<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr"  entityID="https://idp1.agroparistech.fr/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">agroparistech.fr</shibmd:Scope>
<!--
    Fill in the details for your IdP here 

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">A Name for the IdP at idp1.agroparistech.fr</mdui:DisplayName>
                <mdui:Description xml:lang="en">Enter a description of your IdP at idp1.agroparistech.fr</mdui:Description>
                <mdui:Logo height="80" width="80">https://idp1.agroparistech.fr/Path/To/Logo.png</mdui:Logo>
            </mdui:UIInfo>
-->
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDEzCCAfugAwIBAgIJAJoHlOrZF/wTMA0GCSqGSIb3DQEBCwUAMCAxHjAcBgNV
BAMMFWlkcDEuYWdyb3BhcmlzdGVjaC5mcjAeFw0yMTA0MjgwODAyMDVaFw00MTA0
MjMwODAyMDVaMCAxHjAcBgNVBAMMFWlkcDEuYWdyb3BhcmlzdGVjaC5mcjCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMQV6mpevqYLr2kU8Ad9ps/tiN+K
4/xUL5LVuw93GTJJMX3RdHlUaIq9Yl5VEfrfcPccck/M9TsOwyTSWCIPi4B4x6xx
2nESKpVsHvNl0UbJC4lnVEz/ei3CAiSfkgrH1lvzV6ZnALqKOEIl/atDA96vm87R
dRO/Lxja9DPLPTEFHwm+AI4F8RY+x+eT0itVw455QtVuDXLdu84K9VgI+pPkdFP8
DH3FwhvNHxkF97Tjy9ymERRx+QB8AJqskX3MKj+glQbbVlzT8c+xRgyUFnl/c2cn
OWzOpBwGz8ZZv8BlxzO0Il+k/FoiCTjvijedOYs1M6Mq3TAhbERABdQK+N0CAwEA
AaNQME4wHQYDVR0OBBYEFIaxn8mVcLUpBPIAxlLlzRlwdUgZMB8GA1UdIwQYMBaA
FIaxn8mVcLUpBPIAxlLlzRlwdUgZMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEL
BQADggEBAK4WYttd0f5+bPZvqbF2DgC8AkH2mRwuoiVVqpTtbneuGxXeHinE0exx
d+l0ysaBmFXJgEz1Fu8FP0D49BSDffzOM6RINVEZ+2pMIPZnAxlBWA88BNRDoNqO
mB61MZYjsv2S16fR5MsPTFXeU6Ew9KtJsLTqRTkZHnBKkHJFobu5wyKY76PZEjXk
z02kajDNGIQENnwSGMOdjGbbzc3QqGM3aOxYhDn44VIzyOVO7thxNx6tnMtUK0Zp
7ISwCqw5dFEng+ySXn8Jd0xAbYxw6E81VRqh5sHKHGu6RdjYu+55NvucEDvj0xfl
6X6l9Ltg01NUuLenhyL/6jPR67KRfBU=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDEzCCAfugAwIBAgIJAMeagqRU18pbMA0GCSqGSIb3DQEBCwUAMCAxHjAcBgNV
BAMMFWlkcDEuYWdyb3BhcmlzdGVjaC5mcjAeFw0yMTA0MjgwODAwMjNaFw00MTA0
MjMwODAwMjNaMCAxHjAcBgNVBAMMFWlkcDEuYWdyb3BhcmlzdGVjaC5mcjCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMMSyIP+rnU4LtBk4Aua6aQsdqVk
5YJutHm0n8EezqojSILHU2MG7/DRf7/6VMFyvVM7Z+qpGrWpTBFrADHyMcsPRi/B
