<EntityDescriptor entityID="https://shibbsrv1.gsa.ac.uk/idp/shibboleth"
                  xmlns="urn:oasis:names:tc:SAML:2.0:metadata"
                  xmlns:ds="http://www.w3.org/2000/09/xmldsig#"
                  xmlns:shibmd="urn:mace:shibboleth:metadata:1.0"
                  xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">

    <IDPSSODescriptor protocolSupportEnumeration="urn:mace:shibboleth:1.0 urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">gsa.ac.uk</shibmd:Scope>
        </Extensions>

        <KeyDescriptor>
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>

MIIDWjCCAkICCQCivWPQEvRbljANBgkqhkiG9w0BAQUFADBvMQswCQYDVQQGEwJH
QjEQMA4GA1UECBMHR2xhc2dvdzEXMBUGA1UEBxMOUmVuZnJldyBTdHJlZXQxFzAV
BgNVBAoTDlJlbmZyZXcgU3RyZWV0MRwwGgYDVQQDExNzaGliYnNydjEuZ3NhLmFj
LnVrMB4XDTEzMDQxMDE0Mjc1MloXDTMzMDQwNTE0Mjc1MlowbzELMAkGA1UEBhMC
R0IxEDAOBgNVBAgTB0dsYXNnb3cxFzAVBgNVBAcTDlJlbmZyZXcgU3RyZWV0MRcw
FQYDVQQKEw5SZW5mcmV3IFN0cmVldDEcMBoGA1UEAxMTc2hpYmJzcnYxLmdzYS5h
Yy51azCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMyvtXXL1ZjqGV45
QRqdOrqXaX+trM2srXsh74k8UfivA5QxDAho548YVlcdmnm/d1kSTYSIHzD1IZu0
1HD2X3RehRORQTiejQQl+KfZa3HNwVc96PqkQ3UDmsTLwkzCnKToto3SVqEmflGG
ibj1SUA8kr/4kYmO/EZEIyhDq0dWYlx4iMQGHoUUHUp1FBDFRfOffBjUVyoDGzbM
cZesKVyJLIMuwZdWYm8diYnQggNHw17N0t/FsgKbUnPA1Wj2w5bE2sObR/eGCRv1
/QgiPvuW0qawibwgfdNYr+u6x8ZB9D1CA5xwSAmLhxDxAG8Vn34e/j51doS1ET5U
rR071ccCAwEAATANBgkqhkiG9w0BAQUFAAOCAQEAzBfS3T2zWUe+nCXopLOASUxv
Jzx4WHXsLbuR5I9dA/l1GXdQkgswDwMvSBh+eP6bLe2qncKOys/2QLx2R1g/ata2
dxACjh5t68Aca5xKfxD4Axnyzu2j0aW3CojrR0SlzIAiXEWzQAOwUM9FtEYfrcDc
SauS3ziuUbHzzLufHrnuKOvzyTv/6acMNnlL4JZQPTUtMluzdNxApbsndvYuOty+
yhnJqONwsMlgVqghAmHILD54ZgEsBUX+drhMVu7+Vk0tocvfr5SDmp5yfB2zl2RV
ZAsbj5IQmyAuMRF3AnM7837HCnvjO/89bCjODt286HBAvPgyRFbHiUpruf3F+A==

                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
        
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
                                   Location="https://shibbsrv1.gsa.ac.uk:8443/idp/profile/SAML1/SOAP/ArtifactResolution" 
                                   index="1"/>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"
                                   Location="https://shibbsrv1.gsa.ac.uk:8443/idp/profile/SAML2/SOAP/ArtifactResolution" 
                                   index="2"/>

<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://shibbsrv1.gsa.ac.uk/idp/profile/SAML2/Redirect/SLO"/>
<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://shibbsrv1.gsa.ac.uk/idp/profile/SAML2/POST/SLO"/>
<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://shibbsrv1.gsa.ac.uk:8443/idp/profile/SAML2/SOAP/SLO"/>

                                   
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>

        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" 
                             Location="https://shibbsrv1.gsa.ac.uk/idp/profile/Shibboleth/SSO" />
        
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" 
                             Location="https://shibbsrv1.gsa.ac.uk/idp/profile/SAML2/POST/SSO" />

        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" 
                             Location="https://shibbsrv1.gsa.ac.uk/idp/profile/SAML2/POST-SimpleSign/SSO" />
        
