<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" entityID="https://idp.sruc.ac.uk/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">sruc.ac.uk</shibmd:Scope>
<!--
    Fill in the details for your IdP here 

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">A Name for the IdP at idp.sruc.ac.uk</mdui:DisplayName>
                <mdui:Description xml:lang="en">Enter a description of your IdP at idp.sruc.ac.uk</mdui:Description>
                <mdui:Logo height="80" width="80">https://idp.sruc.ac.uk/Path/To/Logo.png</mdui:Logo>
            </mdui:UIInfo>
-->
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDJDCCAgygAwIBAgIVAMisBG8/pYaTN/dKjE96UJTj0pHnMA0GCSqGSIb3DQEB
BQUAMBkxFzAVBgNVBAMTDmlkcC5zcnVjLmFjLnVrMB4XDTEzMDgxNTE4MzUyMVoX
DTMzMDgxNTE4MzUyMVowGTEXMBUGA1UEAxMOaWRwLnNydWMuYWMudWswggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQChYhV93CUW69tAVZOYdhzRX14Gtm8l
Ca8W4/EWAEqeVvoMT70fMMwCTPxHbSCkoEpk8RAwChzwGSTGJt8/dtyZWr6vmrHs
8TzCIKRPo1wJymIPtONtojdZnERwbEr0brAzIw82QIOidzYueWHpbrYSaxwmaQNR
LKwDIjf/0M7Zkm6t50vxu2XRttrxJ92x31U0P/mQa22DLlQs6gmJFoxO7jPc0gUj
svDsMTZXS6J4oXmnpqLHfGpGtiyGocunHRykIGX1cyxyJngRXVb6VCfnIb06nELH
9s27b9t6/IhWgmH9rCxS522xTuQDe0DKD0YpmMIQK3fHAhF8RaMGcT+PAgMBAAGj
YzBhMEAGA1UdEQQ5MDeCDmlkcC5zcnVjLmFjLnVrhiVodHRwczovL2lkcC5zcnVj
LmFjLnVrL2lkcC9zaGliYm9sZXRoMB0GA1UdDgQWBBTj1x9pT421ZN33j8y2qyC2
z7tEnDANBgkqhkiG9w0BAQUFAAOCAQEAbRG6KPM1cS83t1nTr68n4o+SAawN6IBS
yt0oSw7jL2eWsFZA3xgR3pePSiKdHXYLW3YEpJ+O3nS1Hs6Hz1lM3zwguJRSnJBk
tS/2Mvk/LiS3TecJqawwvZ5M+MHPckzKP/2cZwJum6dZps9U3KuuLEwU3aDt6Ri+
74AWwDm1DVM0AfuSOk+Gjjkh0mgoMCfMS1jFTRwJXxfH13/jq2ODCD7HlvlJ5eGD
Fknd4XDnhT0wz9uDxT1gTsXCRe/DP/Ql8iviaG1f9fENTz7MrcvKawLMqaRQpL6Z
9rbQkno5Y20gWQLAD3AF1pceBNBCO/6G/GCzRkdsGCtVNNXfnnsc3Q==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDJDCCAgygAwIBAgIVAMisBG8/pYaTN/dKjE96UJTj0pHnMA0GCSqGSIb3DQEB
BQUAMBkxFzAVBgNVBAMTDmlkcC5zcnVjLmFjLnVrMB4XDTEzMDgxNTE4MzUyMVoX
DTMzMDgxNTE4MzUyMVowGTEXMBUGA1UEAxMOaWRwLnNydWMuYWMudWswggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQChYhV93CUW69tAVZOYdhzRX14Gtm8l
Ca8W4/EWAEqeVvoMT70fMMwCTPxHbSCkoEpk8RAwChzwGSTGJt8/dtyZWr6vmrHs