5/kNAE88jFe4ukKIbTf8l7V3pS6G2XhTJkazU6op2R4t6ps9/tBEi0xs9pOa4QBK
f4cAQw+orU78wcNDL6Y3Tj3O/ZcpeD1RhkivhDJOJj37vPaM3DpWQRR9X7Ac11t2
YM5sT86NWknlo2n2N3lXRhAkYPQpETm54CoQSO36uZFOp+QszIBvGbu4ixJqa7WM
/0nfQZczwmqAX1FPEP+CUfzkpwiFfxB2ZVziBN75aPbRhJCzPQPuvNV1jo0CAwEA
AaNQME4wHQYDVR0OBBYEFNmD5+w33TdKGgu5pBn6Ld/Wyj4bMB8GA1UdIwQYMBaA
FNmD5+w33TdKGgu5pBn6Ld/Wyj4bMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEL
BQADggEBAG+fuRwkaPn0YA9VW6l99PYUmrr6bcYlQwt9PuDplEBgejlRvDGI+hOq
7uvxpgd191b/fe3eqw3mahqieBkIWSfqUXf3T1GwM3zoaMckRNDLWnNWVFu/BeLL
aDw/TthdcH4ufkDkRimOhkYrg1Kf7oSne4VBMYYe/oi55hQQ4G2hHCqL6B3bKBnL
0zgy517Ux5uWigvbL4YQKbeWqnDBAaXBx3x7dvModP+nwYcrNUUWm6RuVUmpl6os
3uwSmXXvyUb3RPUa7TXPznDvzYBLU92jVeJDa3R2SLdOhUWGPQBtWHlWhgtNP23l
QyNr8f29qa2oOOAAqEBJw4zX8R7VoXQ=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDEzCCAfugAwIBAgIJAK86pStN/51hMA0GCSqGSIb3DQEBCwUAMCAxHjAcBgNV
BAMMFWlkcDEuYWdyb3BhcmlzdGVjaC5mcjAeFw0yMTA0MjgwODAxMDZaFw00MTA0
MjMwODAxMDZaMCAxHjAcBgNVBAMMFWlkcDEuYWdyb3BhcmlzdGVjaC5mcjCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMog2tUv/+eCoEDmeBurwUuoj5dS
x/RUm7rnFDfkRicjbreChCUZGQUDvIlfnRYIwU/BqU12uOtxDkfbtP6purhHwsHz
7+V1RfIaMbF0wxYD3jx3hcsozkEsjoGK6NOAXqrq04GP5CagT0HiibpQ4jqIif+q
pD3O1xN/AHVS3vj8sjyJa9LSrXJ+4TaEpXveqeiSM5iVi6fvl+AWSBsCOpCMHWjM
2IIIvgHKvJNQfgwS+iBXIUIHeOk0NXlbUsPKeq9CQJftHwZ844eXCToXDr41z63k
36Vc8CA/OzhKBG9YR+p7+bwBRtt6sRNH8a0IG3/R8wGy0VJZ91AE4i11wisCAwEA
AaNQME4wHQYDVR0OBBYEFEfGfea04B7SF1oUGOuxCI4f/NKFMB8GA1UdIwQYMBaA
FEfGfea04B7SF1oUGOuxCI4f/NKFMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEL
BQADggEBAL/G4sMgotyGduQ2JmLG+Y6lTI3TUDrJLusZn+bG2pr6zfWR8CKQAK1U
5pwQWI5So3ZSweKXLfY6fGYWMZjF9ScdyP9+uC/2BTgqtDXEXiVIxA/eHXJ9cC2g
KfRcUgoa0sa0bvWimp6InFkumgda0LnRCk0faN2rBsHGytmdKUMDkkxmLE5erZAr
9/is3Y3EUqKYkLzBOWHJtuiNhc1GCroz9nJp3+ydcC5Aqm1/5VhlkiS1dv7K1xoJ
MaGBZBTNRmkBOpDs9GaEdHCG5jFttcxz7cOegMKwkkvZST7R7Bwd1rJCZX0U7GJj
Ms6QEKK+JT9bEA5JIjLMj0PhhO9qLLs=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp1.agroparistech.fr:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp1.agroparistech.fr:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>

