<?xml version="1.0"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://aai-demo.egi.eu/proxy/module.php/saml/sp/metadata.php/sso">
  <md:Extensions>
    <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
      <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
        <saml:AttributeValue>http://refeds.org/category/research-and-scholarship</saml:AttributeValue>
        <saml:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</saml:AttributeValue>
      </saml:Attribute>
      <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
        <saml:AttributeValue>https://refeds.org/sirtfi</saml:AttributeValue>
      </saml:Attribute>
      <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="urn:oasis:names:tc:SAML:profiles:subject-id:req" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
        <saml:AttributeValue>any</saml:AttributeValue>
      </saml:Attribute>
    </mdattr:EntityAttributes>
  </md:Extensions>
  <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" AuthnRequestsSigned="false" WantAssertionsSigned="false">
    <md:Extensions>
      <mdui:UIInfo xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui">
        <mdui:DisplayName xml:lang="en">EGI Check-in Service (Demo environment)</mdui:DisplayName>
        <mdui:Description xml:lang="en">EGI Check-in Identity and Access Management Service (Demo environment)</mdui:Description>
        <mdui:InformationURL xml:lang="en">https://www.egi.eu/services/check-in/</mdui:InformationURL>
        <mdui:PrivacyStatementURL xml:lang="en">https://aai.egi.eu/privacy/en</mdui:PrivacyStatementURL>
        <mdui:Logo height="152" width="200">https://aai-demo.egi.eu/assets/images/egi-logo-200x152.png</mdui:Logo>
        <mdui:Logo height="16" width="16">https://aai-demo.egi.eu/assets/images/egi-logo-16x16.png</mdui:Logo>
      </mdui:UIInfo>
    </md:Extensions>
    <md:KeyDescriptor use="signing">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:KeyName>43LwDSCKPt2zZuPMDtDmumeWNks-4q_PkcLR2JLNJ0Y</ds:KeyName>
        <ds:X509Data>
          <ds:X509Certificate>MIIFFTCCAv2gAwIBAgIUdd4B2SEPmDanHxdWbuwmGI1sDw8wDQYJKoZIhvcNAQELBQAwGjEYMBYGA1UEAwwPYWFpLWRlbW8uZWdpLmV1MB4XDTI1MDEyOTE0NDg0N1oXDTM1MDEyOTE0NDg0N1owGjEYMBYGA1UEAwwPYWFpLWRlbW8uZWdpLmV1MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEApPwP6vH+H6OwMGOauPjQ0ig+prat1jOxn22Q3eflPDr1FaivYmN7Ejy6KfIdBsEVElhBOAccaXlcSzcpuTf5WUqDgU0PTcTmpAJHQnPOs8Oyx6M0XewDkczR5MUi64tJjRCk5mk9fOLN4lPJpXro+HGafWbn99S+KOaTjIfte01XDasmyYM5MJUyVLe6FdWsdM48OfXXEd20uVAP55elNQQmvKX2CreoJSDfA4o0HPP5OacWNAjhfET4o9z9zQWdKyuLkDI15vjqaNktVtJpsiTo4ebJYn2dzFyH1ulSpgJYXjyPf9RF1BoXfaDwOqhBhQT7P8dUYtsL0MDwSf3MEBfQs7YVVzGSSlHcSLhS+1Nxp51++SyShwupWvyk/iFHLBr+cXTtJCX2Oqy2ZI5zlTWpd+wAZM/QnpNOiPiItHBfVidOlgZ+LW0wbtketbkxgHThVqfCA4xhWGB9/2pLaLPDVCOG6hh9xqzmCpwPXqR9sWRmy9J3hSI2UdtavxWgDzCVi0m+q4rx1bf6m5QdKx9AwS63x2FW60GP3CnZl4X+vBTyNDPwNi9M65vLccl6V7Tb/q2IgKd8xD5YW5GgvV90JI0IgwD0kRadU4wvz3OavC/HkXqAvAlI1f5+i3QFq+wPfRtRsQcpz86QvXsiF3AxdriFBySi83IA8tIwEOECAwEAAaNTMFEwHQYDVR0OBBYEFMlp9SOfsupU2IpY9Qi76ADPrQyyMB8GA1UdIwQYMBaAFMlp9SOfsupU2IpY9Qi76ADPrQyyMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggIBAC/xWIZsfKt/HCIGYGbhIiz7ycd8U7pjPQAfFhL+qk+9SxoPmoghVtHnQD+J5mVc+VRcR1dJ2VPQcCXH7ii/cVJb+2KCYUQMnlqP9RnBmDYriSFawvoD9HEUMMdKMIhgCwBrLAtgHQEqAFpx9XVbDzLlkLeR0efeaLM6ahIaz4LDuhp0y8v20Ap2X4OAVF9f52l8aUWqX9E8uf+/wU+PKb0fLpgDIdzUzbfWvuRBe6zQBeEzHcWeERdKAxMH5zBZ+lkfKej4WeiwaybNvejdgMyihx9EnZVAwCZtTpja695DF6tDnTxG9GwAHyjf9a7Gg6h+eprPRYIb4W86NrRQwjahTng7MrOU7dQS6Gn9GP3tLq9MkuChNgK5/e3Ry/aPztdfkRIg+kfi/5m3BgkCLGOXwcQmM+i10tsY0KgcMHJBAm3/scjptao/cjhhitAyx8zaVXTFDTrgD1PE0YZKRwdk3Xh2cW4wZekMRqiFpLHfFkPSWjogDzCpRsdzv7f8AAwCH3IeELrcUMB2PCoT+iV7rbA3+JlPZUmRQd4nn1+jSxpbMj76/ISPxQXswFg0Sx5HLu6wHUBYcBI1cdaYF89nGnd+iUO4xFIyytJ/svE96HYfUIip35O932KbcCzmhtiJBjo/35eE463Z2mc2VEJm3KmVvHdR+ZbjhgCX7/Jm</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:KeyDescriptor use="encryption">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:KeyName>aj3dQLaYqsiMOSY6fexHVDb1lXyirr_1h9H1h836f4g</ds:KeyName>
        <ds:X509Data>
          <ds:X509Certificate>MIIFFTCCAv2gAwIBAgIUWN5PZ0cCAkzoYyELyTjZmAaSlRcwDQYJKoZIhvcNAQELBQAwGjEYMBYGA1UEAwwPYWFpLWRlbW8uZWdpLmV1MB4XDTI1MDEyOTE0NTMwNFoXDTM1MDEyOTE0NTMwNFowGjEYMBYGA1UEAwwPYWFpLWRlbW8uZWdpLmV1MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAmO+ENYmZZlY/ba3ZA3cYjhMgDvQTDBkcnvpl196OZmQ2sAl4ohjteyk5+EJiLO7Gav8AfmQ+ECPAwPrwlv8QJ7oGE1cwFuenvlEhrWIoGwxTS8XsWp+dLT4YBvkACpHPakNHiql1Qr0Uhlq0gUOS/r7r1G44VTFg+cbCd1IngteSi6rN7toNhJERLlnG6lXEYTgL8W86XydmWnDii/QQN3i98DS9bmVYvTJetpGIBhg3NJjVW04DcAUKROUqA5/N1K5RyMdXWX438HS3ad7PR4FeN+0b7doOyRQZnO/HOBqRj0fRHIc462tG9qB6IFVoz0eJIGBNdN5K+sy7d/jRkw13XtN4fhvFDwTYw5Gx0UqpffHQA7DuppVYDeJj6GTaLM/a/NXDRiUESg6Ye3ibbT6Cj7kTtUKesrwWmBsMNW5egoZmWOKSlvIUeD49SBAjJGKccZ1QX4+yVeu5/siOkiF2Zt+OqHI3nQfWhU34C5OA57H2gNknDS42e4NNlVjUfrxKbANnUWuk0gS4MTG48lk8SGtN+wCQdmDiUDAbKOVekkteIzC2QNzWEQIq2U9xvt4Mw4+scMVYg9b95/IRfkpQsXBTEDrwfy6HK5s//lfe11CwY2J92E0z2PuphS4MhX7Gsa7On5MLMw8qi0dLDK4SrgFyEmd8pUrHdwJ2AKkCAwEAAaNTMFEwHQYDVR0OBBYEFAiKWDjfB6uAzG6T3fWrlvvefaPXMB8GA1UdIwQYMBaAFAiKWDjfB6uAzG6T3fWrlvvefaPXMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggIBAEm/GGG3KXnjIil9JVmzBBzuZ+Qx5kM2TAvSHVFQnLL6bbY4T2C85jL+y5+FJqh+DVcHndcy5NWshNPAdB9JmxEGiAtpGwgyn6YbyF0Qie6VJjIahVC2mJUeiGi3unaKlViom/FAAro2uBAi9ay/TSv/S1q6lWJuFwcME/Ly53osoAKzPgoUK83jrIVPtRY4krK3ZwK3lrXeInaz06AwvEpFmMV8mCbhlcwUe53JJDyLINo5fqZpI59yvmM4PVb3//fyvxsI5y5youXPvWC7QOmnibF2fTdFgxNNdhmwudvuSzsfen4m6d1KVcOaGyv/CGHA5x5MPlP8NjnEVIcgt+ooiA5qtJEGblRiA30onbu1FbxNLJMQQ9OgYLHTWZn6hdgiQfWfD3OgxbuES70Z6AqPTDo02/Sfk4cDKPY90SkfSV1rWz42uPPtHQJSCOw69NRriireUstx5Hzh1RV0DZ4jR211nLuS5Dt++/zlQJp8Oi4GlqFMrzzSu60ErKLKcaImWOmMLbM5T8sA134CPqRFMameVU6fz2+zlMsdJ7JlvnNdQ31zfrA6kEXWTqHOAhkh+hgxTnthAEZtAgsqrcahq31Lv9dcs1DKqqmP4y5ZDjyzO1wZHN6fPRoLGNL9uw8qyGcaFYkb8X6BgNaj0C+CgXx+bjOxSOIUlZOwGmib</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/>
    </md:KeyDescriptor>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://aai-demo.egi.eu/auth/realms/id/broker/endpoint"/>
    <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat>
    <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://aai-demo.egi.eu/auth/realms/id/broker/endpoint" isDefault="true" index="1">
</md:AssertionConsumerService>
    <md:AttributeConsumingService isDefault="true" index="1">
      <md:ServiceName xml:lang="en">EGI Check-in Service (Demo environment)</md:ServiceName>
      <md:ServiceDescription xml:lang="en">EGI Check-in Identity and Access Management Service (Demo environment)</md:ServiceDescription>
