<!--
	***DO NOT EDIT THIS FILE***

	Generated by:

	master_ukfederation.xsl 2142 2008-08-06 18:38:33Z iay 
-->
<!--
	U K   F E D E R A T I O N   M E T A D A T A
-->
<EntitiesDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" Name="http://ukfederation.org.uk" xsi:schemaLocation="urn:oasis:names:tc:SAML:2.0:metadata sstc-saml-schema-metadata-2.0.xsd   urn:mace:shibboleth:metadata:1.0 shibboleth-metadata-1.0.xsd   http://www.w3.org/2001/04/xmlenc# xenc-schema.xsd   http://www.w3.org/2000/09/xmldsig# xmldsig-core-schema.xsd"><ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#WithComments"></ds:CanonicalizationMethod>
<ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"></ds:SignatureMethod>
<ds:Reference URI="">
<ds:Transforms>
<ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"></ds:Transform>
<ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#WithComments"></ds:Transform>
</ds:Transforms>
<ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"></ds:DigestMethod>
<ds:DigestValue>FaKhQjC6CRanl4YMQcIk1XBlDTk=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>
aCZkljsOqN79m3lvIXSob/ho5LgDqdEUhaGpg3MdYw4BBT7L2TXQog7IXGaBJBb7Kx8il7nnokrq
vbgoALniBTD8C0lW3eyLd8J7ykZ7fLmSIDI5cVueV4myrQ6lXgxbZBKfvFVX1yjwRWRixyokb913
hqMw1aljx41aA/YZz5/cPxZYXVS4ZsgctrCPtmWCKF6AU6NY6ztPmWRPkibjA8cYvLA9vH5TrFvh
WS5vr0hJfOcNE0IvuBuA+poGDACn9BABO4AcRxaHaxWECJR/zr6QCEWj1JlTy4LA+lldMYMsrHl0
3ivdm4L95sTNlbj9mU8lYRMrzKo15oQPMIgqfw==
</ds:SignatureValue>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
MIIEVzCCAz+gAwIBAgIJAO6gban14PLxMA0GCSqGSIb3DQEBBQUAMHoxCzAJBgNVBAYTAkdCMUMw
QQYDVQQKEzpVSyBBY2Nlc3MgTWFuYWdlbWVudCBGZWRlcmF0aW9uIGZvciBFZHVjYXRpb24gYW5k
IFJlc2VhcmNoMSYwJAYDVQQDEx1VSyBGZWRlcmF0aW9uIE1ldGFkYXRhIFNpZ25lcjAeFw0wNjEx
MTcxNTMwMjNaFw0wODExMTYxNTMwMjNaMHoxCzAJBgNVBAYTAkdCMUMwQQYDVQQKEzpVSyBBY2Nl
c3MgTWFuYWdlbWVudCBGZWRlcmF0aW9uIGZvciBFZHVjYXRpb24gYW5kIFJlc2VhcmNoMSYwJAYD
VQQDEx1VSyBGZWRlcmF0aW9uIE1ldGFkYXRhIFNpZ25lcjCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBAOqtfMvCmBuQudC4/jZFPYkHDNHFyp1FA3KJihIUXppFvrecrO2wG5CpyqB1mZ+M
lKf4jKcTMGBIXC2klD+FyrEdJMBhO6vRmJnNphg3uNZMks0NqIaZmtgc7e8435nMhqLHV95UK2oC
LcT4gZrTaXa2vt9kukTOijB0KqDIfEG5369EHXPItApAEeMlHebbWndl5n2I16nya/LeaoiU9qJ6
sVz4xd1UtUesewrmYVKgPA2JYEpovmnr13sTnGssai5Db/FkrE2NJ4Q4drbPYcwincUo/UXzrtuP
clr+l3JEgjtvDzPrBxxvK0S/gARrbKz5tk4LDLkYsj4PKlwVS+UCAwEAAaOB3zCB3DAdBgNVHQ4E
FgQUT0eEG4zGvMFg6PUqP/eC3MCC1QQwgawGA1UdIwSBpDCBoYAUT0eEG4zGvMFg6PUqP/eC3MCC
1QShfqR8MHoxCzAJBgNVBAYTAkdCMUMwQQYDVQQKEzpVSyBBY2Nlc3MgTWFuYWdlbWVudCBGZWRl
cmF0aW9uIGZvciBFZHVjYXRpb24gYW5kIFJlc2VhcmNoMSYwJAYDVQQDEx1VSyBGZWRlcmF0aW9u
IE1ldGFkYXRhIFNpZ25lcoIJAO6gban14PLxMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEFBQAD
ggEBAIjtHPC8Za+TQM7Ol3PB+ovNYu6gTxW+ju1hxwJc+kwiI2NveWiHLDS/daVCT2wapn2h11bA
tgV5rnG6rSe6FlUaPukVMyjfq9Cjma3PI0d5uHPYUE83r8DHL1y6YsUDiCoiretAGVT8po4OLFmf
/4tqZFa14H1zCa17TNwU6Va/94Iqdb28vo0q9nhBYPBb+67nzorxznGVwvDT/CX1dGTVY7do3oSH
7vtv3wgQNwUxoGEp2pRd0z60CGdrqN2zxx5PGiN2VP2PdVbRCRpedBOMMXQl0vkWFYth3PkGKh1y
t8APVPKHkdgr/kajkdxm5jMvi+FwcWnelTmKJuVr2BM=
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo></ds:Signature>

	<Extensions>

		<shibmeta:KeyAuthority xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" VerifyDepth="3">
            <!--
		          Authorities accepted for the federation.
		          
		          The KeyAuthority element's VerifyDepth attribute must be at least as
		          large as the verification depth required by each root certificate below.
            -->
              
			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<!--
				
					SDSS project internal CA
					
					* CN=SDSS CA, O=JISC Core Middleware Programme, C=GB
					
						This is used to sign individual certificates directly with no intermediates.
						
					No intermediates, so requires a verification depth of at least 1.

					Validity
						Not Before: Aug 24 13:34:50 2004 GMT
						Not After : Dec 31 13:34:50 2008 GMT
					
				-->
				<ds:X509Data>
					<ds:X509Certificate>MIICvDCCAiWgAwIBAgIBADANBgkqhkiG9w0BAQUFADBIMQswCQYDVQQGEwJHQjEn
MCUGA1UEChMeSklTQyBDb3JlIE1pZGRsZXdhcmUgUHJvZ3JhbW1lMRAwDgYDVQQD
EwdTRFNTIENBMB4XDTA0MDgyNDEzMzQ1MFoXDTA4MTIzMTEzMzQ1MFowSDELMAkG
A1UEBhMCR0IxJzAlBgNVBAoTHkpJU0MgQ29yZSBNaWRkbGV3YXJlIFByb2dyYW1t
ZTEQMA4GA1UEAxMHU0RTUyBDQTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA
nG0nCHnged5EI4vKLU5ate5WzjJd39Zv7PZLuJIBN8M7RM3AfOqhXfcF1xGYs5oM
GRytf672Fo3UffTn0wjOPRv+ZpK5YMjc1i1I44lWY/zHS3smT5gl7ZinRqyjBhTZ
1WB0rHIiVJtBU10BmC/Gu96xV4331/CIAyoVbQNIn+cCAwEAAaOBtTCBsjAdBgNV
HQ4EFgQUvq0gh0kHZ3Eez9e6q0CKdxYdK8AwcAYDVR0jBGkwZ4AUvq0gh0kHZ3Ee
z9e6q0CKdxYdK8ChTKRKMEgxCzAJBgNVBAYTAkdCMScwJQYDVQQKEx5KSVNDIENv
cmUgTWlkZGxld2FyZSBQcm9ncmFtbWUxEDAOBgNVBAMTB1NEU1MgQ0GCAQAwDwYD
VR0TBAgwBgEB/wIBADAOBgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQEFBQADgYEA
aImnqqpFtvuPayuSPSoH4gTaW0t3GOnN2stnRPrcP0FzfmQOA1BruKA4JsrRhBOs
KyAs/351HF4hkBivFp2BXb4qQDP45l9YUJwTSfZT4oBLem5UWIZ/gzgYISz6G5eH
0SOjzJxojpTWKe0eLkp9qUAdTgFKerXB9p+V84Uzgng=
</ds:X509Certificate>
				</ds:X509Data>
			</ds:KeyInfo>
				
			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<!--
				
					GTE CyberTrust Global Root
					
					* CN=GTE CyberTrust Global Root, OU=GTE CyberTrust Solutions, Inc.,
					  O=GTE Corporation, C=US

						This is used to sign:

						* CN=Cybertrust Educational CA, OU=Educational CA, O=Cybertrust, C=BE

							This in turn is used to sign SureServer EDU end certificates.
						
					One intermediate CA below the root, so requires a verification depth of at least 2.

					Validity
						Not Before: Aug 13 00:29:00 1998 GMT
						Not After : Aug 13 23:59:00 2018 GMT

				-->
				<ds:X509Data>
					<ds:X509Certificate>MIICWjCCAcMCAgGlMA0GCSqGSIb3DQEBBAUAMHUxCzAJBgNVBAYTAlVTMRgwFgYD
VQQKEw9HVEUgQ29ycG9yYXRpb24xJzAlBgNVBAsTHkdURSBDeWJlclRydXN0IFNv
bHV0aW9ucywgSW5jLjEjMCEGA1UEAxMaR1RFIEN5YmVyVHJ1c3QgR2xvYmFsIFJv
b3QwHhcNOTgwODEzMDAyOTAwWhcNMTgwODEzMjM1OTAwWjB1MQswCQYDVQQGEwJV
UzEYMBYGA1UEChMPR1RFIENvcnBvcmF0aW9uMScwJQYDVQQLEx5HVEUgQ3liZXJU
cnVzdCBTb2x1dGlvbnMsIEluYy4xIzAhBgNVBAMTGkdURSBDeWJlclRydXN0IEds
b2JhbCBSb290MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCVD6C28FCc6HrH
iM3dFw4usJTQGz0O9pTAipTHBsiQl8i4ZBp6fmw8U+E3KHNgf7KXUwefU/ltWJTS
r41tiGeA5u2ylc9yMcqlHHK6XALnZELn+aks1joNrI1CqiQBOeacPwGFVw1Yh0X4
04Wqk2kmhXBIgD8SFcd5tB8FLztimQIDAQABMA0GCSqGSIb3DQEBBAUAA4GBAG3r
GwnpXtlR22ciYaQqPEh346B8pt5zohQDhT37qw4wxYMWM4ETCJ57NE7fQMh017l9
3PR2VX2bY1QY6fDq81yx2YtCHrnAlU66+tXifPVoYb+O7AWXX1uw16OFNMQkpw0P
lZPvy5TYnh+dXIVtx6quTx8itc2VrbqnzPmrC3p/
</ds:X509Certificate>
				</ds:X509Data>
			</ds:KeyInfo>

			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<!--
				
					Cybertrust Educational CA
					
					* CN=Cybertrust Educational CA, OU=Educational CA, O=Cybertrust, C=BE

						This is used to sign SureServer EDU end certificates

					This is an intermediate CA, signed by:

						* CN=GTE CyberTrust Global Root, OU=GTE CyberTrust Solutions, Inc.,
						  O=GTE Corporation, C=US

					No intermediate certificates below this, so only requires a
					verification depth of at least 1.

					Validity
						Not Before: Mar 14 20:30:00 2006 GMT
						Not After : Mar 14 23:59:00 2013 GMT					

				-->
				<ds:X509Data>
					<ds:X509Certificate>MIIEQjCCA6ugAwIBAgIEBAAD+zANBgkqhkiG9w0BAQUFADB1MQswCQYDVQQGEwJV
UzEYMBYGA1UEChMPR1RFIENvcnBvcmF0aW9uMScwJQYDVQQLEx5HVEUgQ3liZXJU
cnVzdCBTb2x1dGlvbnMsIEluYy4xIzAhBgNVBAMTGkdURSBDeWJlclRydXN0IEds
b2JhbCBSb290MB4XDTA2MDMxNDIwMzAwMFoXDTEzMDMxNDIzNTkwMFowXzELMAkG
A1UEBhMCQkUxEzARBgNVBAoTCkN5YmVydHJ1c3QxFzAVBgNVBAsTDkVkdWNhdGlv
bmFsIENBMSIwIAYDVQQDExlDeWJlcnRydXN0IEVkdWNhdGlvbmFsIENBMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAlSKhEB1KRmBuBZGb34PC7RKyWnz4
q+H4UFwoLH5+ADiTsItK8cJMPBAsPO+w7KFpL7n8zAgUa41PGPOD0vqpNwggqlyq
gGCi1aUiAM9a5bSX37oevlyOFxlm/a+ffHuJsg4k2MerY8SVMo1I5mNZfQS4M6i9
111kvGO1900o/fkGcjFcukWUZaPStFjsO2FYRKMvYrObgLSC/dXHzFEl5ZU/Ry8w
e6zIeG7i4W0n6z3MAYLoNXeNq1i7VdHVpIFWjRzQFLGwBt6gkSLz8Kg0F0fG4D72
DFqsflBLzeFpbgb8Bn5qTbSVmaBZXDVm7NlJ1BfgYLBdpdca4ipuZvKvHQIDAQAB
o4IBbzCCAWswRQYDVR0fBD4wPDA6oDigNoY0aHR0cDovL3d3dy5wdWJsaWMtdHJ1
c3QuY29tL2NnaS1iaW4vQ1JMLzIwMTgvY2RwLmNybDAdBgNVHQ4EFgQUZWWjPdc7
EaMKByU3yUJKW3Z3UOEwUwYDVR0gBEwwSjBIBgkrBgEEAbE+AQAwOzA5BggrBgEF
BQcCARYtaHR0cDovL3d3dy5wdWJsaWMtdHJ1c3QuY29tL0NQUy9PbW5pUm9vdC5o
dG1sMIGJBgNVHSMEgYEwf6F5pHcwdTELMAkGA1UEBhMCVVMxGDAWBgNVBAoTD0dU
RSBDb3Jwb3JhdGlvbjEnMCUGA1UECxMeR1RFIEN5YmVyVHJ1c3QgU29sdXRpb25z
LCBJbmMuMSMwIQYDVQQDExpHVEUgQ3liZXJUcnVzdCBHbG9iYWwgUm9vdIICAaUw
DgYDVR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8CAQAwDQYJKoZIhvcNAQEF
BQADgYEAQ7NFg1RxxB/csjxrTr8m8k7yrZpb+oY3iOgUbEEYQl/vZT7rA3egt551
elF8uxVbuK+RoDSSU+1/KkmErLmAS7XHsiMi++vY+27JPPPS0bu+yRz/bQHbaYAO
maXqnnuXmI+3zyKcs7hd5akzF3TGlzcPtOkmgl9hCz8ePWTpK5s=
</ds:X509Certificate>
				</ds:X509Data>
			</ds:KeyInfo>

			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<!--
				
					RSA Secure Server CA (issuer for some VeriSign certs)
					
					* OU=Secure Server Certification Authority, O=RSA Data Security, Inc., C=US

						This is used to sign individual certificates directly with no intermediates.
						
					No intermediates, so requires a verification depth of at least 1.

