuc43tRcrG5zi2IRkReJFMiz0+OQvKVYrLU7RiNOXoMnFMbjmmEokYs9Wg/
yhNQUxjOj488C8eZf7NcoNmPuMhiSetMmnXCGdefVhgR7hxzk9MTbMr8+wnkHiR7
qLlHqUQXwt82J1xS3tlu1roVli3VPjEBeHyg1CXLe+MybGWlWktbvYVw56zWbL0M
jOYQjuQFeYidrpsHmVkuDdL/DDrBSeR83WuoJuI2FLwZ7uL/lCBip8zeVI6xvrMo
qf+n+LhEICgT79SE34tgAal8WiM7FUphn4zTo7m4iUICs8nbhBp28OcYMFepklYJ
z7L4w/g=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDYDCCAkigAwIBAgIUHkJjCpGHTOvCOyOw9wtVfTYLKa8wDQYJKoZIhvcNAQEL
BQAwKDEmMCQGA1UEAwwdZHNpLWJhY2stc2hpYmJvbGV0aC1ldzEtYjAxLWEwHhcN
MTkwNzI2MTMyNDMyWhcNMzkwNzI2MTMyNDMyWjAoMSYwJAYDVQQDDB1kc2ktYmFj
ay1zaGliYm9sZXRoLWV3MS1iMDEtYTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCC
AQoCggEBAKS7nP/Glcb7LzlSRSTRWLfM4yRHEB3yv44nBHYJAM/yIfkhlqJpKKhS
cjDimH+5/l4lEybCmE7oc2fJLk6i8Ew7nkzy+CY9B3HCQAcuQ5lYg6PwUbRMzeKL
0a8Dsz2ULZIQ0qpufk3NBI5FZ7JgdBruoRnqBZVaKz9+Vz+n3+RaUJD2LNzxV8XA
Q3vKV6CTyATSjys5QE/x+g9+EZc0eUcDYeaV/AsU47diTweg19Dbcp+SqCn8bpN2
bnfXXBhH/+fQRTC5FS2GLNEwGa0Dag8xN5H8D/Ng36hDdbDdYKHKAdMt5pV6rWV8
cK/Vlz8usUZzglNw2fjxVrdVMljGpIkCAwEAAaOBgTB/MB0GA1UdDgQWBBRO3Stk
roEuYUvJ+PFMlBxP1wjOEjBeBgNVHREEVzBVgh1kc2ktYmFjay1zaGliYm9sZXRo
LWV3MS1iMDEtYYY0aHR0cHM6Ly9kc2ktYmFjay1zaGliYm9sZXRoLWV3MS1iMDEt
YS9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAdXtdV90lNhW6+2vb
DUxDiQ/gdVkV7N5j2M84zmr6e7C687C8se3QTMhkvvNIYk9UvDga7TO1XjlZHZmF
vO8s7kxS/gB5jS5ZZ88BD9VFBHoiQFZ0gXukcMR+7Oy7bZF0sec/LhgngydDvMG6
s9roWIpMDcVNWkD6JKyXpjxjoBaJBBn7vs+T/iUUkgXLCkd2TPlyzCTPKh517kro
VHhkv3F2+f32UvZCHL2pqSaMtiWElTA6YQ0q/yvTmVCRNfC66HywfZOZNRqUgRxH
qgWJiszWV1TV6xIO8n3lD9O7APks5FPvcmuT8HqhYmoyowIW87ie4PZL3s4nllXM
3BTrdg==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://dsi-back-shibboleth-ew1-b01-a:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
        <!-- <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://dsi-back-shibboleth-ew1-b01-a:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> -->
        <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->

    </AttributeAuthorityDescriptor>

</EntityDescriptor>
