<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.
--> 
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" validUntil="2021-10-08T13:51:20.465Z" entityID="https://idp.kh-freiburg.de/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">kh-freiburg.de</shibmd:Scope>

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">Catholic University of Applied Sciences Freiburg</mdui:DisplayName>
                <mdui:DisplayName xml:lang="de">Katholische Hochschule Freiburg</mdui:DisplayName>
                <mdui:Description xml:lang="en">Identity Provider of Catholic University of Applied Sciences Freiburg</mdui:Description>
                <mdui:Description xml:lang="de">Identity Provider der Katholische Hochschule Freiburg</mdui:Description>
                <mdui:Logo height="16" width="16">https://idp.kh-freiburg.de/favicon.ico</mdui:Logo>
                <mdui:Logo height="179" width="144">https://idp.kh-freiburg.de/logo.png</mdui:Logo>
            </mdui:UIInfo>
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel-->


        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIFCDCCAvCgAwIBAgIUbKlOc98oQgpAngtCjbrOzwkM0o0wDQYJKoZIhvcNAQEL
BQAwHTEbMBkGA1UEAxMSaWRwLmtoLWZyZWlidXJnLmRlMB4XDTI1MTAyMTA4MzEx
MFoXDTI5MDEwMzA4MzExMFowHTEbMBkGA1UEAxMSaWRwLmtoLWZyZWlidXJnLmRl
MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAsL1ZC9dnFPY3heg35YOA
TsLBgr2uiJSxyyRDEey/LVQ33ShANxiMzR0G4eXombCmECRH04ydJ1Ft0BtNuOW2
je0mOcI6br9Xe6BBb1EBlwOvhcq+eozvecqoj2OR86fNwV3rEy2AMAmRYeMsGu3Y
D3dYAb/Icz4qBUvlZuhsxdRG/Ov8248ZeU1VqkCPoTE7REXmG6VKWalmKKOjpfKv
PWlyo3Cp5caeyN/KegKiOhmHhreUYT1UQgSxXQFmTFPQQaSm6y8LlYA6iZlEVOdr
j0aT5j2bYXQnpbxS1bZojnKXXAae0ziUgwdbeqLmMl3kL9FoP3hcY786QoFqUZYh
QgcsHlcxEm28J5I6GFZ1cRLVQxHIPKL0vEHeLLBwPAhj2NwqHYf8XfS8hGN6iPb8
9kqJcAPZj/t+w6sS0g7sO7H4sXGj7VN6/ucnHn3LXmqUmWokaIp7ra9JmnzQ39wt
RFncQC7V7f5GDJtNxTml5abQ1Y3OlqVl1PFIL0cU0Eah4f1a9vxqhFLYtODWptb6
/JWcah9z2bFAbbtRn5RH7tT3dQMZphCltstThc1pnWOWullO37ECx0bGksj9R/7P
HTMMDDnc8Rx8tabF79GRr/cEmTPm010JuFLLDylQ+GZMdQdeTofB6rd0dD9WWDZq
jrGAuBX3KAqCpWSbcC8w55cCAwEAAaNAMD4wHQYDVR0RBBYwFIISaWRwLmtoLWZy
ZWlidXJnLmRlMB0GA1UdDgQWBBTWC/TKhUC23z3/o56AM+Dbm/sU0jANBgkqhkiG
9w0BAQsFAAOCAgEAOHa69Tbv+IIqwlCIS9Mh/24kXCWSqwF9q9wFyl6AO7epeUiy
Gfgxin218jvPZkpNln0u56n6san0CDWGPTc8uuYrj3aJ0cK0OW30GFGGnfvg9ufg
BfllNCSmqteglVppzapkGFRwNXPyx58eQsPDu3pq58TKwcQqvINZpW8tM7kUQGNN
zVk0G3PmfF/J8u/KGbIpo2Dmwy0CfpHxDV60f0IMtwC8lk1U6U6dwSB7MMLIrWDL
B8bsvugME7u/JywOWoofoAfKhf8e9i5oUcpU2QsXNkbAoyOsjhTKizhVPOt/4DR/
SiGckHgpkEnkqB7o4bcRuXetkgfDX6Gn9dB6VpsA8wiHchDDKMEaPMftTrRN1GYv
clTXGSf/9pqw0B4qXBsmohNYURWWuI3TU94QyiCj0gvbHjtULRJqenHEfZBHbAKb
gFGpaarblQAHrrmh0Ybfbqhq3yu+zwdXk7gmMk+/z04wiGf733XEFwo8+S6sTRjR
/TEJ2H9tL1xftfDu34KWG80CevAgq+fiX7/3JCpcl0PlMdmYxHZQ4hPlQ1nk0qIR
k8yMKS6wKa+fOeEprvMx3lpc2A2hLfreC9CsRGNuCvbn2yWr0gx5MYdK4gOpGeRG
dz245wSFI52Y5h9INdm6PwAC8w/wo5SRXShanAFcit0QctDsnd5kFjcdc60=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIFCDCCAvCgAwIBAgIUbKlOc98oQgpAngtCjbrOzwkM0o0wDQYJKoZIhvcNAQEL