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" 
                             Location="https://shibbsrv1.gsa.ac.uk/idp/profile/SAML2/Redirect/SSO" />
    </IDPSSODescriptor>

    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">gsa.ac.uk</shibmd:Scope>
        </Extensions>

        <KeyDescriptor>
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>

MIIDWjCCAkICCQCivWPQEvRbljANBgkqhkiG9w0BAQUFADBvMQswCQYDVQQGEwJH
QjEQMA4GA1UECBMHR2xhc2dvdzEXMBUGA1UEBxMOUmVuZnJldyBTdHJlZXQxFzAV
BgNVBAoTDlJlbmZyZXcgU3RyZWV0MRwwGgYDVQQDExNzaGliYnNydjEuZ3NhLmFj
LnVrMB4XDTEzMDQxMDE0Mjc1MloXDTMzMDQwNTE0Mjc1MlowbzELMAkGA1UEBhMC
R0IxEDAOBgNVBAgTB0dsYXNnb3cxFzAVBgNVBAcTDlJlbmZyZXcgU3RyZWV0MRcw
FQYDVQQKEw5SZW5mcmV3IFN0cmVldDEcMBoGA1UEAxMTc2hpYmJzcnYxLmdzYS5h
Yy51azCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMyvtXXL1ZjqGV45
QRqdOrqXaX+trM2srXsh74k8UfivA5QxDAho548YVlcdmnm/d1kSTYSIHzD1IZu0
1HD2X3RehRORQTiejQQl+KfZa3HNwVc96PqkQ3UDmsTLwkzCnKToto3SVqEmflGG
ibj1SUA8kr/4kYmO/EZEIyhDq0dWYlx4iMQGHoUUHUp1FBDFRfOffBjUVyoDGzbM
cZesKVyJLIMuwZdWYm8diYnQggNHw17N0t/FsgKbUnPA1Wj2w5bE2sObR/eGCRv1
/QgiPvuW0qawibwgfdNYr+u6x8ZB9D1CA5xwSAmLhxDxAG8Vn34e/j51doS1ET5U
rR071ccCAwEAATANBgkqhkiG9w0BAQUFAAOCAQEAzBfS3T2zWUe+nCXopLOASUxv
Jzx4WHXsLbuR5I9dA/l1GXdQkgswDwMvSBh+eP6bLe2qncKOys/2QLx2R1g/ata2
dxACjh5t68Aca5xKfxD4Axnyzu2j0aW3CojrR0SlzIAiXEWzQAOwUM9FtEYfrcDc
SauS3ziuUbHzzLufHrnuKOvzyTv/6acMNnlL4JZQPTUtMluzdNxApbsndvYuOty+
yhnJqONwsMlgVqghAmHILD54ZgEsBUX+drhMVu7+Vk0tocvfr5SDmp5yfB2zl2RV
ZAsbj5IQmyAuMRF3AnM7837HCnvjO/89bCjODt286HBAvPgyRFbHiUpruf3F+A==

                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" 
                          Location="https://shibbsrv1.gsa.ac.uk:8443/idp/profile/SAML1/SOAP/AttributeQuery" />
        
        <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"
                          Location="https://shibbsrv1.gsa.ac.uk:8443/idp/profile/SAML2/SOAP/AttributeQuery" />
        
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
        
    </AttributeAuthorityDescriptor>

    <!-- SP metadata for SAML proxy -->
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
  
