<?xml version="1.0" encoding="UTF-8"?>
<!--
    Ohlone IdP metadata
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" entityID="https://login.ohlone.edu/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">ohlone.edu</shibmd:Scope>

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">Ohlone Identity Provider</mdui:DisplayName>
            </mdui:UIInfo>

        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDKzCCAhOgAwIBAgIUOrkD73hkv7XK9Y/d3vjB1rXpYeYwDQYJKoZIhvcNAQEL
BQAwGzEZMBcGA1UEAwwQbG9naW4ub2hsb25lLmVkdTAeFw0xNjEwMDYxODIzMzha
Fw0zNjEwMDYxODIzMzhaMBsxGTAXBgNVBAMMEGxvZ2luLm9obG9uZS5lZHUwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCGpnVUxxUhh2+yHNXkrFjQQ0XN
UtQnqg123Sjt1xm8RSksdCKo4Ft+u7XthDkfrCrlIkD0zh2W5It5MP/eKc1yLDzB
zAut+nYp5YO+UrIyAs8+aCr97MdZvQURxKwJRedmvCfoBG4xBg1nDvVQMhpJyTqa
Y3arso+XsRIB4+RBwPiTe9CIIM0mT9vk7HQyS+08j/XMBFiXOKkifI7BK8CKunE7
qIJqHGVunkkKNR9FF9bxzGtyKlfEpfs3IiHle2yRaAEOYS/TQ/sEgTWdZ8fujBAo
4Ic0tKfTMZXMAgiqjiB3j6SNUhCfgxkhVZx7ZrwL20jgfR1S6+w9Zwv9XbENAgMB
AAGjZzBlMB0GA1UdDgQWBBRFKj4tei9tx8OrCstip9hrf7WfgDBEBgNVHREEPTA7
ghBsb2dpbi5vaGxvbmUuZWR1hidodHRwczovL2xvZ2luLm9obG9uZS5lZHUvaWRw
L3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBAH/nymqaVQDVEXlslz7fwuho
LtSrkj6XSo4MvgVhXzEVMVKBsx0uQr0TWqq2x21nLiNZFAHDUz0AXeTMGb++ZhNi
nOBu5ND2ttE4+uUlD/8R8HD4Ut4hBEHYcQdzin5N2ODUC9LO/peYnZxPjFcNEh51
pc2GihYSVMp4KZ2j6pP7Lviass4fdH5+BdwHpH0ogDzfB/F+fzrEFlh7UNFM8MSH
hDkbXKSEktrks9b2cjUQzLqEH+wIfcWcfA4WKDJZzZcHrdjSg34720F25VHOhm/F
DFiahVIbaWD9K2Z+2ca+M0VnTy4g4vwq0dfyQxrAlAn8k/mXRyG2kikCdzY6Gvw=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDKzCCAhOgAwIBAgIUAn2v/9G8oLbQaoM3H117mDQGASYwDQYJKoZIhvcNAQEL
BQAwGzEZMBcGA1UEAwwQbG9naW4ub2hsb25lLmVkdTAeFw0xNjEwMDYxODIzMzla
Fw0zNjEwMDYxODIzMzlaMBsxGTAXBgNVBAMMEGxvZ2luLm9obG9uZS5lZHUwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCxCUm5WA8FVoBMFKRqcKw/wV6p
bxu5rpsU6LvMLCndyYpzt8fQu+GLNNwkZ0BGTh0PGjkFsRMYRulbD4wr11BgZK/3
8mAtpQW80ibK3XvcnnRLIgZGY/tPUSNEidi7hhsfWuCIVhFdspUvOmVsnSCbqBnY
myJA+L9JvVsUx4bBjLKhamChIaXfjsblNK8RpJWjIjZPGrnF54WC9/48mQXXwHj7
ERv729A9RqRvv4id6ja7eKoXaIVLWEexf12MmX6CxEvJhf2yFD0GO2Hw6hig+16l
zp44PMPrLkigwjcCJirAu5VJVckt2jm3Ax7rhxRvApNhx79ebZJMHFXlljMLAgMB
AAGjZzBlMB0GA1UdDgQWBBQRtVXq4FQfn18hw3RUJ6pi3IK9MzBEBgNVHREEPTA7
ghBsb2dpbi5vaGxvbmUuZWR1hidodHRwczovL2xvZ2luLm9obG9uZS5lZHUvaWRw
L3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBACIEz0ZYaRfShIgn6vv8aRAp
ZYx6nDRTiRjr10PVC8o4uwvM84DoGhKfGV/10Cbum1bNxJiea5o+sQsRrBQjTP9S
owZ0rf5ZcS1X9s/IAOY424/2q8G3WyL8yxulDokkiC6jQvuXFM+fyiRKeptWZzPf
3AktNY1h0tQ4Zp8RL5V5ugsZXrxTm5nCZ5cr2xAOqfJVHDzqB52h41H6IjfUp2Fo
VJxcaYUwv7N/r6aUXyw4hqmrOTgP/yZax0ObCfyYWiV/0TNIiL75Njtv3T8WbsG8
vyzaZjPGh3zwCKnnbXJjXbDqLalgDLAGtzqnI5PjbkqGBCMwBuy+IV9rC3Mi3no=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <!--
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://login.ohlone.edu/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://login.ohlone.edu/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://login.ohlone.edu/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://login.ohlone.edu:8443/idp/profile/SAML2/SOAP/SLO"/>
        -->

        <!-- Not actually a SAMLv2 Logout endpoint, but it is where we want SPs to send the user for logout if appropriate -->
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://login.ohlone.edu/idp/profile/Logout"/>

        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>

        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://login.ohlone.edu/idp/profile/Shibboleth/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://login.ohlone.edu/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://login.ohlone.edu/idp/profile/SAML2/Redirect/SSO"/>

    </IDPSSODescriptor>

</EntityDescriptor>