        <!--
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp1.agroparistech.fr/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp1.agroparistech.fr/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp1.agroparistech.fr/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp1.agroparistech.fr:8443/idp/profile/SAML2/SOAP/SLO"/>
        -->

        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp1.agroparistech.fr/idp/profile/Shibboleth/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://idp1.agroparistech.fr/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://idp1.agroparistech.fr/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://idp1.agroparistech.fr/idp/profile/SAML2/Redirect/SSO"/>

    </IDPSSODescriptor>


    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">agroparistech.fr</shibmd:Scope>
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDEzCCAfugAwIBAgIJAJoHlOrZF/wTMA0GCSqGSIb3DQEBCwUAMCAxHjAcBgNV
BAMMFWlkcDEuYWdyb3BhcmlzdGVjaC5mcjAeFw0yMTA0MjgwODAyMDVaFw00MTA0
MjMwODAyMDVaMCAxHjAcBgNVBAMMFWlkcDEuYWdyb3BhcmlzdGVjaC5mcjCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMQV6mpevqYLr2kU8Ad9ps/tiN+K
4/xUL5LVuw93GTJJMX3RdHlUaIq9Yl5VEfrfcPccck/M9TsOwyTSWCIPi4B4x6xx
2nESKpVsHvNl0UbJC4lnVEz/ei3CAiSfkgrH1lvzV6ZnALqKOEIl/atDA96vm87R
dRO/Lxja9DPLPTEFHwm+AI4F8RY+x+eT0itVw455QtVuDXLdu84K9VgI+pPkdFP8
DH3FwhvNHxkF97Tjy9ymERRx+QB8AJqskX3MKj+glQbbVlzT8c+xRgyUFnl/c2cn
OWzOpBwGz8ZZv8BlxzO0Il+k/FoiCTjvijedOYs1M6Mq3TAhbERABdQK+N0CAwEA
AaNQME4wHQYDVR0OBBYEFIaxn8mVcLUpBPIAxlLlzRlwdUgZMB8GA1UdIwQYMBaA
FIaxn8mVcLUpBPIAxlLlzRlwdUgZMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEL
BQADggEBAK4WYttd0f5+bPZvqbF2DgC8AkH2mRwuoiVVqpTtbneuGxXeHinE0exx
d+l0ysaBmFXJgEz1Fu8FP0D49BSDffzOM6RINVEZ+2pMIPZnAxlBWA88BNRDoNqO
mB61MZYjsv2S16fR5MsPTFXeU6Ew9KtJsLTqRTkZHnBKkHJFobu5wyKY76PZEjXk
z02kajDNGIQENnwSGMOdjGbbzc3QqGM3aOxYhDn44VIzyOVO7thxNx6tnMtUK0Zp
7ISwCqw5dFEng+ySXn8Jd0xAbYxw6E81VRqh5sHKHGu6RdjYu+55NvucEDvj0xfl
6X6l9Ltg01NUuLenhyL/6jPR67KRfBU=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDEzCCAfugAwIBAgIJAMeagqRU18pbMA0GCSqGSIb3DQEBCwUAMCAxHjAcBgNV
BAMMFWlkcDEuYWdyb3BhcmlzdGVjaC5mcjAeFw0yMTA0MjgwODAwMjNaFw00MTA0
MjMwODAwMjNaMCAxHjAcBgNVBAMMFWlkcDEuYWdyb3BhcmlzdGVjaC5mcjCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMMSyIP+rnU4LtBk4Aua6aQsdqVk