					Validity
						Not Before: Nov  9 00:00:00 1994 GMT
						Not After : Jan  7 23:59:59 2010 GMT

				-->
				<ds:X509Data>
					<ds:X509Certificate>MIICNDCCAaECEAKtZn5ORf5eV288mBle3cAwDQYJKoZIhvcNAQECBQAwXzELMAkG
A1UEBhMCVVMxIDAeBgNVBAoTF1JTQSBEYXRhIFNlY3VyaXR5LCBJbmMuMS4wLAYD
VQQLEyVTZWN1cmUgU2VydmVyIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MB4XDTk0
MTEwOTAwMDAwMFoXDTEwMDEwNzIzNTk1OVowXzELMAkGA1UEBhMCVVMxIDAeBgNV
BAoTF1JTQSBEYXRhIFNlY3VyaXR5LCBJbmMuMS4wLAYDVQQLEyVTZWN1cmUgU2Vy
dmVyIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MIGbMA0GCSqGSIb3DQEBAQUAA4GJ
ADCBhQJ+AJLOesGugz5aqomDV6wlAXYMra6OLDfO6zV4ZFQD5YRAUcm/jwjiioII
0haGN1XpsSECrXZogZoFokvJSyVmIlZsiAeP94FZbYQHZXATcXY+m3dM41CJVphI
uR2nKRoTLkoRWZweFdVJVCxzOmmCsZc5nG1wZ0jl3S3WyB57AgMBAAEwDQYJKoZI
hvcNAQECBQADfgBl3X7hsuyw4jrg7HFGmhkRuNPHoLQDQCYCPgmc4RKz0Vr2N6W3
YQO2WxZpO8ZECAyIUwxrl0nHPjXcbLm7qt9cuzovk2C2qUtN8iD3zV9/ZHuO3ABc
1/p3yjkWWW8O6tO1g39NTUJWdrTJXwT4OPjr0l91X817/OWOgHz8UA==
</ds:X509Certificate>
				</ds:X509Data>
			</ds:KeyInfo>
				
			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<!--
				
					VeriSign Class 3 Public Primary CA
					
					* OU=Class 3 Public Primary Certification Authority, O=VeriSign, Inc., C=US

						This is used to sign:

						* CN=VeriSign Class 3 Secure Server CA, OU=VeriSign Trust Network,
						  OU=Terms of use at https://www.verisign.com/rpa (c)05,
						  O=VeriSign, Inc., C=US

							This in turn is used to sign VeriSign Secure Site end certificates.
						
					One intermediate CA below the root, so requires a verification depth of at least 2.

					Validity
						Not Before: Jan 29 00:00:00 1996 GMT
						Not After : Aug  1 23:59:59 2028 GMT

					There are various versions ("generations") of the VeriSign Class3
					Public Primary CA certificate.  The others are also included in this file.

				-->
				<ds:X509Data>
					<ds:X509Certificate>MIICPDCCAaUCEHC65B0Q2Sk0tjjKewPMur8wDQYJKoZIhvcNAQECBQAwXzELMAkG
A1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMTcwNQYDVQQLEy5DbGFz
cyAzIFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MB4XDTk2
MDEyOTAwMDAwMFoXDTI4MDgwMTIzNTk1OVowXzELMAkGA1UEBhMCVVMxFzAVBgNV
BAoTDlZlcmlTaWduLCBJbmMuMTcwNQYDVQQLEy5DbGFzcyAzIFB1YmxpYyBQcmlt
YXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MIGfMA0GCSqGSIb3DQEBAQUAA4GN
ADCBiQKBgQDJXFme8huKARS0EN8EQNvjV69qRUCPhAwL0TPZ2RHP7gJYHyX3KqhE
BarsAx94f56TuZoAqiN91qyFomNFx3InzPRMxnVx0jnvT0Lwdd8KkMaOIG+YD/is
I19wKTakyYbnsZogy1Olhec9vn2a/iRFM9x2Fe0PonFkTGUugWhFpwIDAQABMA0G
CSqGSIb3DQEBAgUAA4GBALtMEivPLCYATxQT3ab7/AoRhIzzKBxnki98tsX63/Do
lbwdj2wsqFHMc9ikwFPwTtYmwHYBV4GSXiHx0bH/59AhWM1pF+NEHJwZRDmJXNyc
AA9WjQKZ7aKQRUzkuxCkPfAyAw7xzvjoyVGM5mKf5p/AfbdynMk2OmufTqj/ZA1k
</ds:X509Certificate>
				</ds:X509Data>
			</ds:KeyInfo>

			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<!--
				
					VeriSign Class 3 Public Primary CA - G2
					
					* OU=Class 3 Public Primary Certification Authority - G2,
					  OU=(c) 1998 VeriSign, Inc. - For authorized use only,
					  OU=VeriSign Trust Network, O=VeriSign, Inc., C=US

					Validity
						Not Before: May 18 00:00:00 1998 GMT
						Not After : Aug  1 23:59:59 2028 GMT

					There are various versions ("generations") of the VeriSign Class3
					Public Primary CA certificate.  The others are also included in this file.

				-->
				<ds:X509Data>
					<ds:X509Certificate>MIIDAjCCAmsCEH3Z/gfPqB63EHln+6eJNMYwDQYJKoZIhvcNAQEFBQAwgcExCzAJ
BgNVBAYTAlVTMRcwFQYDVQQKEw5WZXJpU2lnbiwgSW5jLjE8MDoGA1UECxMzQ2xh
c3MgMyBQdWJsaWMgUHJpbWFyeSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEcy
MTowOAYDVQQLEzEoYykgMTk5OCBWZXJpU2lnbiwgSW5jLiAtIEZvciBhdXRob3Jp
emVkIHVzZSBvbmx5MR8wHQYDVQQLExZWZXJpU2lnbiBUcnVzdCBOZXR3b3JrMB4X
DTk4MDUxODAwMDAwMFoXDTI4MDgwMTIzNTk1OVowgcExCzAJBgNVBAYTAlVTMRcw
FQYDVQQKEw5WZXJpU2lnbiwgSW5jLjE8MDoGA1UECxMzQ2xhc3MgMyBQdWJsaWMg
UHJpbWFyeSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEcyMTowOAYDVQQLEzEo
YykgMTk5OCBWZXJpU2lnbiwgSW5jLiAtIEZvciBhdXRob3JpemVkIHVzZSBvbmx5
MR8wHQYDVQQLExZWZXJpU2lnbiBUcnVzdCBOZXR3b3JrMIGfMA0GCSqGSIb3DQEB
AQUAA4GNADCBiQKBgQDMXtERXVxp0KvTuWpMmR9ZmDCOFoUgRm1HP9SFIIThbbP4
pO0M8RcPO/mn+SXXwc+EY/J8Y8+iR/LGWzOOZEAEaMGAuWQcRXfH2G71lSk8UOg0
13gfqLptQ5GVj0VXXn7F+8qkBOvqlzdUMG+7AUcyM83cV5tkaWH4mx0ciU9cZwID
AQABMA0GCSqGSIb3DQEBBQUAA4GBAFFNzb5cy5gZnBWyATl4Lk0PZ3BwmcYQWpSk
U01UbSuvDV1Ai2TT1+7eVmGSX6bEHRBhNtMsJzzoKQm5EWR0zLVznxxIqbxhAe7i
F6YM40AIOw7n60RzKprxaZLvcRTDOaxxp5EJb+RxBrO6WVcmeQD2+A2iMzAo1KpY
oJ2daZH9
</ds:X509Certificate>
				</ds:X509Data>
			</ds:KeyInfo>

			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<!--
				
					VeriSign Class 3 Public Primary CA - G3
					
					* CN=VeriSign Class 3 Public Primary Certification Authority - G3,
					  OU=(c) 1999 VeriSign, Inc. - For authorized use only,
					  OU=VeriSign Trust Network, O=VeriSign, Inc., C=US

					Validity
						Not Before: Oct  1 00:00:00 1999 GMT
						Not After : Jul 16 23:59:59 2036 GMT

					There are various versions ("generations") of the VeriSign Class3
					Public Primary CA certificate.  The others are also included in this file.

				-->
				<ds:X509Data>
					<ds:X509Certificate>MIIEGjCCAwICEQCbfgZJoz5iudXukEhxKe9XMA0GCSqGSIb3DQEBBQUAMIHKMQsw
CQYDVQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZl
cmlTaWduIFRydXN0IE5ldHdvcmsxOjA4BgNVBAsTMShjKSAxOTk5IFZlcmlTaWdu
LCBJbmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxRTBDBgNVBAMTPFZlcmlT
aWduIENsYXNzIDMgUHVibGljIFByaW1hcnkgQ2VydGlmaWNhdGlvbiBBdXRob3Jp
dHkgLSBHMzAeFw05OTEwMDEwMDAwMDBaFw0zNjA3MTYyMzU5NTlaMIHKMQswCQYD
VQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZlcmlT
aWduIFRydXN0IE5ldHdvcmsxOjA4BgNVBAsTMShjKSAxOTk5IFZlcmlTaWduLCBJ
bmMuIC0gRm9yIGF1dGhvcml6ZWQgdXNlIG9ubHkxRTBDBgNVBAMTPFZlcmlTaWdu
IENsYXNzIDMgUHVibGljIFByaW1hcnkgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkg
LSBHMzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMu6nFL8eB8aHm8b
N3O9+MlrlBIwT/A2R/XQkQr1F8ilYcEWQE37imGQ5XYgwREGfassbqb1EUGO+i2t
KmFZpGcmTNDovFJbcCAEWNF6yaRpvIMXZK0Fi7zQWM6NjPXr8EJJC52XJ2cybuGu
kxUccLwgTS8Y3pKI6GyFVxEa6X7jJhFUokWWVYPKMIno3Nij7SqAP395ZVc+FSBm
CC+Vk7+qRy+oRpfwEuL+wgorUeZ25rdGt+INpsyow0xZVYnm6FNcHOqd8GIWC6fJ
Xwzw3sJ2zq/3avL6QaaiMxTJ5Xpj055iN9WFZZ4O5lMkdBteHRJTW8cs54NJOxWu
imi5V5cCAwEAATANBgkqhkiG9w0BAQUFAAOCAQEAERSWwauSCPc/L8my/uRan2Te
2yFPhpk0djZX3dAVL8WtfxUfN2JzPtTnX84XA9s1+ivbrmAJXx5fj267Cz3qWhMe
DGBvtcC1IyIuBwvLqXTLR7sdwdela8wv0kL9Sd2nic9TutoAWii/gt/4uhMdUIaC
/Y4wjylGsB49Ndo4YhYYSq3mtlFs3q9i6wHQHiT+eo8SGhJouPtmmRQURVyu565p
F4ErWjfJXir0xuKhXFSbplQAz/DxwceYMBo7Nhbbo27q/a2ywtrvAkcTisDxszGt
TxzhT5yvDwyd93gN2PQ1VoDat20Xj50egWTh/sVFuq1ruQp6Tk9LhO5L8X3dEQ==
</ds:X509Certificate>
				</ds:X509Data>
			</ds:KeyInfo>

			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<!--
				
					VeriSign Class 3 Secure Server CA
					
					* CN=VeriSign Class 3 Secure Server CA, OU=VeriSign Trust Network,
					  OU=Terms of use at https://www.verisign.com/rpa (c)05, O=VeriSign, Inc., C=US

						This is used to sign VeriSign Secure Site end certificates
						(IIS certs from May 2005, other platforms from Sep/Oct 2006).

					This is an intermediate CA, signed by:

						* OU=Class 3 Public Primary Certification Authority, O=VeriSign, Inc., C=US

					No intermediate certificates below this, so only requires a
					verification depth of at least 1.

					Validity
						Not Before: Jan 19 00:00:00 2005 GMT
						Not After : Jan 18 23:59:59 2015 GMT					

				-->
				<ds:X509Data>
					<ds:X509Certificate>MIIEnDCCBAWgAwIBAgIQdTN9mrDhIzuuLX3kRpFi1DANBgkqhkiG9w0BAQUFADBf
MQswCQYDVQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xNzA1BgNVBAsT
LkNsYXNzIDMgUHVibGljIFByaW1hcnkgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkw
HhcNMDUwMTE5MDAwMDAwWhcNMTUwMTE4MjM1OTU5WjCBsDELMAkGA1UEBhMCVVMx
FzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMR8wHQYDVQQLExZWZXJpU2lnbiBUcnVz
dCBOZXR3b3JrMTswOQYDVQQLEzJUZXJtcyBvZiB1c2UgYXQgaHR0cHM6Ly93d3cu
dmVyaXNpZ24uY29tL3JwYSAoYykwNTEqMCgGA1UEAxMhVmVyaVNpZ24gQ2xhc3Mg
MyBTZWN1cmUgU2VydmVyIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKC
AQEAlcMhEo5AxQ0BX3ZeZpTZcyxYGSK4yfx6OZAqd3J8HT732FXjr0LLhzAC3Fus
cOa4RLQrNeuT0hcFfstG1lxToDJRnXRkWPkMmgDqXkRJZHL0zRDihQr5NO6ziGap
paRa0A6Yf1gNK1K7hql+LvqySHyN2y1fAXWijQY7i7RhB8m+Ipn4G9G1V2YETTX0
kXGWtZkIJZuXyDrzILHdnpgMSmO3ps6wAc74k2rzDG6fsemEe4GYQeaB3D0s57Rr
4578CBbXs9W5ZhKZfG1xyE2+xw/j+zet1XWHIWuG0EQUWlR5OZZpVsm5Mc2JYVjh
2XYFBa33uQKvp/1HkaIiNFox0QIDAQABo4IBgTCCAX0wEgYDVR0TAQH/BAgwBgEB
/wIBADBEBgNVHSAEPTA7MDkGC2CGSAGG+EUBBxcDMCowKAYIKwYBBQUHAgEWHGh0
dHBzOi8vd3d3LnZlcmlzaWduLmNvbS9ycGEwMQYDVR0fBCowKDAmoCSgIoYgaHR0
cDovL2NybC52ZXJpc2lnbi5jb20vcGNhMy5jcmwwDgYDVR0PAQH/BAQDAgEGMBEG
CWCGSAGG+EIBAQQEAwIBBjApBgNVHREEIjAgpB4wHDEaMBgGA1UEAxMRQ2xhc3Mz
Q0EyMDQ4LTEtNDUwHQYDVR0OBBYEFG/sr6DdiqTv9SoQZy0/VYK81+8lMIGABgNV
HSMEeTB3oWOkYTBfMQswCQYDVQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIElu
Yy4xNzA1BgNVBAsTLkNsYXNzIDMgUHVibGljIFByaW1hcnkgQ2VydGlmaWNhdGlv
biBBdXRob3JpdHmCEHC65B0Q2Sk0tjjKewPMur8wDQYJKoZIhvcNAQEFBQADgYEA
w34IRl2RNs9n3Nenr6+4IsOLBHTTsWC85v63RBKBWzFzFGNWxnIu0RoDQ1w4ClBK
Tc3athmo9JkNr+P32PF1KGX2av6b9L1S2T/L2hbLpZ4ujmZSeD0m+v6UNohKlV4q
TBnvbvqCPy0D79YoszcYz0KyNCFkR9MgazpM3OYDkAw=
</ds:X509Certificate>
				</ds:X509Data>
			</ds:KeyInfo>

			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<!--
				
					VeriSign International CA

					Added for experimental support of VeriSign Secure Site Pro certificates
					
					* O=VeriSign Trust Network,
					  OU=VeriSign, Inc.,
					  OU=VeriSign International Server CA - Class 3,
					  OU=www.verisign.com/CPS Incorp.by Ref. LIABILITY LTD.(c)97 VeriSign

						This is used to sign VeriSign Secure Site Pro (i.e., SGC)
					      end certificates.

					This is an intermediate CA, signed by:

						* OU=Class 3 Public Primary Certification Authority, O=VeriSign, Inc., C=US

					No intermediate certificates below this, so only requires a
					verification depth of at least 1.