8TzCIKRPo1wJymIPtONtojdZnERwbEr0brAzIw82QIOidzYueWHpbrYSaxwmaQNR
LKwDIjf/0M7Zkm6t50vxu2XRttrxJ92x31U0P/mQa22DLlQs6gmJFoxO7jPc0gUj
svDsMTZXS6J4oXmnpqLHfGpGtiyGocunHRykIGX1cyxyJngRXVb6VCfnIb06nELH
9s27b9t6/IhWgmH9rCxS522xTuQDe0DKD0YpmMIQK3fHAhF8RaMGcT+PAgMBAAGj
YzBhMEAGA1UdEQQ5MDeCDmlkcC5zcnVjLmFjLnVrhiVodHRwczovL2lkcC5zcnVj
LmFjLnVrL2lkcC9zaGliYm9sZXRoMB0GA1UdDgQWBBTj1x9pT421ZN33j8y2qyC2
z7tEnDANBgkqhkiG9w0BAQUFAAOCAQEAbRG6KPM1cS83t1nTr68n4o+SAawN6IBS
yt0oSw7jL2eWsFZA3xgR3pePSiKdHXYLW3YEpJ+O3nS1Hs6Hz1lM3zwguJRSnJBk
tS/2Mvk/LiS3TecJqawwvZ5M+MHPckzKP/2cZwJum6dZps9U3KuuLEwU3aDt6Ri+
74AWwDm1DVM0AfuSOk+Gjjkh0mgoMCfMS1jFTRwJXxfH13/jq2ODCD7HlvlJ5eGD
Fknd4XDnhT0wz9uDxT1gTsXCRe/DP/Ql8iviaG1f9fENTz7MrcvKawLMqaRQpL6Z
9rbQkno5Y20gWQLAD3AF1pceBNBCO/6G/GCzRkdsGCtVNNXfnnsc3Q==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDJDCCAgygAwIBAgIVAMisBG8/pYaTN/dKjE96UJTj0pHnMA0GCSqGSIb3DQEB
BQUAMBkxFzAVBgNVBAMTDmlkcC5zcnVjLmFjLnVrMB4XDTEzMDgxNTE4MzUyMVoX
DTMzMDgxNTE4MzUyMVowGTEXMBUGA1UEAxMOaWRwLnNydWMuYWMudWswggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQChYhV93CUW69tAVZOYdhzRX14Gtm8l
Ca8W4/EWAEqeVvoMT70fMMwCTPxHbSCkoEpk8RAwChzwGSTGJt8/dtyZWr6vmrHs
8TzCIKRPo1wJymIPtONtojdZnERwbEr0brAzIw82QIOidzYueWHpbrYSaxwmaQNR
LKwDIjf/0M7Zkm6t50vxu2XRttrxJ92x31U0P/mQa22DLlQs6gmJFoxO7jPc0gUj
svDsMTZXS6J4oXmnpqLHfGpGtiyGocunHRykIGX1cyxyJngRXVb6VCfnIb06nELH
9s27b9t6/IhWgmH9rCxS522xTuQDe0DKD0YpmMIQK3fHAhF8RaMGcT+PAgMBAAGj
YzBhMEAGA1UdEQQ5MDeCDmlkcC5zcnVjLmFjLnVrhiVodHRwczovL2lkcC5zcnVj
LmFjLnVrL2lkcC9zaGliYm9sZXRoMB0GA1UdDgQWBBTj1x9pT421ZN33j8y2qyC2
z7tEnDANBgkqhkiG9w0BAQUFAAOCAQEAbRG6KPM1cS83t1nTr68n4o+SAawN6IBS
yt0oSw7jL2eWsFZA3xgR3pePSiKdHXYLW3YEpJ+O3nS1Hs6Hz1lM3zwguJRSnJBk
tS/2Mvk/LiS3TecJqawwvZ5M+MHPckzKP/2cZwJum6dZps9U3KuuLEwU3aDt6Ri+
74AWwDm1DVM0AfuSOk+Gjjkh0mgoMCfMS1jFTRwJXxfH13/jq2ODCD7HlvlJ5eGD
Fknd4XDnhT0wz9uDxT1gTsXCRe/DP/Ql8iviaG1f9fENTz7MrcvKawLMqaRQpL6Z
9rbQkno5Y20gWQLAD3AF1pceBNBCO/6G/GCzRkdsGCtVNNXfnnsc3Q==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.sruc.ac.uk:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.sruc.ac.uk:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>