5YJutHm0n8EezqojSILHU2MG7/DRf7/6VMFyvVM7Z+qpGrWpTBFrADHyMcsPRi/B
5/kNAE88jFe4ukKIbTf8l7V3pS6G2XhTJkazU6op2R4t6ps9/tBEi0xs9pOa4QBK
f4cAQw+orU78wcNDL6Y3Tj3O/ZcpeD1RhkivhDJOJj37vPaM3DpWQRR9X7Ac11t2
YM5sT86NWknlo2n2N3lXRhAkYPQpETm54CoQSO36uZFOp+QszIBvGbu4ixJqa7WM
/0nfQZczwmqAX1FPEP+CUfzkpwiFfxB2ZVziBN75aPbRhJCzPQPuvNV1jo0CAwEA
AaNQME4wHQYDVR0OBBYEFNmD5+w33TdKGgu5pBn6Ld/Wyj4bMB8GA1UdIwQYMBaA
FNmD5+w33TdKGgu5pBn6Ld/Wyj4bMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEL
BQADggEBAG+fuRwkaPn0YA9VW6l99PYUmrr6bcYlQwt9PuDplEBgejlRvDGI+hOq
7uvxpgd191b/fe3eqw3mahqieBkIWSfqUXf3T1GwM3zoaMckRNDLWnNWVFu/BeLL
aDw/TthdcH4ufkDkRimOhkYrg1Kf7oSne4VBMYYe/oi55hQQ4G2hHCqL6B3bKBnL
0zgy517Ux5uWigvbL4YQKbeWqnDBAaXBx3x7dvModP+nwYcrNUUWm6RuVUmpl6os
3uwSmXXvyUb3RPUa7TXPznDvzYBLU92jVeJDa3R2SLdOhUWGPQBtWHlWhgtNP23l
QyNr8f29qa2oOOAAqEBJw4zX8R7VoXQ=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDEzCCAfugAwIBAgIJAK86pStN/51hMA0GCSqGSIb3DQEBCwUAMCAxHjAcBgNV
BAMMFWlkcDEuYWdyb3BhcmlzdGVjaC5mcjAeFw0yMTA0MjgwODAxMDZaFw00MTA0
MjMwODAxMDZaMCAxHjAcBgNVBAMMFWlkcDEuYWdyb3BhcmlzdGVjaC5mcjCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMog2tUv/+eCoEDmeBurwUuoj5dS
x/RUm7rnFDfkRicjbreChCUZGQUDvIlfnRYIwU/BqU12uOtxDkfbtP6purhHwsHz
7+V1RfIaMbF0wxYD3jx3hcsozkEsjoGK6NOAXqrq04GP5CagT0HiibpQ4jqIif+q
pD3O1xN/AHVS3vj8sjyJa9LSrXJ+4TaEpXveqeiSM5iVi6fvl+AWSBsCOpCMHWjM
2IIIvgHKvJNQfgwS+iBXIUIHeOk0NXlbUsPKeq9CQJftHwZ844eXCToXDr41z63k
36Vc8CA/OzhKBG9YR+p7+bwBRtt6sRNH8a0IG3/R8wGy0VJZ91AE4i11wisCAwEA
AaNQME4wHQYDVR0OBBYEFEfGfea04B7SF1oUGOuxCI4f/NKFMB8GA1UdIwQYMBaA
FEfGfea04B7SF1oUGOuxCI4f/NKFMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEL
BQADggEBAL/G4sMgotyGduQ2JmLG+Y6lTI3TUDrJLusZn+bG2pr6zfWR8CKQAK1U
5pwQWI5So3ZSweKXLfY6fGYWMZjF9ScdyP9+uC/2BTgqtDXEXiVIxA/eHXJ9cC2g
KfRcUgoa0sa0bvWimp6InFkumgda0LnRCk0faN2rBsHGytmdKUMDkkxmLE5erZAr
9/is3Y3EUqKYkLzBOWHJtuiNhc1GCroz9nJp3+ydcC5Aqm1/5VhlkiS1dv7K1xoJ
MaGBZBTNRmkBOpDs9GaEdHCG5jFttcxz7cOegMKwkkvZST7R7Bwd1rJCZX0U7GJj
Ms6QEKK+JT9bEA5JIjLMj0PhhO9qLLs=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp1.agroparistech.fr:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
        <!-- <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp1.agroparistech.fr:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> -->
        <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->

    </AttributeAuthorityDescriptor>

</EntityDescriptor>