					Validity
						Not Before: Apr 17 00:00:00 1997 GMT
						Not After : Oct 24 23:59:59 2011 GMT					

				-->
				<ds:X509Data>
					<ds:X509Certificate>MIIDgzCCAuygAwIBAgIQJUuKhThCzONY+MXdriJupDANBgkqhkiG9w0BAQUFADBf
MQswCQYDVQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xNzA1BgNVBAsT
LkNsYXNzIDMgUHVibGljIFByaW1hcnkgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkw
HhcNOTcwNDE3MDAwMDAwWhcNMTExMDI0MjM1OTU5WjCBujEfMB0GA1UEChMWVmVy
aVNpZ24gVHJ1c3QgTmV0d29yazEXMBUGA1UECxMOVmVyaVNpZ24sIEluYy4xMzAx
BgNVBAsTKlZlcmlTaWduIEludGVybmF0aW9uYWwgU2VydmVyIENBIC0gQ2xhc3Mg
MzFJMEcGA1UECxNAd3d3LnZlcmlzaWduLmNvbS9DUFMgSW5jb3JwLmJ5IFJlZi4g
TElBQklMSVRZIExURC4oYyk5NyBWZXJpU2lnbjCBnzANBgkqhkiG9w0BAQEFAAOB
jQAwgYkCgYEA2IKA6NYZAn0fhRg5JaJlK+G/1AXTvOY2O6rwTGxbtueqPHNFVbLx
veqXQu2aNAoV1Klc9UAl3dkHwTKydWzEyruj/lYncUOqY/UwPpMo5frxCTvzt01O
OfdcSVq4wR3Tsor+cDCVQsv+K1GLWjw6+SJPkLICp1OcTzTnqwSye28CAwEAAaOB
4zCB4DAPBgNVHRMECDAGAQH/AgEAMEQGA1UdIAQ9MDswOQYLYIZIAYb4RQEHAQEw
KjAoBggrBgEFBQcCARYcaHR0cHM6Ly93d3cudmVyaXNpZ24uY29tL0NQUzA0BgNV
HSUELTArBggrBgEFBQcDAQYIKwYBBQUHAwIGCWCGSAGG+EIEAQYKYIZIAYb4RQEI
ATALBgNVHQ8EBAMCAQYwEQYJYIZIAYb4QgEBBAQDAgEGMDEGA1UdHwQqMCgwJqAk
oCKGIGh0dHA6Ly9jcmwudmVyaXNpZ24uY29tL3BjYTMuY3JsMA0GCSqGSIb3DQEB
BQUAA4GBAAgB7ORolANC8XPxI6I63unx2sZUxCM+hurPajozq+qcBBQHNgYL+Yhv
1RPuKSvD5HKNRO3RrCAJLeH24RkFOLA9D59/+J4C3IYChmFOJl9en5IeDCSk9dBw
E88mw0M9SR2egi5SX7w+xmYpAY5Okiy8RnUDgqxz6dl+C2fvVFIa
</ds:X509Certificate>
				</ds:X509Data>
			</ds:KeyInfo>

			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<!--
				
					UK e-Science Root CA
					
					* CN=CA, L=Root, OU=Authority, O=eScienceRoot, C=UK
					
						This is used to sign:

						* CN=CA, OU=Authority, O=eScienceCA, C=UK

							This in turn is used to sign e-Science end certificates.
						
					One intermediate CA below the root, so requires a verification depth of at least 2.

					Validity
						Not Before: Jul 14 16:30:27 2006 GMT
						Not After : Jul 14 16:30:27 2026 GMT					
				-->
				<ds:X509Data>
					<ds:X509Certificate>MIID5TCCAs2gAwIBAgIBADANBgkqhkiG9w0BAQUFADBUMQswCQYDVQQGEwJVSzEV
MBMGA1UEChMMZVNjaWVuY2VSb290MRIwEAYDVQQLEwlBdXRob3JpdHkxDTALBgNV
BAcTBFJvb3QxCzAJBgNVBAMTAkNBMB4XDTA2MDcxNDE2MzAyN1oXDTI2MDcxNDE2
MzAyN1owVDELMAkGA1UEBhMCVUsxFTATBgNVBAoTDGVTY2llbmNlUm9vdDESMBAG
A1UECxMJQXV0aG9yaXR5MQ0wCwYDVQQHEwRSb290MQswCQYDVQQDEwJDQTCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL/TfukTbIrOJ116B8oFqVlGeNNX
bwIX2NVkCF8blpMobk7kHnUcsyA7wW4bW70e4MfL4jF+U80bEgioIEivJaN2udSA
jEmM7yiHelbW5MvS2FiH8rY72ahZMfu6Mc15RD27Lr4WphXUKGazd3XDcyGOZukh
uEksjSKMcPZ+UX4TBlI/a20YCcPD5K61Jh8tF0W+yiDjjXPDwNK31YtIKekbNntf
w2VZtX1SHLl9xtVoj3JUvO4B4sG2QdYPAPW6EvMEFdQ3wNbA0ySNfD42lLExWYSD
sJI8qwKHBict/KAUdyBeKdjiA+A0fawFkD1wevF1chPkPqMEHD2uajC2kzECAwEA
AaOBwTCBvjAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4E
FgQUcXcuwiKiOKOwp8hMHZcqlYnagqMwfAYDVR0jBHUwc4AUcXcuwiKiOKOwp8hM
HZcqlYnagqOhWKRWMFQxCzAJBgNVBAYTAlVLMRUwEwYDVQQKEwxlU2NpZW5jZVJv
b3QxEjAQBgNVBAsTCUF1dGhvcml0eTENMAsGA1UEBxMEUm9vdDELMAkGA1UEAxMC
Q0GCAQAwDQYJKoZIhvcNAQEFBQADggEBAKP+MU3IrDKBWNY1ujegVe/RFq0ONduh
ZXc13xD+tN2/1I2qLydv3hccRdbZ6fB6Cw1A/vC9XxwSgp2qc5Hzx1UVNFyN7oFc
SzJmSC/i9FAHIeScZHLwm5CpwiXslkWwHJ01MN50Pj/C2KLee3DlUdvAUpb5Kmxo
2H41NPd0qpd4BW93bXVgytKimcCz9nNGW2M6SxNKpgtsRidiF+fVBXCcbmaD/MGK
bHYRYc94DJpA+UbDQx6bH4iddVd4afwtXSn8oHKdbnUV6pqrSOmWr/Qk37jRDdRE
pP+kIGJEM3oRG0UjcuRJ/E6KgoKdZLjtjV5ZBkaJf4ABWImkStD2JZo=
</ds:X509Certificate>
				</ds:X509Data>
			</ds:KeyInfo>
				
			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<!--
				
					UK e-Science CA
					
					* CN=CA, OU=Authority, O=eScienceCA, C=UK
					
						This is used to sign e-Science end certificates issued from 4 August 2006.

					No intermediates below this, so requires verification depth of at least 1.

					This is an intermediate CA, signed by:

						* CN=CA, L=Root, OU=Authority, O=eScienceRoot, C=UK

					Validity
						Not Before: Jul 14 16:32:55 2006 GMT
						Not After : Jul 15 16:32:55 2011 GMT					
				-->
				<ds:X509Data>
					<ds:X509Certificate>MIID1DCCArygAwIBAgIBATANBgkqhkiG9w0BAQUFADBUMQswCQYDVQQGEwJVSzEV
MBMGA1UEChMMZVNjaWVuY2VSb290MRIwEAYDVQQLEwlBdXRob3JpdHkxDTALBgNV
BAcTBFJvb3QxCzAJBgNVBAMTAkNBMB4XDTA2MDcxNDE2MzI1NVoXDTExMDcxNTE2
MzI1NVowQzELMAkGA1UEBhMCVUsxEzARBgNVBAoTCmVTY2llbmNlQ0ExEjAQBgNV
BAsTCUF1dGhvcml0eTELMAkGA1UEAxMCQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IB
DwAwggEKAoIBAQC08S40q4YSCt4sNNM9T5qB133eCLW5B0Qg0YWHgViSVc6f6f2B
VJS4MBpOth6sdwvca7mO7C+dOnMEBwyRdFu7wtVOyRR86dbStMkKyljvOOwM6AYf
lz52x9XnVPvTj+FN9mLD5/NmboSRv86Kw6erKJhAQQwuHVPkCOjtWorhdmpcHVci
oA4FfVEBZGeAND5IPrOXTYH281baPBciDqfPOESNEh4xltyUrbFnhmAgYGb7IGoP
b0sNOEOIWOivKuSHMU+dthIBZuytXzctcAtGa4yIGZluj0vs7Ak2HunA2PuXw6/c
v2j41jBBNpil5WgxYNwt4FsFjLUvWy+gS7mPAgMBAAGjgcEwgb4wDwYDVR0TAQH/
BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwHQYDVR0OBBYEFP+lqRpuD2+U6TfRwKVG
Haghk2pLMHwGA1UdIwR1MHOAFHF3LsIiojijsKfITB2XKpWJ2oKjoVikVjBUMQsw
CQYDVQQGEwJVSzEVMBMGA1UEChMMZVNjaWVuY2VSb290MRIwEAYDVQQLEwlBdXRo
b3JpdHkxDTALBgNVBAcTBFJvb3QxCzAJBgNVBAMTAkNBggEAMA0GCSqGSIb3DQEB
BQUAA4IBAQCBuqI6gcY6/BpOTSYHb4B6ga9LBPK9zo96pVOy4IFfoMN6VS9Bo2fK
lBCK+OOSWy5KpN1q6UOyWh8Dcf/hc2lmEBo92gFqG+4gRKBa4IrTDJBARVWXd379
kOAl68sqUDGcciUrQJwVclTO+KsgaVYmo3BvAhqJf4gnLm6XVUgHKl9+WPqDAQdf
DeBCGOOPd0pPMy6RUgXIE+HAgh14yyGfJkiFlYHqaeqqL7A8gxrGSABcqbcUHnH1
kTdHshE2ulkcpqV9wwWldr8S26tIYg9ZvYO1KNNgkwgoLIcKIc22r5IvQ8c7zeI7
8tqPk/TcVznFNfvmsrJSn2urKL4pKJrT
</ds:X509Certificate>
				</ds:X509Data>
			</ds:KeyInfo>
				
			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<!--
				
					GlobalSign Root CA
				
					* CN=GlobalSign Root CA, OU=Root CA, O=GlobalSign nv-sa, C=BE
					
						Up to Summer 2007 this was used to sign the legacy ServerSign hierarchy:
						
						* CN=GlobalSign Primary Secure Server CA, OU=Primary Secure Server CA, O=GlobalSign nv-sa, C=BE
						
							This is used to sign:
							
							* CN=GlobalSign ServerSign CA, OU=ServerSign CA, O=GlobalSign nv-sa, C=BE
							
								This in turn is used to sign ServerSign end certificates.					
	
						Post Summer 2007, it is used to sign:

						* CN=GlobalSign Organization Validation CA, OU=Organization Validation CA, O=GlobalSign

							This is used directly to sign OrganizationSSL end certificates.

					Potentially two levels of intermediate certificate below the root,
					so requires a verification depth of at least 3.
					
					Validity
						Not Before: Sep  1 12:00:00 1998 GMT
						Not After : Jan 28 12:00:00 2014 GMT

				-->
				<ds:X509Data>
					<ds:X509Certificate>MIIDdTCCAl2gAwIBAgILAgAAAAAA1ni3lAUwDQYJKoZIhvcNAQEEBQAwVzELMAkG
A1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYtc2ExEDAOBgNVBAsTB1Jv
b3QgQ0ExGzAZBgNVBAMTEkdsb2JhbFNpZ24gUm9vdCBDQTAeFw05ODA5MDExMjAw
MDBaFw0xNDAxMjgxMjAwMDBaMFcxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9i
YWxTaWduIG52LXNhMRAwDgYDVQQLEwdSb290IENBMRswGQYDVQQDExJHbG9iYWxT
aWduIFJvb3QgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDaDuaZ
jc6j40+Kfvvxi4Mla+pIH/EqsLmVEQS98GPR4mdmzxzdzxtIK+6NiY6arymAZavp
xy0Sy6scTHAHoT0KMM0VjU/43dSMUBUc71DuxC73/OlS8pF94G3VNTCOXkNz8kHp
1Wrjsok6Vjk4bwY8iGlbKk3Fp1S4bInMm/k8yuX9ifUSPJJ4ltbcdG6TRGHRjcdG
snUOhugZitVtbNV4FpWi6cgKOOvyJBNPc1STE4U6G7weNLWLBYy5d4ux2x8gkasJ
U26Qzns3dLlwR5EiUWMWea6xrkEmCMgZK9FGqkjWZCrXgzT/LCrBbBlDSgeF59N8
9iFo7+ryUp9/k5DPAgMBAAGjQjBAMA4GA1UdDwEB/wQEAwIABjAdBgNVHQ4EFgQU
YHtmGkUNl8qJUC99BM00qP/8/UswDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0B
AQQFAAOCAQEArqqf/LfSyx9fOSkoGJ40yWxPbxrwZKJwSk8ThptgKJ7ogUmYfQq7
5bCdPTbbjwVR/wkxKh/diXeeDy5slQTthsu0AD+EAk2AaioteAuubyuig0SDH81Q
gkwkr733pbTIWg/050deSY43lv6aiAU62cDbKYfmGZZHpzqmjIs8d/5GY6dT2iHR
rH5Jokvmw2dZL7OKDrssvamqQnw1wdh/1acxOk5jQzmvCLBhNIzTmKlDNPYPhyk7
ncJWWJh3w/cbrPad+D6qp1RF8PX51TFl/mtYnHGzHtdS6jIX/EBgHcl5JLL2bP2o
Zg6C3ZjL2sJETy6ge/L3ayx2EYRGinij4w==
</ds:X509Certificate>
				</ds:X509Data>
			</ds:KeyInfo>
	
			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<!--
				
					GlobalSign Organization Validation CA
				
					* CN=GlobalSign Organization Validation CA, OU=Organization Validation CA, O=GlobalSign
					
						This is used to sign OrganizationSSL end certificates.					
	
					No intermediate certificates below this, so only requires a
					verification depth of at least 1.

					This is an intermediate CA, signed by:

						* CN=GlobalSign Root CA, OU=Root CA, O=GlobalSign nv-sa, C=BE
				
					Validity
						Not Before: Apr 11 12:00:00 2007 GMT
						Not After : Jan 27 11:00:00 2014 GMT

				-->
				<ds:X509Data>
					<ds:X509Certificate>MIIEZzCCA0+gAwIBAgILBAAAAAABEd/obGYwDQYJKoZIhvcNAQEFBQAwVzELMAkG
A1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYtc2ExEDAOBgNVBAsTB1Jv
b3QgQ0ExGzAZBgNVBAMTEkdsb2JhbFNpZ24gUm9vdCBDQTAeFw0wNzA0MTExMjAw
MDBaFw0xNDAxMjcxMTAwMDBaMGoxIzAhBgNVBAsTGk9yZ2FuaXphdGlvbiBWYWxp
ZGF0aW9uIENBMRMwEQYDVQQKEwpHbG9iYWxTaWduMS4wLAYDVQQDEyVHbG9iYWxT
aWduIE9yZ2FuaXphdGlvbiBWYWxpZGF0aW9uIENBMIIBIjANBgkqhkiG9w0BAQEF
AAOCAQ8AMIIBCgKCAQEAoS/EvM6HA+lnwYnI5ZP8fbStnvZjTmronCxziaIB9I8h
+P0lnVgWbYb27klXdX516iIRfj37x0JB3PzFDJFVgHvrZDMdm/nKOOmrxiVDUSVA
9OR+GFVqqY8QOkAe1leD738vNC8t0vZTwhkNt+3JgfVGLLQjQl6dEwN17Opq/Fd8
yTaXO5jcExPs7EH6XTTquZPnEBZlzJyS/fXFnT5KuQn85F8eaV9N9FZyRLEdIwPI
NvZliMi/ORZFjh4mbFEWxSoAOMWkE2mVfasBO6jEFLSA2qwaRCDV/qkGexQnr+Aw
Id2Q9KnVIxkuHgPmwd+VKeTBlEPdPpCqy0vJvorTOQIDAQABo4IBHzCCARswDgYD
VR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8CAQAwHQYDVR0OBBYEFH1tKuxm
q6dRNqsCafFwj8RZC5ofMEsGA1UdIAREMEIwQAYJKwYBBAGgMgEUMDMwMQYIKwYB
BQUHAgEWJWh0dHA6Ly93d3cuZ2xvYmFsc2lnbi5uZXQvcmVwb3NpdG9yeS8wMwYD
VR0fBCwwKjAooCagJIYiaHR0cDovL2NybC5nbG9iYWxzaWduLm5ldC9yb290LmNy
bDARBglghkgBhvhCAQEEBAMCAgQwIAYDVR0lBBkwFwYKKwYBBAGCNwoDAwYJYIZI
AYb4QgQBMB8GA1UdIwQYMBaAFGB7ZhpFDZfKiVAvfQTNNKj//P1LMA0GCSqGSIb3
DQEBBQUAA4IBAQA3qI82eQA8GOgaxfJ7IihrvxmPF5rtpsTWodZjLXv7BFso2sz5
tu4CVBnebJHyYQ39fyggzI820WGHoFlJqgeW3vmzLPm17hUpM820E53HkM5NfPJa
EYd7+tSN0S9VmRpf7xYIsT3SPR7LtfBXl1I6EmNitvK8zeKmnBfOKODGD1rsv3C9
WudUvvHPxj2fX3raty5l6sLT6ce6vk3L2jOuVZ2uFPYyCGLhieQ0KnU8KgWpK1A4
u1mGpoRahMO9Q7qfHxUFzrV3DdTdL0nI/liVS7xOlhMAHpy4J3dxHcRhy/QejDOz
AGcNt7KsjD063DgvZC0AgYk12OK5MRf+Ol/R
</ds:X509Certificate>
				</ds:X509Data>
			</ds:KeyInfo>
				
			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<!--
				
					GlobalSign Primary Secure Server CA
				
					* CN=GlobalSign Primary Secure Server CA, OU=Primary Secure Server CA, O=GlobalSign nv-sa, C=BE
					
						This is used to sign:
						
						* CN=GlobalSign ServerSign CA, OU=ServerSign CA, O=GlobalSign nv-sa, C=BE
						
							This in turn is used to sign ServerSign end certificates.					
	