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
MIIDWjCCAkICCQCivWPQEvRbljANBgkqhkiG9w0BAQUFADBvMQswCQYDVQQGEwJH
QjEQMA4GA1UECBMHR2xhc2dvdzEXMBUGA1UEBxMOUmVuZnJldyBTdHJlZXQxFzAV
BgNVBAoTDlJlbmZyZXcgU3RyZWV0MRwwGgYDVQQDExNzaGliYnNydjEuZ3NhLmFj
LnVrMB4XDTEzMDQxMDE0Mjc1MloXDTMzMDQwNTE0Mjc1MlowbzELMAkGA1UEBhMC
R0IxEDAOBgNVBAgTB0dsYXNnb3cxFzAVBgNVBAcTDlJlbmZyZXcgU3RyZWV0MRcw
FQYDVQQKEw5SZW5mcmV3IFN0cmVldDEcMBoGA1UEAxMTc2hpYmJzcnYxLmdzYS5h
Yy51azCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMyvtXXL1ZjqGV45
QRqdOrqXaX+trM2srXsh74k8UfivA5QxDAho548YVlcdmnm/d1kSTYSIHzD1IZu0
1HD2X3RehRORQTiejQQl+KfZa3HNwVc96PqkQ3UDmsTLwkzCnKToto3SVqEmflGG
ibj1SUA8kr/4kYmO/EZEIyhDq0dWYlx4iMQGHoUUHUp1FBDFRfOffBjUVyoDGzbM
cZesKVyJLIMuwZdWYm8diYnQggNHw17N0t/FsgKbUnPA1Wj2w5bE2sObR/eGCRv1
/QgiPvuW0qawibwgfdNYr+u6x8ZB9D1CA5xwSAmLhxDxAG8Vn34e/j51doS1ET5U
rR071ccCAwEAATANBgkqhkiG9w0BAQUFAAOCAQEAzBfS3T2zWUe+nCXopLOASUxv
Jzx4WHXsLbuR5I9dA/l1GXdQkgswDwMvSBh+eP6bLe2qncKOys/2QLx2R1g/ata2
dxACjh5t68Aca5xKfxD4Axnyzu2j0aW3CojrR0SlzIAiXEWzQAOwUM9FtEYfrcDc
SauS3ziuUbHzzLufHrnuKOvzyTv/6acMNnlL4JZQPTUtMluzdNxApbsndvYuOty+
yhnJqONwsMlgVqghAmHILD54ZgEsBUX+drhMVu7+Vk0tocvfr5SDmp5yfB2zl2RV
ZAsbj5IQmyAuMRF3AnM7837HCnvjO/89bCjODt286HBAvPgyRFbHiUpruf3F+A==
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
MIIDWjCCAkICCQCivWPQEvRbljANBgkqhkiG9w0BAQUFADBvMQswCQYDVQQGEwJH
QjEQMA4GA1UECBMHR2xhc2dvdzEXMBUGA1UEBxMOUmVuZnJldyBTdHJlZXQxFzAV
BgNVBAoTDlJlbmZyZXcgU3RyZWV0MRwwGgYDVQQDExNzaGliYnNydjEuZ3NhLmFj
LnVrMB4XDTEzMDQxMDE0Mjc1MloXDTMzMDQwNTE0Mjc1MlowbzELMAkGA1UEBhMC
R0IxEDAOBgNVBAgTB0dsYXNnb3cxFzAVBgNVBAcTDlJlbmZyZXcgU3RyZWV0MRcw
FQYDVQQKEw5SZW5mcmV3IFN0cmVldDEcMBoGA1UEAxMTc2hpYmJzcnYxLmdzYS5h
Yy51azCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMyvtXXL1ZjqGV45
QRqdOrqXaX+trM2srXsh74k8UfivA5QxDAho548YVlcdmnm/d1kSTYSIHzD1IZu0
1HD2X3RehRORQTiejQQl+KfZa3HNwVc96PqkQ3UDmsTLwkzCnKToto3SVqEmflGG
ibj1SUA8kr/4kYmO/EZEIyhDq0dWYlx4iMQGHoUUHUp1FBDFRfOffBjUVyoDGzbM
cZesKVyJLIMuwZdWYm8diYnQggNHw17N0t/FsgKbUnPA1Wj2w5bE2sObR/eGCRv1
/QgiPvuW0qawibwgfdNYr+u6x8ZB9D1CA5xwSAmLhxDxAG8Vn34e/j51doS1ET5U
rR071ccCAwEAATANBgkqhkiG9w0BAQUFAAOCAQEAzBfS3T2zWUe+nCXopLOASUxv
Jzx4WHXsLbuR5I9dA/l1GXdQkgswDwMvSBh+eP6bLe2qncKOys/2QLx2R1g/ata2
dxACjh5t68Aca5xKfxD4Axnyzu2j0aW3CojrR0SlzIAiXEWzQAOwUM9FtEYfrcDc
SauS3ziuUbHzzLufHrnuKOvzyTv/6acMNnlL4JZQPTUtMluzdNxApbsndvYuOty+
yhnJqONwsMlgVqghAmHILD54ZgEsBUX+drhMVu7+Vk0tocvfr5SDmp5yfB2zl2RV
ZAsbj5IQmyAuMRF3AnM7837HCnvjO/89bCjODt286HBAvPgyRFbHiUpruf3F+A==
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
  
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://shibbsrv1.gsa.ac.uk/idp/profile/Authn/SAML2/POST/SSO" index="0"/>
    </SPSSODescriptor>
    
</EntityDescriptor>    