      <md:RequestedAttribute isRequired="true" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.13" FriendlyName="eduPersonUniqueId" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"/>
      <md:RequestedAttribute isRequired="true" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" FriendlyName="eduPersonPrincipalName" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"/>
      <md:RequestedAttribute isRequired="true" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" FriendlyName="eduPersonTargetedID" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"/>
      <md:RequestedAttribute isRequired="true" Name="urn:oid:2.5.4.4" FriendlyName="sn" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"/>
      <md:RequestedAttribute isRequired="true" Name="urn:oid:2.5.4.42" FriendlyName="givenName" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"/>
      <md:RequestedAttribute isRequired="true" Name="urn:oid:2.16.840.1.113730.3.1.241" FriendlyName="displayName" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"/>
      <md:RequestedAttribute isRequired="true" Name="urn:oid:0.9.2342.19200300.100.1.3" FriendlyName="mail" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"/>
      <md:RequestedAttribute isRequired="true" Name="urn:oid:1.3.6.1.4.1.25178.1.2.9" FriendlyName="schacHomeOrganization" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"/>
      <md:RequestedAttribute isRequired="true" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" FriendlyName="eduPersonScopedAffiliation" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"/>
      <md:RequestedAttribute isRequired="true" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.11" FriendlyName="eduPersonAssurance" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"/>
      <md:RequestedAttribute isRequired="false" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.7" FriendlyName="eduPersonEntitlement" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"/>
    </md:AttributeConsumingService>
  </md:SPSSODescriptor>
  <md:Organization>
    <md:OrganizationName xml:lang="en">EGI Foundation</md:OrganizationName>
    <md:OrganizationDisplayName xml:lang="en">EGI Foundation</md:OrganizationDisplayName>
    <md:OrganizationURL xml:lang="en">https://www.egi.eu/</md:OrganizationURL>
  </md:Organization>
  <md:ContactPerson contactType="administrative">
    <md:GivenName>EGI Check-in</md:GivenName>
    <md:EmailAddress>mailto:check-in@egi.eu</md:EmailAddress>
  </md:ContactPerson>
  <md:ContactPerson contactType="support">
    <md:GivenName>EGI Check-in Support</md:GivenName>
    <md:EmailAddress>mailto:checkin-support@mailman.egi.eu</md:EmailAddress>
  </md:ContactPerson>
  <md:ContactPerson contactType="technical">
    <md:GivenName>EGI Check-in</md:GivenName>
    <md:EmailAddress>mailto:check-in@egi.eu</md:EmailAddress>
  </md:ContactPerson>
  <md:ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security">
    <md:Company>EGI Foundation</md:Company>
    <md:GivenName>EGI Check-in Computer Security and Incident Response Team</md:GivenName>
    <md:EmailAddress>mailto:check-in-abuse@mailman.egi.eu</md:EmailAddress>
  </md:ContactPerson>
</md:EntityDescriptor>