					One level of intermediate certificate below this, so requires a
					verification depth of at least 2.

					This is an intermediate CA, signed by:
				
						* CN=GlobalSign Root CA, OU=Root CA, O=GlobalSign nv-sa, C=BE

					Validity
						Not Before: Jan 28 12:00:00 1999 GMT
						Not After : Jan 27 11:00:00 2014 GMT

				-->
				<ds:X509Data>
					<ds:X509Certificate>MIID7zCCAtegAwIBAgILBAAAAAABCNlhHh4wDQYJKoZIhvcNAQEFBQAwVzELMAkG
A1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYtc2ExEDAOBgNVBAsTB1Jv
b3QgQ0ExGzAZBgNVBAMTEkdsb2JhbFNpZ24gUm9vdCBDQTAeFw05OTAxMjgxMjAw
MDBaFw0xNDAxMjcxMTAwMDBaMHkxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9i
YWxTaWduIG52LXNhMSEwHwYDVQQLExhQcmltYXJ5IFNlY3VyZSBTZXJ2ZXIgQ0Ex
LDAqBgNVBAMTI0dsb2JhbFNpZ24gUHJpbWFyeSBTZWN1cmUgU2VydmVyIENBMIIB
IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9mrtqGswoy2s6UKeGDXAHvdv
dMu3QiRTrTHL76XJxT0DXqWdds0Z4uEWLaQtRCDxGh/3fWDNpscVqauKoslmbN0Q
o9ibdynupkDNLzQ2f6MXBQvLWKUipnw15o1doVPCmsXaXf7YDn07IpdSLN2yPAuQ
3AX9suUKVR5dnmL7f+O4lvSfJqyiXITZgrrg6PWVbgQKlmRJow+eg6lj58khmWug
FpElyBTZvdzsPHdTR1ZDhH7WY+XjKK88T8B9tBj2175XC4nb1sGDkpLjnDDRWUyl
cZBfhgdw6E6UFMnyTqOAwloRqejo4rwCnL84TXraPFFj7rz4fFF+oLjgSKmvrQID
AQABo4GZMIGWMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1Ud
DgQWBBTRZoP1iV7Qvn9h0t2oyvorekp/MTAzBgNVHR8ELDAqMCigJqAkhiJodHRw
Oi8vY3JsLmdsb2JhbHNpZ24ubmV0L1Jvb3QuY3JsMB8GA1UdIwQYMBaAFGB7ZhpF
DZfKiVAvfQTNNKj//P1LMA0GCSqGSIb3DQEBBQUAA4IBAQCc/xTUC7yfoztsuSwh
yDfDRU0w+0uSkOBYBb30bknZlLUJiGhuU9zOLHajg0ooxYo/RdDxLwBloK4XBzgA
1Cjiw+JJbLcC4Sk9lNzUx9pjAU88q+HnhGFE5v4tfP/iXBm8TFnMvpq0cUgizi2b
tH7B2ue+jWeIdmXqkSUDVuoEjiVlaFQjGZEm37JGdjFYqwr9qDXioMQlr3owBIcd
/8B7a4AeSnd70iwU0giZBlwCjdVJo1sAFKoznEmRbCoBi+IXncx0w2oK5uuBOKX8
J6mFIJZtXOCLMhhh+cO801XohixLfQk38vjRkXZrvPqQcLo4WiQpff/N0n41bdnu
mvjF
</ds:X509Certificate>
				</ds:X509Data>
			</ds:KeyInfo>
			
			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<!--
				
					GlobalSign ServerSign CA
				
					* CN=GlobalSign ServerSign CA, OU=ServerSign CA, O=GlobalSign nv-sa, C=BE
					
						This is used to sign ServerSign end certificates.					
	
					No intermediate certificates below this, so only requires a
					verification depth of at least 1.

					This is an intermediate CA, signed by:

						* CN=GlobalSign Primary Secure Server CA, OU=Primary Secure Server CA, O=GlobalSign nv-sa, C=BE
				
					Validity
						Not Before: Jan 22 09:00:00 2004 GMT
						Not After : Jan 27 10:00:00 2014 GMT

				-->
				<ds:X509Data>
					<ds:X509Certificate>MIIEFzCCAv+gAwIBAgILBAAAAAABCNlhJc8wDQYJKoZIhvcNAQEFBQAweTELMAkG
A1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYtc2ExITAfBgNVBAsTGFBy
aW1hcnkgU2VjdXJlIFNlcnZlciBDQTEsMCoGA1UEAxMjR2xvYmFsU2lnbiBQcmlt
YXJ5IFNlY3VyZSBTZXJ2ZXIgQ0EwHhcNMDQwMTIyMDkwMDAwWhcNMTQwMTI3MTAw
MDAwWjBjMQswCQYDVQQGEwJCRTEZMBcGA1UEChMQR2xvYmFsU2lnbiBudi1zYTEW
MBQGA1UECxMNU2VydmVyU2lnbiBDQTEhMB8GA1UEAxMYR2xvYmFsU2lnbiBTZXJ2
ZXJTaWduIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0dkNqei/
yW/6JO5Wc7YT0C4NnfG/7TxWnxjFjMkdi2adIiSYRJmYkKyY7VKVYAjSIdpOelaO
cjfkWiLKYUVa+Bznik0EASFwGcWh12YgscLaFwaPINsO0EbU77Akx+ObdvXJwtIE
CSL8sGX/bPbWKZdjJQjtkNaK/IkHvazrAxZjeuqj+IKGdFT3dabWXLKkqqx/s3C8
TiXHW8YDXaqxteXa+CzXsTI9dPm6C9PQ5wMaZFc7bMOxi3jiA9CVt4Scb/VRWRWB
86UxBpD5Aw0Wg9g4RrfG3vJbec5q6NU4gGINHDQJOj3ZoZmbWk6EVm22jH3sHa5I
aW84jH70y+nX7QIDAQABo4G1MIGyMA4GA1UdDwEB/wQEAwIBBjASBgNVHRMBAf8E
CDAGAQH/AgEAMB0GA1UdDgQWBBRIu6i/W4TSV0jkYemRIJHYHSXffzA5BgNVHR8E
MjAwMC6gLKAqhihodHRwOi8vY3JsLmdsb2JhbHNpZ24ubmV0L3ByaW1zZXJ2ZXIu
Y3JsMBEGCWCGSAGG+EIBAQQEAwICBDAfBgNVHSMEGDAWgBTRZoP1iV7Qvn9h0t2o
yvorekp/MTANBgkqhkiG9w0BAQUFAAOCAQEAP/iVafKvW0zupGPQ/4Kc2OqZSCLo
lwkE0+tsZzH7q/oIL5o1HKzEA4acHOHMoxZ7PrUL24sZz+9KoGxsZaz3+pj7JSih
/k0kFaLkJ+jcDqGz441uhRWRfP0Nv8o/GvMsGxAwZHUa3cW1ytEKHUvzgSnKqr0o
rGbJSoAb59oezXnB6YWkel+4840tciE/DwwYfBFL7Kq6SFdSM8ioDsOfz7bsDbnt
nk67vMUgBiiiFFoQymb++pOpIMBYV5Bvqtc5vUGla6fOL53iU4GiwPnUEMqVwpra
HBtFP+DIpNCr0Iai5G1wY5rfdmdz9TaJPi3YtwXLdNfZAf9KfJv5q547rQ==
</ds:X509Certificate>
				</ds:X509Data>
			</ds:KeyInfo>
				
			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<!--
			
					Thawte Premium Server CA
					
					* C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc,
                                            OU=Certification Services Division, CN=Thawte Premium Server CA
                                               /emailAddress=premium-server@thawte.com
					
						This is used to sign individual certificates directly with no intermediates.
						
					No intermediates, so requires a verification depth of at least 1.
	
					Validity
						Not Before: Aug  1 00:00:00 1996 GMT
						Not After : Dec 31 23:59:59 2020 GMT

				-->
				<ds:X509Data>
					<ds:X509Certificate>MIIDJzCCApCgAwIBAgIBATANBgkqhkiG9w0BAQQFADCBzjELMAkGA1UEBhMCWkEx
FTATBgNVBAgTDFdlc3Rlcm4gQ2FwZTESMBAGA1UEBxMJQ2FwZSBUb3duMR0wGwYD
VQQKExRUaGF3dGUgQ29uc3VsdGluZyBjYzEoMCYGA1UECxMfQ2VydGlmaWNhdGlv
biBTZXJ2aWNlcyBEaXZpc2lvbjEhMB8GA1UEAxMYVGhhd3RlIFByZW1pdW0gU2Vy
dmVyIENBMSgwJgYJKoZIhvcNAQkBFhlwcmVtaXVtLXNlcnZlckB0aGF3dGUuY29t
MB4XDTk2MDgwMTAwMDAwMFoXDTIwMTIzMTIzNTk1OVowgc4xCzAJBgNVBAYTAlpB
MRUwEwYDVQQIEwxXZXN0ZXJuIENhcGUxEjAQBgNVBAcTCUNhcGUgVG93bjEdMBsG
A1UEChMUVGhhd3RlIENvbnN1bHRpbmcgY2MxKDAmBgNVBAsTH0NlcnRpZmljYXRp
b24gU2VydmljZXMgRGl2aXNpb24xITAfBgNVBAMTGFRoYXd0ZSBQcmVtaXVtIFNl
cnZlciBDQTEoMCYGCSqGSIb3DQEJARYZcHJlbWl1bS1zZXJ2ZXJAdGhhd3RlLmNv
bTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA0jY2aovXwlue2oFBYo847kkE
VdbQ7xwblRZH7xhINTpS9CtqBo87L+pW46+GjZ4X9560ZXUCTe/LCaIhUdib0GfQ
ug2SBhRz1JPLlyoAnFxODLz6FVL88kRu2hFKbgifLy3j+ao6hnO2RlNYyIkFvYMR
uHM/qgeN9EJN50CdHDcCAwEAAaMTMBEwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG
9w0BAQQFAAOBgQAmSCwWwlj66BZ0DKqqX1Q/8tfJeGBeXm43YyJ3Nn6yF8Q0ufUI
hfzJATj/Tb7yFkJD57taRvvBxhEf8UqwKEbJw8RCfbz6q1lu1bdRiBHjpIUZa4JM
pAwSremkrj/xw0llmozFyD4lt5SZu5IycQfwhl7tUCemDaYj+bvLpgcUQg==
</ds:X509Certificate>
				</ds:X509Data>
			</ds:KeyInfo>
				
		</shibmeta:KeyAuthority>
	</Extensions>
	
	
	