        <!--
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.sruc.ac.uk/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.sruc.ac.uk/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.sruc.ac.uk:8443/idp/profile/SAML2/SOAP/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.sruc.ac.uk/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        -->

        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.sruc.ac.uk/idp/profile/Shibboleth/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://idp.sruc.ac.uk/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://idp.sruc.ac.uk/idp/profile/SAML2/Redirect/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://idp.sruc.ac.uk/idp/profile/SAML2/POST/SSO"/>

    </IDPSSODescriptor>


    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">sruc.ac.uk</shibmd:Scope>
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDJDCCAgygAwIBAgIVAMisBG8/pYaTN/dKjE96UJTj0pHnMA0GCSqGSIb3DQEB
BQUAMBkxFzAVBgNVBAMTDmlkcC5zcnVjLmFjLnVrMB4XDTEzMDgxNTE4MzUyMVoX
DTMzMDgxNTE4MzUyMVowGTEXMBUGA1UEAxMOaWRwLnNydWMuYWMudWswggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQChYhV93CUW69tAVZOYdhzRX14Gtm8l
Ca8W4/EWAEqeVvoMT70fMMwCTPxHbSCkoEpk8RAwChzwGSTGJt8/dtyZWr6vmrHs
8TzCIKRPo1wJymIPtONtojdZnERwbEr0brAzIw82QIOidzYueWHpbrYSaxwmaQNR
LKwDIjf/0M7Zkm6t50vxu2XRttrxJ92x31U0P/mQa22DLlQs6gmJFoxO7jPc0gUj
svDsMTZXS6J4oXmnpqLHfGpGtiyGocunHRykIGX1cyxyJngRXVb6VCfnIb06nELH
9s27b9t6/IhWgmH9rCxS522xTuQDe0DKD0YpmMIQK3fHAhF8RaMGcT+PAgMBAAGj
YzBhMEAGA1UdEQQ5MDeCDmlkcC5zcnVjLmFjLnVrhiVodHRwczovL2lkcC5zcnVj
LmFjLnVrL2lkcC9zaGliYm9sZXRoMB0GA1UdDgQWBBTj1x9pT421ZN33j8y2qyC2
z7tEnDANBgkqhkiG9w0BAQUFAAOCAQEAbRG6KPM1cS83t1nTr68n4o+SAawN6IBS
yt0oSw7jL2eWsFZA3xgR3pePSiKdHXYLW3YEpJ+O3nS1Hs6Hz1lM3zwguJRSnJBk
tS/2Mvk/LiS3TecJqawwvZ5M+MHPckzKP/2cZwJum6dZps9U3KuuLEwU3aDt6Ri+
74AWwDm1DVM0AfuSOk+Gjjkh0mgoMCfMS1jFTRwJXxfH13/jq2ODCD7HlvlJ5eGD
Fknd4XDnhT0wz9uDxT1gTsXCRe/DP/Ql8iviaG1f9fENTz7MrcvKawLMqaRQpL6Z
9rbQkno5Y20gWQLAD3AF1pceBNBCO/6G/GCzRkdsGCtVNNXfnnsc3Q==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDJDCCAgygAwIBAgIVAMisBG8/pYaTN/dKjE96UJTj0pHnMA0GCSqGSIb3DQEB
BQUAMBkxFzAVBgNVBAMTDmlkcC5zcnVjLmFjLnVrMB4XDTEzMDgxNTE4MzUyMVoX
DTMzMDgxNTE4MzUyMVowGTEXMBUGA1UEAxMOaWRwLnNydWMuYWMudWswggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQChYhV93CUW69tAVZOYdhzRX14Gtm8l