BQAwHTEbMBkGA1UEAxMSaWRwLmtoLWZyZWlidXJnLmRlMB4XDTI1MTAyMTA4MzEx
MFoXDTI5MDEwMzA4MzExMFowHTEbMBkGA1UEAxMSaWRwLmtoLWZyZWlidXJnLmRl
MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAsL1ZC9dnFPY3heg35YOA
TsLBgr2uiJSxyyRDEey/LVQ33ShANxiMzR0G4eXombCmECRH04ydJ1Ft0BtNuOW2
je0mOcI6br9Xe6BBb1EBlwOvhcq+eozvecqoj2OR86fNwV3rEy2AMAmRYeMsGu3Y
D3dYAb/Icz4qBUvlZuhsxdRG/Ov8248ZeU1VqkCPoTE7REXmG6VKWalmKKOjpfKv
PWlyo3Cp5caeyN/KegKiOhmHhreUYT1UQgSxXQFmTFPQQaSm6y8LlYA6iZlEVOdr
j0aT5j2bYXQnpbxS1bZojnKXXAae0ziUgwdbeqLmMl3kL9FoP3hcY786QoFqUZYh
QgcsHlcxEm28J5I6GFZ1cRLVQxHIPKL0vEHeLLBwPAhj2NwqHYf8XfS8hGN6iPb8
9kqJcAPZj/t+w6sS0g7sO7H4sXGj7VN6/ucnHn3LXmqUmWokaIp7ra9JmnzQ39wt
RFncQC7V7f5GDJtNxTml5abQ1Y3OlqVl1PFIL0cU0Eah4f1a9vxqhFLYtODWptb6
/JWcah9z2bFAbbtRn5RH7tT3dQMZphCltstThc1pnWOWullO37ECx0bGksj9R/7P
HTMMDDnc8Rx8tabF79GRr/cEmTPm010JuFLLDylQ+GZMdQdeTofB6rd0dD9WWDZq
jrGAuBX3KAqCpWSbcC8w55cCAwEAAaNAMD4wHQYDVR0RBBYwFIISaWRwLmtoLWZy
ZWlidXJnLmRlMB0GA1UdDgQWBBTWC/TKhUC23z3/o56AM+Dbm/sU0jANBgkqhkiG
9w0BAQsFAAOCAgEAOHa69Tbv+IIqwlCIS9Mh/24kXCWSqwF9q9wFyl6AO7epeUiy
Gfgxin218jvPZkpNln0u56n6san0CDWGPTc8uuYrj3aJ0cK0OW30GFGGnfvg9ufg
BfllNCSmqteglVppzapkGFRwNXPyx58eQsPDu3pq58TKwcQqvINZpW8tM7kUQGNN
zVk0G3PmfF/J8u/KGbIpo2Dmwy0CfpHxDV60f0IMtwC8lk1U6U6dwSB7MMLIrWDL
B8bsvugME7u/JywOWoofoAfKhf8e9i5oUcpU2QsXNkbAoyOsjhTKizhVPOt/4DR/
SiGckHgpkEnkqB7o4bcRuXetkgfDX6Gn9dB6VpsA8wiHchDDKMEaPMftTrRN1GYv
clTXGSf/9pqw0B4qXBsmohNYURWWuI3TU94QyiCj0gvbHjtULRJqenHEfZBHbAKb
gFGpaarblQAHrrmh0Ybfbqhq3yu+zwdXk7gmMk+/z04wiGf733XEFwo8+S6sTRjR
/TEJ2H9tL1xftfDu34KWG80CevAgq+fiX7/3JCpcl0PlMdmYxHZQ4hPlQ1nk0qIR
k8yMKS6wKa+fOeEprvMx3lpc2A2hLfreC9CsRGNuCvbn2yWr0gx5MYdK4gOpGeRG
dz245wSFI52Y5h9INdm6PwAC8w/wo5SRXShanAFcit0QctDsnd5kFjcdc60=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>


        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.kh-freiburg.de:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>
        <!--<ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.kh-freiburg.de:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
-->

        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.kh-freiburg.de/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.kh-freiburg.de:8443/idp/profile/SAML2/SOAP/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.kh-freiburg.de/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.kh-freiburg.de/idp/profile/SAML2/Redirect/SLO"/>


        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://idp.kh-freiburg.de/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://idp.kh-freiburg.de/idp/profile/SAML2/Redirect/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://idp.kh-freiburg.de/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <!--<SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.kh-freiburg.de/idp/profile/Shibboleth/SSO"/>
-->

        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>









    </IDPSSODescriptor>


</EntityDescriptor>