<EntityDescriptor ID="uk000001" entityID="urn:mace:ac.uk:sdss.ac.uk:provider:service:target.iay.org.uk">
    <!--
        This is an SDSS project test SP running outside the University environment.
    -->
    <Extensions>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>
    </Extensions>
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>target.iay.org.uk</ds:KeyName>
                <ds:X509Data>
                    <ds:X509Certificate>
                        MIIDBzCCAnCgAwIBAgIBBTANBgkqhkiG9w0BAQUFADBIMQswCQYDVQQGEwJHQjEn
                        MCUGA1UEChMeSklTQyBDb3JlIE1pZGRsZXdhcmUgUHJvZ3JhbW1lMRAwDgYDVQQD
                        EwdTRFNTIENBMB4XDTA0MDkyMjExMzMxMVoXDTA4MTIzMTAwMDAwMFowaTELMAkG
                        A1UEBhMCR0IxJzAlBgNVBAoTHkpJU0MgQ29yZSBNaWRkbGV3YXJlIFByb2dyYW1t
                        ZTEVMBMGA1UECxMMU0RTUyBQcm9qZWN0MRowGAYDVQQDExF0YXJnZXQuaWF5Lm9y
                        Zy51azCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA34CHuV6Jl29eJJfZKowR
                        7sTjBDUjSfJ3/Bnr84Zsl7GKyN6Lk39Xlf429KYECVEqJc3bBvXajoWkIOyZa9Db
                        5qxS8iFLMIdRgEYdrUBCJXSgQrjRb+duaVEJVigSnhAFFXTsPib8UFI1HtJ9v2N5
                        g0PQC0qTF3/BoFz5lOt7U7kCAwEAAaOB3zCB3DAJBgNVHRMEAjAAMAsGA1UdDwQE
                        AwIEsDAxBgNVHR8EKjAoMCagJKAihiBodHRwOi8vc2Rzcy5hYy51ay9jYS9zZHNz
                        LWNhLmNybDAdBgNVHQ4EFgQUciNzXnxVmc0BV758CYOesfhLzucwcAYDVR0jBGkw
                        Z4AUvq0gh0kHZ3Eez9e6q0CKdxYdK8ChTKRKMEgxCzAJBgNVBAYTAkdCMScwJQYD
                        VQQKEx5KSVNDIENvcmUgTWlkZGxld2FyZSBQcm9ncmFtbWUxEDAOBgNVBAMTB1NE
                        U1MgQ0GCAQAwDQYJKoZIhvcNAQEFBQADgYEACoQ25YbR7bYo0nRKsXOEGDE7urlL
                        R+F7c/VnF11t1iPK3aeP/ndQo1WbPDb4CXaS5HERVocmAS8F8wdTDFjIjN2yyf+I
                        kkfQOueJ1tVBRnpciNO6emQ3i0C5FrGJjtZK/kpt9zOAX9rxmTQmjuQzF9M74jVm
                        iFR3yx2meMGHQPk=
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://target.iay.org.uk/Shibboleth.sso/SAML/POST" index="3"></AssertionConsumerService>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://target.iay.org.uk/Shibboleth.sso/SAML/Artifact" index="4"></AssertionConsumerService>
    </SPSSODescriptor>
    <Organization>
        <OrganizationName xml:lang="en">Ian A. Young</OrganizationName>
        <OrganizationDisplayName xml:lang="en">SDSS Fountainhall</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://sdss.ac.uk/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Ian</GivenName>
        <SurName>Young</SurName>
        <EmailAddress>mailto:ian@iay.org.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Ian</GivenName>
        <SurName>Young</SurName>
        <EmailAddress>mailto:ian@iay.org.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Ian</GivenName>
        <SurName>Young</SurName>
        <EmailAddress>mailto:ian@iay.org.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000003" entityID="urn:mace:eduserv.org.uk:athens:federation:beta">
    <!--
        This is a beta Athens/Shibboleth gateway. The entity is a combined IdP and SP.
    -->
    <Extensions>
        <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">athensams.net</shibmeta:Scope>
        <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">test.athensams.net</shibmeta:Scope>
        <wayf:HideFromWAYF xmlns:wayf="http://sdss.ac.uk/2006/06/WAYF">
            <!-- omit this entity from the SDSS Federation WAYF -->				
        </wayf:HideFromWAYF>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>
        <AthensPUIDAuthority xmlns="http://eduserv.org.uk/labels"></AthensPUIDAuthority>
    </Extensions>
    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">athensams.net</shibmeta:Scope>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">test.athensams.net</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:X509Data>
                    <ds:X509Certificate>
                        MIIDJDCCAo2gAwIBAgIQGr7rfjevEA6rgm90E4sAsjANBgkqhkiG9w0BAQUFADBM
                        MQswCQYDVQQGEwJaQTElMCMGA1UEChMcVGhhd3RlIENvbnN1bHRpbmcgKFB0eSkg
                        THRkLjEWMBQGA1UEAxMNVGhhd3RlIFNHQyBDQTAeFw0wODA2MjUxNDA3NTVaFw0w
                        OTA2MjIxMzM3NDVaMGsxCzAJBgNVBAYTAkdCMQ0wCwYDVQQIEwRCYXRoMQ0wCwYD
                        VQQHEwRCYXRoMRAwDgYDVQQKEwdFZHVzZXJ2MQ8wDQYDVQQLEwZBdGhlbnMxGzAZ
                        BgNVBAMTEmJldGEuYXRoZW5zYW1zLm5ldDCBnzANBgkqhkiG9w0BAQEFAAOBjQAw
                        gYkCgYEA4wbVkBSqXXuj/Gf0Gr4BA2Ax/xxlh/J7csac/p9SmF1mKnkKhtBGQYeA
                        Mckrh8FgZeU02QGiqI9T4JnEA3Dst/Sn1MDKQg826Co84eTZBZSJ0aX04eOglacx
                        AsEbjAc5zeA1egElzjZUp/Zaa8azEurGFg4MeYS6mTJLyjs5sSECAwEAAaOB5zCB
                        5DAoBgNVHSUEITAfBggrBgEFBQcDAQYIKwYBBQUHAwIGCWCGSAGG+EIEATA2BgNV
                        HR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnRoYXd0ZS5jb20vVGhhd3RlU0dDQ0Eu
                        Y3JsMHIGCCsGAQUFBwEBBGYwZDAiBggrBgEFBQcwAYYWaHR0cDovL29jc3AudGhh
                        d3RlLmNvbTA+BggrBgEFBQcwAoYyaHR0cDovL3d3dy50aGF3dGUuY29tL3JlcG9z
                        aXRvcnkvVGhhd3RlX1NHQ19DQS5jcnQwDAYDVR0TAQH/BAIwADANBgkqhkiG9w0B
                        AQUFAAOBgQCov+VddLPoG4yWNDDzYlK7nLtA4/cKWIj1OR9b/bS3D2O0r2XOB3fN
                        uBnTEzt/2Mk8P7Ci6IAnXQnYmi6EMCzNrQqHY3Ab8qXQ3hZhpYxx5GPDySB09jb9
                        RDrUW5ij/R/gO9zmJlG3PJapkB1Bf3ExCYvCxeiwbRV3kw4e3GkXAg==
                    </ds:X509Certificate>
                </ds:X509Data>                
            </ds:KeyInfo>
        </KeyDescriptor>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://gateway.athensams.net:5057/services/SAML11ArtifactResolver" index="0"></ArtifactResolutionService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://beta.athensams.net"></SingleSignOnService>
    </IDPSSODescriptor>
    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">athensams.net</shibmeta:Scope>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">test.athensams.net</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:X509Data>
                    <ds:X509Certificate>
                        MIIDJDCCAo2gAwIBAgIQGr7rfjevEA6rgm90E4sAsjANBgkqhkiG9w0BAQUFADBM
                        MQswCQYDVQQGEwJaQTElMCMGA1UEChMcVGhhd3RlIENvbnN1bHRpbmcgKFB0eSkg
                        THRkLjEWMBQGA1UEAxMNVGhhd3RlIFNHQyBDQTAeFw0wODA2MjUxNDA3NTVaFw0w
                        OTA2MjIxMzM3NDVaMGsxCzAJBgNVBAYTAkdCMQ0wCwYDVQQIEwRCYXRoMQ0wCwYD
                        VQQHEwRCYXRoMRAwDgYDVQQKEwdFZHVzZXJ2MQ8wDQYDVQQLEwZBdGhlbnMxGzAZ
                        BgNVBAMTEmJldGEuYXRoZW5zYW1zLm5ldDCBnzANBgkqhkiG9w0BAQEFAAOBjQAw
                        gYkCgYEA4wbVkBSqXXuj/Gf0Gr4BA2Ax/xxlh/J7csac/p9SmF1mKnkKhtBGQYeA
                        Mckrh8FgZeU02QGiqI9T4JnEA3Dst/Sn1MDKQg826Co84eTZBZSJ0aX04eOglacx
                        AsEbjAc5zeA1egElzjZUp/Zaa8azEurGFg4MeYS6mTJLyjs5sSECAwEAAaOB5zCB
                        5DAoBgNVHSUEITAfBggrBgEFBQcDAQYIKwYBBQUHAwIGCWCGSAGG+EIEATA2BgNV
                        HR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnRoYXd0ZS5jb20vVGhhd3RlU0dDQ0Eu
                        Y3JsMHIGCCsGAQUFBwEBBGYwZDAiBggrBgEFBQcwAYYWaHR0cDovL29jc3AudGhh
                        d3RlLmNvbTA+BggrBgEFBQcwAoYyaHR0cDovL3d3dy50aGF3dGUuY29tL3JlcG9z
                        aXRvcnkvVGhhd3RlX1NHQ19DQS5jcnQwDAYDVR0TAQH/BAIwADANBgkqhkiG9w0B
                        AQUFAAOBgQCov+VddLPoG4yWNDDzYlK7nLtA4/cKWIj1OR9b/bS3D2O0r2XOB3fN
                        uBnTEzt/2Mk8P7Ci6IAnXQnYmi6EMCzNrQqHY3Ab8qXQ3hZhpYxx5GPDySB09jb9
                        RDrUW5ij/R/gO9zmJlG3PJapkB1Bf3ExCYvCxeiwbRV3kw4e3GkXAg==
                    </ds:X509Certificate>
                </ds:X509Data>                
            </ds:KeyInfo>
        </KeyDescriptor>
        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://beta.athensams.net:5057/services/SAML11AttributeAuthority"></AttributeService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
    </AttributeAuthorityDescriptor> 
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:X509Data>
                    <ds:X509Certificate>
                        MIIDJDCCAo2gAwIBAgIQGr7rfjevEA6rgm90E4sAsjANBgkqhkiG9w0BAQUFADBM
                        MQswCQYDVQQGEwJaQTElMCMGA1UEChMcVGhhd3RlIENvbnN1bHRpbmcgKFB0eSkg
                        THRkLjEWMBQGA1UEAxMNVGhhd3RlIFNHQyBDQTAeFw0wODA2MjUxNDA3NTVaFw0w
                        OTA2MjIxMzM3NDVaMGsxCzAJBgNVBAYTAkdCMQ0wCwYDVQQIEwRCYXRoMQ0wCwYD
                        VQQHEwRCYXRoMRAwDgYDVQQKEwdFZHVzZXJ2MQ8wDQYDVQQLEwZBdGhlbnMxGzAZ
                        BgNVBAMTEmJldGEuYXRoZW5zYW1zLm5ldDCBnzANBgkqhkiG9w0BAQEFAAOBjQAw
                        gYkCgYEA4wbVkBSqXXuj/Gf0Gr4BA2Ax/xxlh/J7csac/p9SmF1mKnkKhtBGQYeA
                        Mckrh8FgZeU02QGiqI9T4JnEA3Dst/Sn1MDKQg826Co84eTZBZSJ0aX04eOglacx
                        AsEbjAc5zeA1egElzjZUp/Zaa8azEurGFg4MeYS6mTJLyjs5sSECAwEAAaOB5zCB
                        5DAoBgNVHSUEITAfBggrBgEFBQcDAQYIKwYBBQUHAwIGCWCGSAGG+EIEATA2BgNV
                        HR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnRoYXd0ZS5jb20vVGhhd3RlU0dDQ0Eu
                        Y3JsMHIGCCsGAQUFBwEBBGYwZDAiBggrBgEFBQcwAYYWaHR0cDovL29jc3AudGhh
                        d3RlLmNvbTA+BggrBgEFBQcwAoYyaHR0cDovL3d3dy50aGF3dGUuY29tL3JlcG9z
                        aXRvcnkvVGhhd3RlX1NHQ19DQS5jcnQwDAYDVR0TAQH/BAIwADANBgkqhkiG9w0B
                        AQUFAAOBgQCov+VddLPoG4yWNDDzYlK7nLtA4/cKWIj1OR9b/bS3D2O0r2XOB3fN
                        uBnTEzt/2Mk8P7Ci6IAnXQnYmi6EMCzNrQqHY3Ab8qXQ3hZhpYxx5GPDySB09jb9
                        RDrUW5ij/R/gO9zmJlG3PJapkB1Bf3ExCYvCxeiwbRV3kw4e3GkXAg==
                    </ds:X509Certificate>
                </ds:X509Data>                
            </ds:KeyInfo>
        </KeyDescriptor>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://beta.athensams.net/saml/AfctRcv" index="0"></AssertionConsumerService>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://beta.athensams.net/saml/PostRcv" index="1"></AssertionConsumerService>
    </SPSSODescriptor>
    <Organization>
        <OrganizationName xml:lang="en">Eduserv</OrganizationName>
        <OrganizationDisplayName xml:lang="en">Eduserv Athens (Beta)</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://www.athensams.net/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Athens Helpdesk</GivenName>
        <EmailAddress>mailto:athenshelp@eduserv.org.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Athens Helpdesk</GivenName>
        <EmailAddress>mailto:athenshelp@eduserv.org.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Athens Helpdesk</GivenName>
        <EmailAddress>mailto:athenshelp@eduserv.org.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000004" entityID="https://typekey.sdss.ac.uk/shibboleth">
    <!--
        This is an SDSS project site running a TypeKey to Shibboleth bridge.
    -->
    <Extensions>
        <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">typekey.sdss.ac.uk</shibmeta:Scope>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>
    </Extensions>
    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">typekey.sdss.ac.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>typekey.sdss.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://typekey.sdss.ac.uk:8443/typekey/Artifact" index="1"></ArtifactResolutionService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://typekey.sdss.ac.uk/typekey/SSO"></SingleSignOnService>
    </IDPSSODescriptor>
    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">typekey.sdss.ac.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>typekey.sdss.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://typekey.sdss.ac.uk:8443/typekey/AA"></AttributeService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
    </AttributeAuthorityDescriptor>
    <Organization>
        <OrganizationName xml:lang="en">University of Edinburgh</OrganizationName>
        <OrganizationDisplayName xml:lang="en">JISC project: SDSS (TypeKey Bridge)</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://sdss.ac.uk/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>SDSS Support List</GivenName>
        <EmailAddress>mailto:sdss-support@lists.ed.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Ian</GivenName>
        <SurName>Young</SurName>
        <EmailAddress>mailto:ian@iay.org.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Alan</GivenName>
        <SurName>Ferguson</SurName>
        <EmailAddress>mailto:Alan.Ferguson@ed.ac.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000005" entityID="https://typekey.iay.org.uk/shibboleth">
    <!--
        This is an SDSS project IdP running outside the University environment.
        This variation is an experimental TypeKey to Shibboleth bridge.
    -->
    <Extensions>
        <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">typekey.iay.org.uk</shibmeta:Scope>
        <wayf:HideFromWAYF xmlns:wayf="http://sdss.ac.uk/2006/06/WAYF"></wayf:HideFromWAYF>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>
    </Extensions>
    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">typekey.iay.org.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>typekey.iay.org.uk</ds:KeyName>
                <ds:X509Data>
                    <ds:X509Certificate>
                        MIIDCDCCAnGgAwIBAgIBNDANBgkqhkiG9w0BAQUFADBIMQswCQYDVQQGEwJHQjEn
                        MCUGA1UEChMeSklTQyBDb3JlIE1pZGRsZXdhcmUgUHJvZ3JhbW1lMRAwDgYDVQQD
                        EwdTRFNTIENBMB4XDTA2MDUwMzEzMDgwNloXDTA4MTIzMTAwMDAwMFowajELMAkG
                        A1UEBhMCR0IxJzAlBgNVBAoTHkpJU0MgQ29yZSBNaWRkbGV3YXJlIFByb2dyYW1t
                        ZTEVMBMGA1UECxMMU0RTUyBQcm9qZWN0MRswGQYDVQQDExJ0eXBla2V5LmlheS5v
                        cmcudWswgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBALht9nI6ptlFxZWEl2vV
                        43Xptz2gHrUQDClrHW5cBSnjv1enxv/SuguS+O6l99TP8gBojrEBWHYfzFEMz+z+
                        FzsbBzdOVn9aopF/TNF3fxM/oA43UYDGa5iBdSBYASQmdoBAOITYdy0M7rODNR2R
                        srxb7LeucEGxnLVmPGoxqHQ3AgMBAAGjgd8wgdwwCQYDVR0TBAIwADALBgNVHQ8E
                        BAMCBLAwMQYDVR0fBCowKDAmoCSgIoYgaHR0cDovL3Nkc3MuYWMudWsvY2Evc2Rz
                        cy1jYS5jcmwwHQYDVR0OBBYEFKVL9TFhqUcGuePLcLVqvveSZD5NMHAGA1UdIwRp
                        MGeAFL6tIIdJB2dxHs/XuqtAincWHSvAoUykSjBIMQswCQYDVQQGEwJHQjEnMCUG
                        A1UEChMeSklTQyBDb3JlIE1pZGRsZXdhcmUgUHJvZ3JhbW1lMRAwDgYDVQQDEwdT
                        RFNTIENBggEAMA0GCSqGSIb3DQEBBQUAA4GBAJn9Av00NfMQVTgf7G2LIaikA3pJ
                        XlwW0jDNP7lr8UUokq0dSVbMbs5LqrahqYOyXVe9EU13Vu64b+RIMS/40lSGOsdY
                        q0uInD4DEDadSbqbWsww4CrH0GrrCf/MYS6YP8BwtHdLnFGqaKkMcLiBovRtBdxI
                        PiGb0i1oYBRRNGeI
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://typekey.iay.org.uk:8451/typekey/Artifact" index="1"></ArtifactResolutionService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://typekey.iay.org.uk:8450/typekey/SSO"></SingleSignOnService>
    </IDPSSODescriptor>
    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">typekey.iay.org.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>typekey.iay.org.uk</ds:KeyName>
                <ds:X509Data>
                    <ds:X509Certificate>
                        MIIDCDCCAnGgAwIBAgIBNDANBgkqhkiG9w0BAQUFADBIMQswCQYDVQQGEwJHQjEn
                        MCUGA1UEChMeSklTQyBDb3JlIE1pZGRsZXdhcmUgUHJvZ3JhbW1lMRAwDgYDVQQD
                        EwdTRFNTIENBMB4XDTA2MDUwMzEzMDgwNloXDTA4MTIzMTAwMDAwMFowajELMAkG
                        A1UEBhMCR0IxJzAlBgNVBAoTHkpJU0MgQ29yZSBNaWRkbGV3YXJlIFByb2dyYW1t
                        ZTEVMBMGA1UECxMMU0RTUyBQcm9qZWN0MRswGQYDVQQDExJ0eXBla2V5LmlheS5v
                        cmcudWswgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBALht9nI6ptlFxZWEl2vV
                        43Xptz2gHrUQDClrHW5cBSnjv1enxv/SuguS+O6l99TP8gBojrEBWHYfzFEMz+z+
                        FzsbBzdOVn9aopF/TNF3fxM/oA43UYDGa5iBdSBYASQmdoBAOITYdy0M7rODNR2R
                        srxb7LeucEGxnLVmPGoxqHQ3AgMBAAGjgd8wgdwwCQYDVR0TBAIwADALBgNVHQ8E
                        BAMCBLAwMQYDVR0fBCowKDAmoCSgIoYgaHR0cDovL3Nkc3MuYWMudWsvY2Evc2Rz
                        cy1jYS5jcmwwHQYDVR0OBBYEFKVL9TFhqUcGuePLcLVqvveSZD5NMHAGA1UdIwRp
                        MGeAFL6tIIdJB2dxHs/XuqtAincWHSvAoUykSjBIMQswCQYDVQQGEwJHQjEnMCUG
                        A1UEChMeSklTQyBDb3JlIE1pZGRsZXdhcmUgUHJvZ3JhbW1lMRAwDgYDVQQDEwdT
                        RFNTIENBggEAMA0GCSqGSIb3DQEBBQUAA4GBAJn9Av00NfMQVTgf7G2LIaikA3pJ
                        XlwW0jDNP7lr8UUokq0dSVbMbs5LqrahqYOyXVe9EU13Vu64b+RIMS/40lSGOsdY
                        q0uInD4DEDadSbqbWsww4CrH0GrrCf/MYS6YP8BwtHdLnFGqaKkMcLiBovRtBdxI
                        PiGb0i1oYBRRNGeI
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://typekey.iay.org.uk:8451/typekey/AA"></AttributeService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
    </AttributeAuthorityDescriptor>
    <Organization>
        <OrganizationName xml:lang="en">Ian A. Young</OrganizationName>
        <OrganizationDisplayName xml:lang="en">JISC project: SDSS (Fountainhall TypeKey)</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://sdss.ac.uk/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Ian</GivenName>
        <SurName>Young</SurName>
        <EmailAddress>mailto:ian@iay.org.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Ian</GivenName>
        <SurName>Young</SurName>
        <EmailAddress>mailto:ian@iay.org.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Ian</GivenName>
        <SurName>Young</SurName>
        <EmailAddress>mailto:ian@iay.org.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000006" entityID="https://idp2.iay.org.uk/idp/shibboleth">
    <!--
        This is an SDSS project test IdP running outside the University environment.
    -->
    <Extensions>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>
        <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">iay.org.uk</shibmeta:Scope>
    </Extensions>
    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0 urn:oasis:names:tc:SAML:2.0:protocol">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">iay.org.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:X509Data>
                    <ds:X509Certificate>
                        MIIDSTCCAjGgAwIBAgIhAMSPOSGN+3UUTXSKV+2EBOuF3x/pwPX/TD9GfyEkzLp+
                        MA0GCSqGSIb3DQEBBQUAMFgxGDAWBgNVBAMMD2lkcDIuaWF5Lm9yZy51azETMBEG
                        CgmSJomT8ixkARkWA2lheTETMBEGCgmSJomT8ixkARkWA29yZzESMBAGCgmSJomT
                        8ixkARkWAnVrMB4XDTA4MDIyNTEwMzAxNFoXDTI4MDIyNTEwMzAxNFowWDEYMBYG
                        A1UEAwwPaWRwMi5pYXkub3JnLnVrMRMwEQYKCZImiZPyLGQBGRYDaWF5MRMwEQYK
                        CZImiZPyLGQBGRYDb3JnMRIwEAYKCZImiZPyLGQBGRYCdWswggEiMA0GCSqGSIb3
                        DQEBAQUAA4IBDwAwggEKAoIBAQCb6ts48g10XHTnpy+23huzR184aahkrG0AoeUl
                        FVlomPjoFDk6czq0S3Qyd+ceF7tMRu3XzS7cMmtVH53O9d+wCs8aPQcPXxHQ5gLk
                        L7Gu6eJ+3N3jXhpt7/DDPhnzFPNW3EVMueHJ/0IzyspTvq2LPbNWXJ86NKJ+gesZ
                        QftskwXScOjpoJEIP0EA890QYd4WdYtQPqVV+LPKtnYBoGOnuRhSAM1D/EhCbeb0
                        lCmRGcdGbDFBchiPO4VLGl85sLa0EhjxMIPAOKXcj8bBlO9Ww9kkG06kQp6eLHwm
                        Jmt7VNKveCGhyF2QH/CvmdUaPv3gcp1UjrlqFN9LBVSaTIL/AgMBAAEwDQYJKoZI
                        hvcNAQEFBQADggEBAG+jDBAtlKoHaEBB+l6PpW5zuiDjyHG4zZZYqX77mZ9xP/xe
                        Kn0yJ18ZLjS3b9WztGLYyC4SJHSF2okq1K02bqsCv9YeP+UWpw2uRR8jt96lLWxZ
                        jTjoko2v8jBtzDk8LZsqw58m4vZ0AGNZjKeGIywKhxnepwREguyj3bjBpZAGgl0M
                        HQuXoO/BDC9yKyZslE5CpWp5xP4XzY2/LrorrkwOJLnFuk1sox4/gvkDQukUx/jr
                        YRbrWfOjcNBx3LE/HI6RNLINicK7yUwerDE86nix5Zc3hskVcCykW+r6HbY6bx7P
                        YmNKYMZhQAgDtXIjFHOy+WbyVTidmJvxM9UeYCY=
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp2.iay.org.uk:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"></ArtifactResolutionService>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp2.iay.org.uk:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"></ArtifactResolutionService>