Ca8W4/EWAEqeVvoMT70fMMwCTPxHbSCkoEpk8RAwChzwGSTGJt8/dtyZWr6vmrHs
8TzCIKRPo1wJymIPtONtojdZnERwbEr0brAzIw82QIOidzYueWHpbrYSaxwmaQNR
LKwDIjf/0M7Zkm6t50vxu2XRttrxJ92x31U0P/mQa22DLlQs6gmJFoxO7jPc0gUj
svDsMTZXS6J4oXmnpqLHfGpGtiyGocunHRykIGX1cyxyJngRXVb6VCfnIb06nELH
9s27b9t6/IhWgmH9rCxS522xTuQDe0DKD0YpmMIQK3fHAhF8RaMGcT+PAgMBAAGj
YzBhMEAGA1UdEQQ5MDeCDmlkcC5zcnVjLmFjLnVrhiVodHRwczovL2lkcC5zcnVj
LmFjLnVrL2lkcC9zaGliYm9sZXRoMB0GA1UdDgQWBBTj1x9pT421ZN33j8y2qyC2
z7tEnDANBgkqhkiG9w0BAQUFAAOCAQEAbRG6KPM1cS83t1nTr68n4o+SAawN6IBS
yt0oSw7jL2eWsFZA3xgR3pePSiKdHXYLW3YEpJ+O3nS1Hs6Hz1lM3zwguJRSnJBk
tS/2Mvk/LiS3TecJqawwvZ5M+MHPckzKP/2cZwJum6dZps9U3KuuLEwU3aDt6Ri+
74AWwDm1DVM0AfuSOk+Gjjkh0mgoMCfMS1jFTRwJXxfH13/jq2ODCD7HlvlJ5eGD
Fknd4XDnhT0wz9uDxT1gTsXCRe/DP/Ql8iviaG1f9fENTz7MrcvKawLMqaRQpL6Z
9rbQkno5Y20gWQLAD3AF1pceBNBCO/6G/GCzRkdsGCtVNNXfnnsc3Q==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDJDCCAgygAwIBAgIVAMisBG8/pYaTN/dKjE96UJTj0pHnMA0GCSqGSIb3DQEB
BQUAMBkxFzAVBgNVBAMTDmlkcC5zcnVjLmFjLnVrMB4XDTEzMDgxNTE4MzUyMVoX
DTMzMDgxNTE4MzUyMVowGTEXMBUGA1UEAxMOaWRwLnNydWMuYWMudWswggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQChYhV93CUW69tAVZOYdhzRX14Gtm8l
Ca8W4/EWAEqeVvoMT70fMMwCTPxHbSCkoEpk8RAwChzwGSTGJt8/dtyZWr6vmrHs
8TzCIKRPo1wJymIPtONtojdZnERwbEr0brAzIw82QIOidzYueWHpbrYSaxwmaQNR
LKwDIjf/0M7Zkm6t50vxu2XRttrxJ92x31U0P/mQa22DLlQs6gmJFoxO7jPc0gUj
svDsMTZXS6J4oXmnpqLHfGpGtiyGocunHRykIGX1cyxyJngRXVb6VCfnIb06nELH
9s27b9t6/IhWgmH9rCxS522xTuQDe0DKD0YpmMIQK3fHAhF8RaMGcT+PAgMBAAGj
YzBhMEAGA1UdEQQ5MDeCDmlkcC5zcnVjLmFjLnVrhiVodHRwczovL2lkcC5zcnVj
LmFjLnVrL2lkcC9zaGliYm9sZXRoMB0GA1UdDgQWBBTj1x9pT421ZN33j8y2qyC2
z7tEnDANBgkqhkiG9w0BAQUFAAOCAQEAbRG6KPM1cS83t1nTr68n4o+SAawN6IBS
yt0oSw7jL2eWsFZA3xgR3pePSiKdHXYLW3YEpJ+O3nS1Hs6Hz1lM3zwguJRSnJBk
tS/2Mvk/LiS3TecJqawwvZ5M+MHPckzKP/2cZwJum6dZps9U3KuuLEwU3aDt6Ri+
74AWwDm1DVM0AfuSOk+Gjjkh0mgoMCfMS1jFTRwJXxfH13/jq2ODCD7HlvlJ5eGD
Fknd4XDnhT0wz9uDxT1gTsXCRe/DP/Ql8iviaG1f9fENTz7MrcvKawLMqaRQpL6Z
9rbQkno5Y20gWQLAD3AF1pceBNBCO/6G/GCzRkdsGCtVNNXfnnsc3Q==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.sruc.ac.uk:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
        <!-- <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.sruc.ac.uk:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> -->
        <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->