        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>

        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp2.iay.org.uk/idp/profile/Shibboleth/SSO"></SingleSignOnService>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp2.iay.org.uk/idp/profile/SAML2/POST/SSO"></SingleSignOnService>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp2.iay.org.uk/idp/profile/SAML2/POST-SimpleSign/SSO"></SingleSignOnService>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp2.iay.org.uk/idp/profile/SAML2/Redirect/SSO"></SingleSignOnService>
    </IDPSSODescriptor>
    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">iay.org.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:X509Data>
                    <ds:X509Certificate>
                        MIIDSTCCAjGgAwIBAgIhAMSPOSGN+3UUTXSKV+2EBOuF3x/pwPX/TD9GfyEkzLp+
                        MA0GCSqGSIb3DQEBBQUAMFgxGDAWBgNVBAMMD2lkcDIuaWF5Lm9yZy51azETMBEG
                        CgmSJomT8ixkARkWA2lheTETMBEGCgmSJomT8ixkARkWA29yZzESMBAGCgmSJomT
                        8ixkARkWAnVrMB4XDTA4MDIyNTEwMzAxNFoXDTI4MDIyNTEwMzAxNFowWDEYMBYG
                        A1UEAwwPaWRwMi5pYXkub3JnLnVrMRMwEQYKCZImiZPyLGQBGRYDaWF5MRMwEQYK
                        CZImiZPyLGQBGRYDb3JnMRIwEAYKCZImiZPyLGQBGRYCdWswggEiMA0GCSqGSIb3
                        DQEBAQUAA4IBDwAwggEKAoIBAQCb6ts48g10XHTnpy+23huzR184aahkrG0AoeUl
                        FVlomPjoFDk6czq0S3Qyd+ceF7tMRu3XzS7cMmtVH53O9d+wCs8aPQcPXxHQ5gLk
                        L7Gu6eJ+3N3jXhpt7/DDPhnzFPNW3EVMueHJ/0IzyspTvq2LPbNWXJ86NKJ+gesZ
                        QftskwXScOjpoJEIP0EA890QYd4WdYtQPqVV+LPKtnYBoGOnuRhSAM1D/EhCbeb0
                        lCmRGcdGbDFBchiPO4VLGl85sLa0EhjxMIPAOKXcj8bBlO9Ww9kkG06kQp6eLHwm
                        Jmt7VNKveCGhyF2QH/CvmdUaPv3gcp1UjrlqFN9LBVSaTIL/AgMBAAEwDQYJKoZI
                        hvcNAQEFBQADggEBAG+jDBAtlKoHaEBB+l6PpW5zuiDjyHG4zZZYqX77mZ9xP/xe
                        Kn0yJ18ZLjS3b9WztGLYyC4SJHSF2okq1K02bqsCv9YeP+UWpw2uRR8jt96lLWxZ
                        jTjoko2v8jBtzDk8LZsqw58m4vZ0AGNZjKeGIywKhxnepwREguyj3bjBpZAGgl0M
                        HQuXoO/BDC9yKyZslE5CpWp5xP4XzY2/LrorrkwOJLnFuk1sox4/gvkDQukUx/jr
                        YRbrWfOjcNBx3LE/HI6RNLINicK7yUwerDE86nix5Zc3hskVcCykW+r6HbY6bx7P
                        YmNKYMZhQAgDtXIjFHOy+WbyVTidmJvxM9UeYCY=
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp2.iay.org.uk:8443/idp/profile/SAML1/SOAP/AttributeQuery"></AttributeService>
        <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp2.iay.org.uk:8443/idp/profile/SAML2/SOAP/AttributeQuery"></AttributeService>