    </AttributeAuthorityDescriptor>

    <!-- SP metadata for SAML proxy -->
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
  
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
MIIDJDCCAgygAwIBAgIVAMisBG8/pYaTN/dKjE96UJTj0pHnMA0GCSqGSIb3DQEB
BQUAMBkxFzAVBgNVBAMTDmlkcC5zcnVjLmFjLnVrMB4XDTEzMDgxNTE4MzUyMVoX
DTMzMDgxNTE4MzUyMVowGTEXMBUGA1UEAxMOaWRwLnNydWMuYWMudWswggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQChYhV93CUW69tAVZOYdhzRX14Gtm8l
Ca8W4/EWAEqeVvoMT70fMMwCTPxHbSCkoEpk8RAwChzwGSTGJt8/dtyZWr6vmrHs
8TzCIKRPo1wJymIPtONtojdZnERwbEr0brAzIw82QIOidzYueWHpbrYSaxwmaQNR
LKwDIjf/0M7Zkm6t50vxu2XRttrxJ92x31U0P/mQa22DLlQs6gmJFoxO7jPc0gUj
svDsMTZXS6J4oXmnpqLHfGpGtiyGocunHRykIGX1cyxyJngRXVb6VCfnIb06nELH
9s27b9t6/IhWgmH9rCxS522xTuQDe0DKD0YpmMIQK3fHAhF8RaMGcT+PAgMBAAGj
YzBhMEAGA1UdEQQ5MDeCDmlkcC5zcnVjLmFjLnVrhiVodHRwczovL2lkcC5zcnVj
LmFjLnVrL2lkcC9zaGliYm9sZXRoMB0GA1UdDgQWBBTj1x9pT421ZN33j8y2qyC2
z7tEnDANBgkqhkiG9w0BAQUFAAOCAQEAbRG6KPM1cS83t1nTr68n4o+SAawN6IBS
yt0oSw7jL2eWsFZA3xgR3pePSiKdHXYLW3YEpJ+O3nS1Hs6Hz1lM3zwguJRSnJBk
tS/2Mvk/LiS3TecJqawwvZ5M+MHPckzKP/2cZwJum6dZps9U3KuuLEwU3aDt6Ri+
74AWwDm1DVM0AfuSOk+Gjjkh0mgoMCfMS1jFTRwJXxfH13/jq2ODCD7HlvlJ5eGD
Fknd4XDnhT0wz9uDxT1gTsXCRe/DP/Ql8iviaG1f9fENTz7MrcvKawLMqaRQpL6Z
9rbQkno5Y20gWQLAD3AF1pceBNBCO/6G/GCzRkdsGCtVNNXfnnsc3Q==
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
MIIDJDCCAgygAwIBAgIVAMisBG8/pYaTN/dKjE96UJTj0pHnMA0GCSqGSIb3DQEB
BQUAMBkxFzAVBgNVBAMTDmlkcC5zcnVjLmFjLnVrMB4XDTEzMDgxNTE4MzUyMVoX
DTMzMDgxNTE4MzUyMVowGTEXMBUGA1UEAxMOaWRwLnNydWMuYWMudWswggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQChYhV93CUW69tAVZOYdhzRX14Gtm8l
Ca8W4/EWAEqeVvoMT70fMMwCTPxHbSCkoEpk8RAwChzwGSTGJt8/dtyZWr6vmrHs
8TzCIKRPo1wJymIPtONtojdZnERwbEr0brAzIw82QIOidzYueWHpbrYSaxwmaQNR
LKwDIjf/0M7Zkm6t50vxu2XRttrxJ92x31U0P/mQa22DLlQs6gmJFoxO7jPc0gUj
svDsMTZXS6J4oXmnpqLHfGpGtiyGocunHRykIGX1cyxyJngRXVb6VCfnIb06nELH
9s27b9t6/IhWgmH9rCxS522xTuQDe0DKD0YpmMIQK3fHAhF8RaMGcT+PAgMBAAGj
YzBhMEAGA1UdEQQ5MDeCDmlkcC5zcnVjLmFjLnVrhiVodHRwczovL2lkcC5zcnVj
LmFjLnVrL2lkcC9zaGliYm9sZXRoMB0GA1UdDgQWBBTj1x9pT421ZN33j8y2qyC2
z7tEnDANBgkqhkiG9w0BAQUFAAOCAQEAbRG6KPM1cS83t1nTr68n4o+SAawN6IBS
yt0oSw7jL2eWsFZA3xgR3pePSiKdHXYLW3YEpJ+O3nS1Hs6Hz1lM3zwguJRSnJBk
tS/2Mvk/LiS3TecJqawwvZ5M+MHPckzKP/2cZwJum6dZps9U3KuuLEwU3aDt6Ri+
74AWwDm1DVM0AfuSOk+Gjjkh0mgoMCfMS1jFTRwJXxfH13/jq2ODCD7HlvlJ5eGD
Fknd4XDnhT0wz9uDxT1gTsXCRe/DP/Ql8iviaG1f9fENTz7MrcvKawLMqaRQpL6Z
9rbQkno5Y20gWQLAD3AF1pceBNBCO/6G/GCzRkdsGCtVNNXfnnsc3Q==
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
  
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.sruc.ac.uk/idp/profile/Authn/SAML2/POST/SSO" index="0"/>
    </SPSSODescriptor>

</EntityDescriptor>