        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>    
    </AttributeAuthorityDescriptor>
    <Organization>
        <OrganizationName xml:lang="en">Ian A. Young</OrganizationName>
        <OrganizationDisplayName xml:lang="en">JISC project: SDSS (Fountainhall)</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://sdss.ac.uk/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Ian</GivenName>
        <SurName>Young</SurName>
        <EmailAddress>mailto:ian@iay.org.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Ian</GivenName>
        <SurName>Young</SurName>
        <EmailAddress>mailto:ian@iay.org.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Ian</GivenName>
        <SurName>Young</SurName>
        <EmailAddress>mailto:ian@iay.org.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000007" entityID="https://sh2testsp1.iay.org.uk/shibboleth">
    <!--
        This is an SDSS project test SP running outside the University environment.
    -->
    <Extensions>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy> 
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>
    </Extensions>
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <Extensions>
            <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://sh2testsp1.iay.org.uk/Shibboleth.sso/DS" index="1"></idpdisc:DiscoveryResponse>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>sh2testsp1.iay.org.uk</ds:KeyName>
                <ds:X509Data>
                    <ds:X509Certificate>
                        MIIDjzCCAvigAwIBAgIBUTANBgkqhkiG9w0BAQUFADBIMQswCQYDVQQGEwJHQjEn
                        MCUGA1UEChMeSklTQyBDb3JlIE1pZGRsZXdhcmUgUHJvZ3JhbW1lMRAwDgYDVQQD
                        EwdTRFNTIENBMB4XDTA3MDcxNjExMTUwMloXDTA4MTIzMTAwMDAwMFowbTELMAkG
                        A1UEBhMCR0IxJzAlBgNVBAoTHkpJU0MgQ29yZSBNaWRkbGV3YXJlIFByb2dyYW1t
                        ZTEVMBMGA1UECxMMU0RTUyBQcm9qZWN0MR4wHAYDVQQDExVzaDJ0ZXN0c3AxLmlh
                        eS5vcmcudWswggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDjn5vEtcuR
                        ZwsqQdwlHKGE8YeWkLvvoPRcvp88xQjuOrZU3fVXbn1JY2oArq5y9hujPJJQMNOy
                        9ESN7KFeH3I9qvZFZcl1gjw/arVzkNETsnXHU/Gc7Oj+lPCCWwUxIefSn5wttXoS
                        VGqJBvctZquHXbTj62Vei1/VhlTixFYqbLHXfDgK4RYOD6QZlgHobr0Hye8yPs6s
                        KdDbu+DhmnbtoG5y7Y5/b24SyV9p1eCbOdhYEdc+NijccDPN/Ms/Ub7zI/Rj9F6J
                        RfxcFlyMjGiYfMLeyiMTUbIC4R7AkoWiAs7ptddZ2XeuGCBjZOLQ5Xgj7sDrMaXV
                        nlFnzZQovlIRAgMBAAGjgd8wgdwwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwMQYD
                        VR0fBCowKDAmoCSgIoYgaHR0cDovL3Nkc3MuYWMudWsvY2Evc2Rzcy1jYS5jcmww
                        HQYDVR0OBBYEFLYTfNB3+zufAcpluCuJtXMKzEOTMHAGA1UdIwRpMGeAFL6tIIdJ
                        B2dxHs/XuqtAincWHSvAoUykSjBIMQswCQYDVQQGEwJHQjEnMCUGA1UEChMeSklT
                        QyBDb3JlIE1pZGRsZXdhcmUgUHJvZ3JhbW1lMRAwDgYDVQQDEwdTRFNTIENBggEA
                        MA0GCSqGSIb3DQEBBQUAA4GBAErZS6zZjpTbcRv3VsYxHafT+WQdoVAL4ARnXYhm
                        9iAxbAn8ubhpm2XgZyoO28ZB+JP1yJ5lKFi+YDOatRO+DozIuhZmLtPuoSWrxyI2
                        KtHzt7GYSgOT4wz343tv1ROC/geLdA4rN5KcbISgHYbbHoR8TD9XDVASPg8wAdBv
                        j1pm
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://sh2testsp1.iay.org.uk/Shibboleth.sso/SAML2/POST" index="1"></AssertionConsumerService>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://sh2testsp1.iay.org.uk/Shibboleth.sso/SAML2/POST-SimpleSign" index="2"></AssertionConsumerService>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://sh2testsp1.iay.org.uk/Shibboleth.sso/SAML2/Artifact" index="3"></AssertionConsumerService>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://sh2testsp1.iay.org.uk/Shibboleth.sso/SAML2/ECP" index="4"></AssertionConsumerService>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://sh2testsp1.iay.org.uk/Shibboleth.sso/SAML/POST" index="5"></AssertionConsumerService>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://sh2testsp1.iay.org.uk/Shibboleth.sso/SAML/Artifact" index="6"></AssertionConsumerService>
    </SPSSODescriptor>
    <Organization>
        <OrganizationName xml:lang="en">Ian A. Young</OrganizationName>
        <OrganizationDisplayName xml:lang="en">SDSS Fountainhall Shibboleth 2.0 Test SP 1</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://sdss.ac.uk/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Ian</GivenName>
        <SurName>Young</SurName>
        <EmailAddress>mailto:ian@iay.org.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Ian</GivenName>
        <SurName>Young</SurName>
        <EmailAddress>mailto:ian@iay.org.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Ian</GivenName>
        <SurName>Young</SurName>
        <EmailAddress>mailto:ian@iay.org.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000008" entityID="https://shibidp.ntu.ac.uk/shibboleth">
    <!--
        Identity Provider for Nottingham Trent University
    -->
    <Extensions>
        <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">ntu.ac.uk</shibmeta:Scope>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember> 
        <AccountableUsers xmlns="http://ukfederation.org.uk/2006/11/label"></AccountableUsers>
    </Extensions>
    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">ntu.ac.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>shibidp.ntu.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://shibidp.ntu.ac.uk/shibboleth-idp/SSO"></SingleSignOnService>
    </IDPSSODescriptor>
    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">ntu.ac.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>shibidp.ntu.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://shibidp.ntu.ac.uk:8443/shibboleth-idp/AA"></AttributeService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
    </AttributeAuthorityDescriptor>
    <Organization>
        <OrganizationName xml:lang="en">Nottingham Trent University</OrganizationName>
        <OrganizationDisplayName xml:lang="en">Nottingham Trent University</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://www.ntu.ac.uk/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Richard</GivenName>
        <SurName>Cross</SurName>
        <EmailAddress>mailto:richard.cross@ntu.ac.uk </EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Francis</GivenName>
        <SurName>Lowry</SurName>
        <EmailAddress>mailto:francis.lowry@ntu.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Julie</GivenName>
        <SurName>Redford</SurName>
        <EmailAddress>mailto:julie.redford@ntu.ac.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000009" entityID="urn:mace:ac.uk:sdss.ac.uk:provider:service:gilead.ncl.ac.uk">
    <!--
        This is an SP for metalib library software.
    -->
    <Extensions>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>
    </Extensions>
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <KeyDescriptor>
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>gilead.ncl.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://gilead.ncl.ac.uk/Shibboleth.sso/SAML/POST" index="0"></AssertionConsumerService>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://gilead.ncl.ac.uk:8331/Shibboleth.sso/SAML/POST" index="1"></AssertionConsumerService>
    </SPSSODescriptor>
    <Organization>
        <OrganizationName xml:lang="en">University of Newcastle upon Tyne</OrganizationName>
        <OrganizationDisplayName xml:lang="en">University of Newcastle Library Metalib test</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://www.ncl.ac.uk/iss/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Helpline</GivenName>
        <EmailAddress>mailto:webmaster@ncl.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Caleb</GivenName>
        <SurName>Racey</SurName>
        <EmailAddress>mailto:Caleb.Racey@ncl.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>John</GivenName>
        <SurName>Williams</SurName>
        <EmailAddress>mailto:John.Williams@ncl.ac.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000010" entityID="urn:mace:ac.uk:sdss.ac.uk:provider:identity:shib.ncl.ac.uk">
    <!--
        This is a test IdP for Newcastle University.
    -->
    <Extensions>
        <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">ncl.ac.uk</shibmeta:Scope>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember> 
        <AccountableUsers xmlns="http://ukfederation.org.uk/2006/11/label"></AccountableUsers>
        <wayf:HideFromWAYF xmlns:wayf="http://sdss.ac.uk/2006/06/WAYF"></wayf:HideFromWAYF>
    </Extensions>
    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">ncl.ac.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>shib.ncl.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://shib.ncl.ac.uk:8443/shibboleth/Artifact" index="1"></ArtifactResolutionService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://shib.ncl.ac.uk/shibboleth/HS"></SingleSignOnService>
    </IDPSSODescriptor>
    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">ncl.ac.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>shib.ncl.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://shib.ncl.ac.uk:8443/shibboleth/AA"></AttributeService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
    </AttributeAuthorityDescriptor>
    <Organization>
        <OrganizationName xml:lang="en">University of Newcastle upon Tyne</OrganizationName>
        <OrganizationDisplayName xml:lang="en">Newcastle University (test)</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://www.ncl.ac.uk/iss/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Helpline</GivenName>
        <EmailAddress>mailto:webmaster@ncl.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Caleb</GivenName>
        <SurName>Racey</SurName>
        <EmailAddress>mailto:Caleb.Racey@ncl.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Janet</GivenName>
        <SurName>Wheeler</SurName>
        <EmailAddress>mailto:J.E.Wheeler@ncl.ac.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000011" entityID="urn:mace:ac.uk:sdss.ac.uk:provider:service:cocoon.ncl.ac.uk">
    <!--
        This is a service provider for the University of Newcastle upon Tyne.
    -->
    <Extensions>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>
    </Extensions>
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <KeyDescriptor>
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>cocoon.ncl.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://cocoon.ncl.ac.uk/Shibboleth.sso/SAML/POST" index="0"></AssertionConsumerService>
    </SPSSODescriptor>
    <Organization>
        <OrganizationName xml:lang="en">University of Newcastle upon Tyne</OrganizationName>
        <OrganizationDisplayName xml:lang="en">Newcastle University: cocoon</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://www.ncl.ac.uk/iss/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Helpline</GivenName>
        <EmailAddress>mailto:webmaster@ncl.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Caleb</GivenName>
        <SurName>Racey</SurName>
        <EmailAddress>mailto:Caleb.Racey@ncl.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Janet</GivenName>
        <SurName>Wheeler</SurName>
        <EmailAddress>mailto:J.E.Wheeler@ncl.ac.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000012" entityID="https://dangermouse.ncl.ac.uk/shibboleth/metadata">
    <!--
        This is a Newcastle University IIS test service provider.
    -->
    <Extensions>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>
    </Extensions>
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <KeyDescriptor>
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>dangermouse.ncl.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://dangermouse.ncl.ac.uk/Shibboleth.sso/SAML/POST" index="0"></AssertionConsumerService>
    </SPSSODescriptor>
    <Organization>
        <OrganizationName xml:lang="en">University of Newcastle upon Tyne</OrganizationName>
        <OrganizationDisplayName xml:lang="en">Newcastle University: IIS test</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://www.ncl.ac.uk/iss/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Helpline</GivenName>
        <EmailAddress>mailto:webmaster@ncl.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Caleb</GivenName>
        <SurName>Racey</SurName>
        <EmailAddress>mailto:Caleb.Racey@ncl.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Janet</GivenName>
        <SurName>Wheeler</SurName>
        <EmailAddress>mailto:J.E.Wheeler@ncl.ac.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000013" entityID="urn:mace:ac.uk:sdss.ac.uk:provider:service:lists.ncl.ac.uk">
    <!--
        This is the Newcastle University's SP for a Sympa based list server.
    -->
    <Extensions>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>
    </Extensions>
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <KeyDescriptor>
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>lists.ncl.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://lists.ncl.ac.uk/Shibboleth.sso/SAML/POST" index="0"></AssertionConsumerService>
    </SPSSODescriptor>
    <Organization>
        <OrganizationName xml:lang="en">University of Newcastle upon Tyne</OrganizationName>
        <OrganizationDisplayName xml:lang="en">Newcastle University: lists</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://www.ncl.ac.uk/iss/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Helpline</GivenName>
        <EmailAddress>mailto:webmaster@ncl.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Caleb</GivenName>
        <SurName>Racey</SurName>
        <EmailAddress>mailto:Caleb.Racey@ncl.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Gavin</GivenName>
        <SurName>Younger</SurName>
        <EmailAddress>mailto:gavin.younger@ncl.ac.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000020" entityID="https://coursework.cs.ncl.ac.uk/shibboleth/metadata">
    <!--
        coursework.ncl.ac.uk is an SP for Newcastle University.
    -->
    <Extensions>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>
    </Extensions>
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <KeyDescriptor>
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>coursework.cs.ncl.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://coursework.cs.ncl.ac.uk/Shibboleth.sso/SAML/POST" index="0"></AssertionConsumerService>
    </SPSSODescriptor>
    <Organization>
        <OrganizationName xml:lang="en">University of Newcastle upon Tyne</OrganizationName>
        <OrganizationDisplayName xml:lang="en">Newcastle University: coursework</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://www.ncl.ac.uk/iss/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Helpline</GivenName>
        <EmailAddress>mailto:webmaster@ncl.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Lindsay</GivenName>
        <SurName>Marshall</SurName>
        <EmailAddress>mailto:Lindsay.Marshall@ncl.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Caleb</GivenName>
        <SurName>Racey</SurName>
        <EmailAddress>mailto:Caleb.Racey@ncl.ac.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000021" entityID="https://www.educationcity.com/sso/shib">
    <!--
        This is an SP for EducationCity, an organisation offering educational services to schoolchildren.
        They are known to I2Q.
        EducationCity are using their own SP implementation, which allows the two AssertionConsumerService
        elements below to have the same Location value.
    -->
    <Extensions>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>     
    </Extensions>
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>CN=www.educationcity.com, OU=IT, O=EducationCity Ltd, L=Melton Mowbray, S=Leicestershire, C=GB</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://www.educationcity.com/sso/shib/acs1/" index="0"></AssertionConsumerService>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://www.educationcity.com/sso/shib/acs1/" index="1"></AssertionConsumerService>
    </SPSSODescriptor>
    <Organization>
        <OrganizationName xml:lang="en">EducationCity Limited</OrganizationName>
        <OrganizationDisplayName xml:lang="en">EducationCity</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://www.educationcity.com/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Customer Support</GivenName>
        <EmailAddress>mailto:support@educationcity.com</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Tom</GivenName>
        <SurName>Morgan</SurName>
        <EmailAddress>mailto:tom@educationcity.com</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Tom</GivenName>
        <SurName>Morgan</SurName>
        <EmailAddress>mailto:tom@educationcity.com</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000023" entityID="https://shib.oerc.ox.ac.uk/shibboleth-sp">
    <!--
        This SP is used by the ShibGrid Project for test purposes in Oxford e-Research Centre(OeRC).
    -->
    <Extensions>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy> 
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>        
    </Extensions>
    <SPSSODescriptor WantAssertionsSigned="true" protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <!--
            Note non-standard setup: the WantAssertionsSigned attribute is set to true for this SP
            by specific request.
        -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>emailAddress=kang.tang@oerc.ox.ac.uk, CN=host/kangaroo.oerc.ox.ac.uk, L=OeSC, OU=Oxford, O=eScience, C=UK</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://kangaroo.oerc.ox.ac.uk/Shibboleth.sso/SAML/POST" index="0"></AssertionConsumerService>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://kangaroo.oerc.ox.ac.uk/Shibboleth.sso/SAML/Artifact" index="1"></AssertionConsumerService>
    </SPSSODescriptor>
    <Organization>
        <OrganizationName xml:lang="en">University of Oxford</OrganizationName>
        <OrganizationDisplayName xml:lang="en">University of Oxford: OeRC SP</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://www.oerc.ox.ac.uk/activities/projects/index.xml?ID=ShibGrid</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Kang</GivenName>
        <SurName>Tang</SurName>
        <EmailAddress>mailto:kang.tang@oerc.ox.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Kang</GivenName>
        <SurName>Tang</SurName>
        <EmailAddress>mailto:kang.tang@oerc.ox.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Kang</GivenName>
        <SurName>Tang</SurName>
        <EmailAddress>mailto:kang.tang@oerc.ox.ac.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000025" entityID="https://shibdev.ltscotland.com/shibboleth">
    <!--
        shibdev.ltscotland.com is a service provider for the Learning and Teaching Scotland SSDN Integration Project.
    -->
    <Extensions>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>
    </Extensions>
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>CN=shibdev.ltscotland.com, OU=LT Scotland SSDN Integration Project, O=JISC Core Middleware Programme, C=GB</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://shibdev.ltscotland.com/Shibboleth.sso/SAML/POST" index="0"></AssertionConsumerService>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://shibdev.ltscotland.com/Shibboleth.sso/SAML/Artifact" index="1"></AssertionConsumerService>
    </SPSSODescriptor>
    <Organization>
        <OrganizationName xml:lang="en">Learning and Teaching Scotland</OrganizationName>
        <OrganizationDisplayName xml:lang="en">LTS Development</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://www.ltscotland.org.uk/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Graham</GivenName>
        <SurName>Wilson</SurName>
        <EmailAddress>mailto:G.Wilson@LTScotland.org.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Graham</GivenName>
        <SurName>Wilson</SurName>
        <EmailAddress>mailto:G.Wilson@LTScotland.org.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Graham</GivenName>
        <SurName>Wilson</SurName>
        <EmailAddress>mailto:G.Wilson@LTScotland.org.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000026" entityID="urn:mace:eduserv.org.uk:athens:provider:tvu.ac.uk">
    <!--
        This is the IdP for Thames Valley University.
    -->
    <Extensions>
        <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">tvu.ac.uk</shibmeta:Scope>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy> 
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember> 
        <AccountableUsers xmlns="http://ukfederation.org.uk/2006/11/label"></AccountableUsers>
    </Extensions>
    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">tvu.ac.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>shibboleth1.tvu.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://shibboleth1.tvu.ac.uk/shibboleth-idp/Artifact" index="1"></ArtifactResolutionService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://shibboleth1.tvu.ac.uk/shibboleth-idp/SSO"></SingleSignOnService>
    </IDPSSODescriptor>
    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">tvu.ac.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>shibboleth1.tvu.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://shibboleth1.tvu.ac.uk:8443/shibboleth-idp/AA"></AttributeService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
    </AttributeAuthorityDescriptor>
    <Organization>
        <OrganizationName xml:lang="en">Thames Valley University</OrganizationName>
        <OrganizationDisplayName xml:lang="en">Thames Valley University</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://www.tvu.ac.uk/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Xiao</GivenName>
        <SurName>Xu</SurName>
        <EmailAddress>mailto:xiaoyan.xu@tvu.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Tiger</GivenName>
        <SurName>Wang</SurName>
        <EmailAddress>mailto:tiger.wang@tvu.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Xiao</GivenName>
        <SurName>Xu</SurName>
        <EmailAddress>mailto:xiaoyan.xu@tvu.ac.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000029" entityID="urn:mace:eduserv.org.uk:athens:provider:liv.ac.uk">
    <!--
        This is an Identity Provider for the University of Liverpool.
    -->
    <Extensions>
        <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">liv.ac.uk</shibmeta:Scope>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy> 
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>
        <AccountableUsers xmlns="http://ukfederation.org.uk/2006/11/label"></AccountableUsers>
    </Extensions>
    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">liv.ac.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>shibboleth.liv.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://shibboleth.liv.ac.uk/shibboleth-idp/SSO"></SingleSignOnService>
    </IDPSSODescriptor>
    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">liv.ac.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>shibboleth.liv.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://shibboleth.liv.ac.uk:8443/shibboleth-idp/AA"></AttributeService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
    </AttributeAuthorityDescriptor>
    <Organization>
        <OrganizationName xml:lang="en">University of Liverpool</OrganizationName>
        <OrganizationDisplayName xml:lang="en">University of Liverpool</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://www.liv.ac.uk/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>John</GivenName>
        <SurName>Gilbertson</SurName>
        <EmailAddress>mailto:webmaster@liv.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Pete</GivenName>
        <SurName>Mallinson</SurName>
        <EmailAddress>mailto:webmaster@liv.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Pete</GivenName>
        <SurName>Mallinson</SurName>
        <EmailAddress>mailto:webmaster@liv.ac.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000031" entityID="https://shib.salfordsoftware.co.uk/shibboleth">
    <!--
        https://shib.salfordsoftware.co.uk/shibboleth is an Identity Provider for Salford Software.
    -->
    <Extensions>
        <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">salfordsoftware.co.uk</shibmeta:Scope>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember> 
        <AccountableUsers xmlns="http://ukfederation.org.uk/2006/11/label"></AccountableUsers>
    </Extensions>
    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">salfordsoftware.co.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>shib.salfordsoftware.co.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://shib.salfordsoftware.co.uk/shibboleth-idp/Artifact" index="1"></ArtifactResolutionService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://go.salfordsoftware.co.uk/shibboleth-idp/SSO"></SingleSignOnService>
    </IDPSSODescriptor>
    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">salfordsoftware.co.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>shib.salfordsoftware.co.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://shib.salfordsoftware.co.uk/shibboleth-idp/AA"></AttributeService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
    </AttributeAuthorityDescriptor>
    <Organization>
        <OrganizationName xml:lang="en">Salford Software Limited</OrganizationName>
        <OrganizationDisplayName xml:lang="en">Salford Software</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://www.salfordsoftware.co.uk/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Matt</GivenName>
        <SurName>Dunkin</SurName>
        <EmailAddress>mailto:matt.dunkin@salfordsoftware.co.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Matt</GivenName>
        <SurName>Dunkin</SurName>
        <EmailAddress>mailto:matt.dunkin@salfordsoftware.co.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Matt</GivenName>
        <SurName>Dunkin</SurName>
        <EmailAddress>mailto:matt.dunkin@salfordsoftware.co.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000032" entityID="urn:mace:ac.uk:sdss.ac.uk:provider:service:gabriel.lse.ac.uk">
    <!--
        This is a Perseus Project SP (an LSE Projects WIKI)
    -->
    <Extensions>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>
    </Extensions>
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <KeyDescriptor>
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>gabriel.lse.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://gabriel.lse.ac.uk/Shibboleth.sso/SAML/POST" index="0"></AssertionConsumerService>
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://gabriel.lse.ac.uk/Shibboleth.sso/SAML/Artifact" index="1"></AssertionConsumerService>
    </SPSSODescriptor>
    <Organization>
        <OrganizationName xml:lang="en">London School of Economics and Political Science</OrganizationName>
        <OrganizationDisplayName xml:lang="en">LSE Projects WIKI</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://www.angel.ac.uk/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Simon</GivenName>
        <SurName>McLeish</SurName>
        <EmailAddress>mailto:s.mcleish@lse.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Simon</GivenName>
        <SurName>McLeish</SurName>
        <EmailAddress>mailto:s.mcleish@lse.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Simon</GivenName>
        <SurName>McLeish</SurName>
        <EmailAddress>mailto:s.mcleish@lse.ac.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000033" entityID="https://idp.atomwide.com/shibboleth">
    <!--
        This entity is an Identity Provider for Atomwide Limited.
    -->
    <Extensions>
        <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">uso.atomwide.com</shibmeta:Scope>
        <!-- The following regular expression-type scope is for internal testing only. -->
        <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="true">^.+\.atomwide\.com$</shibmeta:Scope>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember> 
        <AccountableUsers xmlns="http://ukfederation.org.uk/2006/11/label"></AccountableUsers>
    </Extensions>
    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">uso.atomwide.com</shibmeta:Scope>
            <!-- The following regular expression-type scope is for internal testing only. -->
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="true">^.+\.atomwide\.com$</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>idp.atomwide.com</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.atomwide.com:8443/shibboleth-idp/Artifact" index="1"></ArtifactResolutionService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.atomwide.com/shibboleth-idp/SSO"></SingleSignOnService>
    </IDPSSODescriptor>
    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">uso.atomwide.com</shibmeta:Scope>
            <!-- The following regular expression-type scope is for internal testing only. -->
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="true">^.+\.atomwide\.com$</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>idp.atomwide.com</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.atomwide.com:8443/shibboleth-idp/AA"></AttributeService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
    </AttributeAuthorityDescriptor>
    <Organization>
        <OrganizationName xml:lang="en">Atomwide Limited</OrganizationName>
        <OrganizationDisplayName xml:lang="en">Atomwide Limited: USO</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://www.atomwide.com/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Atomwide Shibboleth Support</GivenName>
        <EmailAddress>mailto:shibboleth@atomwide.com</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Phil</GivenName>
        <SurName>Chapman</SurName>
        <EmailAddress>mailto:phil@atomwide.com</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Phil</GivenName>
        <SurName>Chapman</SurName>
        <EmailAddress>mailto:phil@atomwide.com</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000034" entityID="urn:mace:ac.uk:sdss.ac.uk:provider:identity:sdss.ac.uk">
    <!--
        This is the identity provider for the SDSS project.
    -->
    <Extensions>
        <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">sdss.ac.uk</shibmeta:Scope>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>
    </Extensions>
    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">sdss.ac.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>origin.sdss.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://origin.sdss.ac.uk:8443/shibboleth-idp/Artifact" index="0"></ArtifactResolutionService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://origin.sdss.ac.uk/shibboleth-idp/SSO"></SingleSignOnService>
    </IDPSSODescriptor>
    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">sdss.ac.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>origin.sdss.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://origin.sdss.ac.uk:8443/shibboleth-idp/AA"></AttributeService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
    </AttributeAuthorityDescriptor>
    <Organization>
        <OrganizationName xml:lang="en">University of Edinburgh</OrganizationName>
        <OrganizationDisplayName xml:lang="en">JISC project: SDSS</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://sdss.ac.uk/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>SDSS Support List</GivenName>
        <EmailAddress>mailto:sdss-support@lists.ed.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Fiona</GivenName>
        <SurName>Culloch</SurName>
        <EmailAddress>mailto:mbxuid-sdssmetadata@yahoo.co.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Alan</GivenName>
        <SurName>Ferguson</SurName>
        <EmailAddress>mailto:Alan.Ferguson@ed.ac.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000036" entityID="urn:mace:ac.uk:sdss.ac.uk:provider:identity:idp.iay.org.uk">
    <!--
        This is an SDSS project IdP running outside the University environment.
    -->
    <Extensions>
        <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">iay.org.uk</shibmeta:Scope>
        <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">morbius.iay.org.uk</shibmeta:Scope>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>
        <wayf:HideFromWAYF xmlns:wayf="http://sdss.ac.uk/2006/06/WAYF"></wayf:HideFromWAYF>
    </Extensions>
    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">iay.org.uk</shibmeta:Scope>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">morbius.iay.org.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>idp.iay.org.uk</ds:KeyName>
                <ds:X509Data>
                    <ds:X509Certificate>
                        MIIDBDCCAm2gAwIBAgIBGjANBgkqhkiG9w0BAQUFADBIMQswCQYDVQQGEwJHQjEn
                        MCUGA1UEChMeSklTQyBDb3JlIE1pZGRsZXdhcmUgUHJvZ3JhbW1lMRAwDgYDVQQD
                        EwdTRFNTIENBMB4XDTA1MDcwNTExNDIyNFoXDTA4MTIzMTAwMDAwMFowZjELMAkG
                        A1UEBhMCR0IxJzAlBgNVBAoTHkpJU0MgQ29yZSBNaWRkbGV3YXJlIFByb2dyYW1t
                        ZTEVMBMGA1UECxMMU0RTUyBQcm9qZWN0MRcwFQYDVQQDEw5pZHAuaWF5Lm9yZy51
                        azCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAyQ5vRpGVbwXHLWRsKKzoq0yP
                        +wX1RM7O9zCw5YkBlAn8svorX/D05JR6o9GjmFU03llpjfdlcsFWwsBOzstAsZ77
                        uOR11OkivIdp+yIU4Fb5nKuvowNEq6Zx8xlzvCfpTAVFSsFuqZ5P3sBI5uCulzbo
                        d2BGfEcTh7UL26X5HEECAwEAAaOB3zCB3DAJBgNVHRMEAjAAMAsGA1UdDwQEAwIE
                        sDAxBgNVHR8EKjAoMCagJKAihiBodHRwOi8vc2Rzcy5hYy51ay9jYS9zZHNzLWNh
                        LmNybDAdBgNVHQ4EFgQUoBKCWhi4rl8Va3Z3Df1JDyscTgowcAYDVR0jBGkwZ4AU
                        vq0gh0kHZ3Eez9e6q0CKdxYdK8ChTKRKMEgxCzAJBgNVBAYTAkdCMScwJQYDVQQK
                        Ex5KSVNDIENvcmUgTWlkZGxld2FyZSBQcm9ncmFtbWUxEDAOBgNVBAMTB1NEU1Mg
                        Q0GCAQAwDQYJKoZIhvcNAQEFBQADgYEAS4dgXQy1Oxb5r3ydZthN1qYvLfnC7I4w
                        k7HMBfoD5LP+spbd/LIH9D/8XixKJj6nEK6VTCrhiXMUXB4Smf7kAudRz/+YEevO
                        dkrHPt1uK35az7zB8oFXJcxJFkRZl7Yg5A0YPY8ZO18HmIEpqFJe8Ao82fMyJ97i
                        NnSEF3d5ePI=
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.iay.org.uk:8443/shibboleth-idp/Artifact" index="1"></ArtifactResolutionService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.iay.org.uk/shibboleth-idp/SSO"></SingleSignOnService>
    </IDPSSODescriptor>
    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">iay.org.uk</shibmeta:Scope>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">morbius.iay.org.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>idp.iay.org.uk</ds:KeyName>
                <ds:X509Data>
                    <ds:X509Certificate>
                        MIIDBDCCAm2gAwIBAgIBGjANBgkqhkiG9w0BAQUFADBIMQswCQYDVQQGEwJHQjEn
                        MCUGA1UEChMeSklTQyBDb3JlIE1pZGRsZXdhcmUgUHJvZ3JhbW1lMRAwDgYDVQQD
                        EwdTRFNTIENBMB4XDTA1MDcwNTExNDIyNFoXDTA4MTIzMTAwMDAwMFowZjELMAkG
                        A1UEBhMCR0IxJzAlBgNVBAoTHkpJU0MgQ29yZSBNaWRkbGV3YXJlIFByb2dyYW1t
                        ZTEVMBMGA1UECxMMU0RTUyBQcm9qZWN0MRcwFQYDVQQDEw5pZHAuaWF5Lm9yZy51
                        azCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAyQ5vRpGVbwXHLWRsKKzoq0yP
                        +wX1RM7O9zCw5YkBlAn8svorX/D05JR6o9GjmFU03llpjfdlcsFWwsBOzstAsZ77
                        uOR11OkivIdp+yIU4Fb5nKuvowNEq6Zx8xlzvCfpTAVFSsFuqZ5P3sBI5uCulzbo
                        d2BGfEcTh7UL26X5HEECAwEAAaOB3zCB3DAJBgNVHRMEAjAAMAsGA1UdDwQEAwIE
                        sDAxBgNVHR8EKjAoMCagJKAihiBodHRwOi8vc2Rzcy5hYy51ay9jYS9zZHNzLWNh
                        LmNybDAdBgNVHQ4EFgQUoBKCWhi4rl8Va3Z3Df1JDyscTgowcAYDVR0jBGkwZ4AU
                        vq0gh0kHZ3Eez9e6q0CKdxYdK8ChTKRKMEgxCzAJBgNVBAYTAkdCMScwJQYDVQQK
                        Ex5KSVNDIENvcmUgTWlkZGxld2FyZSBQcm9ncmFtbWUxEDAOBgNVBAMTB1NEU1Mg
                        Q0GCAQAwDQYJKoZIhvcNAQEFBQADgYEAS4dgXQy1Oxb5r3ydZthN1qYvLfnC7I4w
                        k7HMBfoD5LP+spbd/LIH9D/8XixKJj6nEK6VTCrhiXMUXB4Smf7kAudRz/+YEevO
                        dkrHPt1uK35az7zB8oFXJcxJFkRZl7Yg5A0YPY8ZO18HmIEpqFJe8Ao82fMyJ97i
                        NnSEF3d5ePI=
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.iay.org.uk:8443/shibboleth-idp/AA"></AttributeService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
    </AttributeAuthorityDescriptor>
    <Organization>
        <OrganizationName xml:lang="en">Ian A. Young</OrganizationName>
        <OrganizationDisplayName xml:lang="en">JISC project: SDSS (Fountainhall 1.3)</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://sdss.ac.uk/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Ian</GivenName>
        <SurName>Young</SurName>
        <EmailAddress>mailto:ian@iay.org.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Ian</GivenName>
        <SurName>Young</SurName>
        <EmailAddress>mailto:ian@iay.org.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Ian</GivenName>
        <SurName>Young</SurName>
        <EmailAddress>mailto:ian@iay.org.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000038" entityID="urn:mace:ac.uk:sdss.ac.uk:provider:identity:dur.ac.uk">
    <!--
        This is the identity provider for the University of Durham.
    -->
    <Extensions>
        <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">dur.ac.uk</shibmeta:Scope>
        <SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy> 
        <UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>
        <AccountableUsers xmlns="http://ukfederation.org.uk/2006/11/label"></AccountableUsers>
    </Extensions>
    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">dur.ac.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>shib.dur.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://shib.dur.ac.uk:8443/shibboleth-idp/Artifact" index="1"></ArtifactResolutionService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://shib.dur.ac.uk/shibboleth-idp/SSO"></SingleSignOnService>
    </IDPSSODescriptor>
    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
        <Extensions>
            <shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">dur.ac.uk</shibmeta:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:KeyName>shib.dur.ac.uk</ds:KeyName>
            </ds:KeyInfo>
        </KeyDescriptor>
        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://shib.dur.ac.uk:8443/shibboleth-idp/AA"></AttributeService>
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
    </AttributeAuthorityDescriptor>
    <Organization>
        <OrganizationName xml:lang="en">University of Durham</OrganizationName>
        <OrganizationDisplayName xml:lang="en">University of Durham</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">http://www.dur.ac.uk/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="support">
        <GivenName>Service Desk</GivenName>
        <EmailAddress>mailto:itservicedesk@durham.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
        <GivenName>Michael</GivenName>
        <SurName>Young</SurName>
        <EmailAddress>mailto:m.a.young@durham.ac.uk</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
        <GivenName>Michael</GivenName>
        <SurName>Costello</SurName>
        <EmailAddress>mailto:m.j.costello@durham.ac.uk</EmailAddress>
    </ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000041" entityID="urn:mace:ac.uk:sdss.ac.uk:provider:identity:erewhon.ucs.ed.ac.uk">
	<!--
		This is an IdP for the University of Edinburgh.
	-->
	<Extensions>
		<shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">ed.ac.uk</shibmeta:Scope>
		<SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
		<AccountableUsers xmlns="http://ukfederation.org.uk/2006/11/label"></AccountableUsers>
		<UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember>
		<wayf:HideFromWAYF xmlns:wayf="http://sdss.ac.uk/2006/06/WAYF"></wayf:HideFromWAYF>        
	</Extensions>
	<IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
		<Extensions>
			<shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">ed.ac.uk</shibmeta:Scope>
		</Extensions>
		<KeyDescriptor use="signing">
			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<ds:KeyName>erewhon.ucs.ed.ac.uk</ds:KeyName>
			</ds:KeyInfo>
		</KeyDescriptor>
		<ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://erewhon.ucs.ed.ac.uk:8443/shibboleth-idp/Artifact" index="1"></ArtifactResolutionService>
		<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		<SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://erewhon.ucs.ed.ac.uk/shibboleth-idp/SSO"></SingleSignOnService>
	</IDPSSODescriptor>
	<AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		<Extensions>
			<shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">ed.ac.uk</shibmeta:Scope>
		</Extensions>
		<KeyDescriptor use="signing">
			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<ds:KeyName>erewhon.ucs.ed.ac.uk</ds:KeyName>
			</ds:KeyInfo>
		</KeyDescriptor>
		<AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://erewhon.ucs.ed.ac.uk:8443/shibboleth-idp/AA"></AttributeService>
		<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
	</AttributeAuthorityDescriptor>
	<Organization>
		<OrganizationName xml:lang="en">University of Edinburgh</OrganizationName>
		<OrganizationDisplayName xml:lang="en">University of Edinburgh: IS-ITI</OrganizationDisplayName>
		<OrganizationURL xml:lang="en">http://www.ed.ac.uk/</OrganizationURL>
	</Organization>
	<ContactPerson contactType="support">
		<GivenName>John</GivenName>
		<SurName>Maddock</SurName>
		<EmailAddress>mailto:J.Maddock@ed.ac.uk</EmailAddress>
	</ContactPerson>
	<ContactPerson contactType="technical">
		<GivenName>John</GivenName>
		<SurName>Maddock</SurName>
		<EmailAddress>mailto:J.Maddock@ed.ac.uk</EmailAddress>
	</ContactPerson>
	<ContactPerson contactType="administrative">
		<GivenName>John</GivenName>
		<SurName>Maddock</SurName>
		<EmailAddress>mailto:J.Maddock@ed.ac.uk</EmailAddress>
	</ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000042" entityID="urn:mace:ac.uk:sdss.ac.uk:provider:identity:exeter.ac.uk">
	<!--
		This is an identity provider for the University of Exeter.
	-->
	<Extensions>
		<shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">exeter.ac.uk</shibmeta:Scope>
		<SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy>
		<UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember> 
		<AccountableUsers xmlns="http://ukfederation.org.uk/2006/11/label"></AccountableUsers>
		<wayf:HideFromWAYF xmlns:wayf="http://sdss.ac.uk/2006/06/WAYF"></wayf:HideFromWAYF>
	</Extensions>
	<IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
		<Extensions>
			<shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">exeter.ac.uk</shibmeta:Scope>
		</Extensions>
		<KeyDescriptor use="signing">
			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<ds:KeyName>gilead.ex.ac.uk</ds:KeyName>
			</ds:KeyInfo>
		</KeyDescriptor>
		<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		<SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://gilead.ex.ac.uk/shibboleth-idp/SSO"></SingleSignOnService>
	</IDPSSODescriptor>
	<AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		<Extensions>
			<shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">exeter.ac.uk</shibmeta:Scope>
		</Extensions>
		<KeyDescriptor use="signing">
			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<ds:KeyName>gilead.ex.ac.uk</ds:KeyName>
			</ds:KeyInfo>
		</KeyDescriptor>
		<AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://gilead.ex.ac.uk:8443/shibboleth-idp/AA"></AttributeService>
		<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
	</AttributeAuthorityDescriptor>
	<Organization>
		<OrganizationName xml:lang="en">University of Exeter</OrganizationName>
		<OrganizationDisplayName xml:lang="en">University of Exeter: SWISH</OrganizationDisplayName>
		<OrganizationURL xml:lang="en">http://www.its.exeter.ac.uk/</OrganizationURL>
	</Organization>
	<ContactPerson contactType="support">
		<GivenName>Bill</GivenName>
		<SurName>Edmunds</SurName>
		<EmailAddress>mailto:W.Edmunds@exeter.ac.uk</EmailAddress>
	</ContactPerson>
	<ContactPerson contactType="technical">
		<GivenName>Nick</GivenName>
		<SurName>Johnson</SurName>
		<EmailAddress>mailto:Nick.Johnson@exeter.ac.uk</EmailAddress>
	</ContactPerson>
	<ContactPerson contactType="administrative">
		<GivenName>Ian J.</GivenName>
		<SurName>Tilsed</SurName>
		<EmailAddress>mailto:I.J.Tilsed@exeter.ac.uk</EmailAddress>
	</ContactPerson>
</EntityDescriptor>
<EntityDescriptor ID="uk000043" entityID="urn:mace:ac.uk:sdss.ac.uk:provider:identity:uhi.ac.uk">
	<!--
		This is the identity provider for the UHI Millennium Institute.
	-->
	<Extensions>
		<shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">uhi.ac.uk</shibmeta:Scope>
		<SDSSPolicy xmlns="http://ukfederation.org.uk/2006/11/label"></SDSSPolicy> 
		<UKFederationMember xmlns="http://ukfederation.org.uk/2006/11/label"></UKFederationMember> 
		<AccountableUsers xmlns="http://ukfederation.org.uk/2006/11/label"></AccountableUsers>
	</Extensions>
	<IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
		<Extensions>
			<shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">uhi.ac.uk</shibmeta:Scope>
		</Extensions>
		<KeyDescriptor use="signing">
			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<ds:KeyName>guanxi.uhi.ac.uk</ds:KeyName>
			</ds:KeyInfo>
		</KeyDescriptor>
		<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		<SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://guanxi.uhi.ac.uk/idp/SSO"></SingleSignOnService>
	</IDPSSODescriptor>
	<AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		<Extensions>
			<shibmeta:Scope xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" regexp="false">uhi.ac.uk</shibmeta:Scope>
		</Extensions>
		<KeyDescriptor use="signing">
			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<ds:KeyName>guanxi.uhi.ac.uk</ds:KeyName>
			</ds:KeyInfo>
		</KeyDescriptor>
		<AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://guanxi.uhi.ac.uk/idp/AA"></AttributeService>
		<NameIDFormat>urn