<!--
This is example metadata only. Do *NOT* supply it as is without review,
and do *NOT* provide it in real time to your partners.
 -->
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
                     xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute"
                     xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
                     ID="_a1c917baa7b177cb866c3307b495faff98e5b48a"
                     entityID="https://sp2.local/shibboleth">

  <md:Extensions xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport">
    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/>
    <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
    <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
    <mdattr:EntityAttributes>
      <saml:Attribute
          Name="http://macedir.org/entity-category"
          NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
        <saml:AttributeValue>
          http://aai.dfn.de/category/dfn-edu-id
        </saml:AttributeValue>
      </saml:Attribute>
    </mdattr:EntityAttributes>
  </md:Extensions>

  <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
    <md:Extensions>
      <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://sp2.local/Shibboleth.sso/Login"/>
    </md:Extensions>
    <md:KeyDescriptor>
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:KeyName>sp2.local</ds:KeyName>
        <ds:X509Data>
          <ds:X509SubjectName>CN=sp2.local,OU=DFN-AAI,O=Verein zur Foerderung eines Deutschen Forschungsnetzes e. V.,L=Berlin,ST=Berlin,C=DE</ds:X509SubjectName>
          <ds:X509Certificate>MIIFwTCCA6kCFAN/xRp+5BjxtRGJy/b/iyiDZnGAMA0GCSqGSIb3DQEBCwUAMIGc
MQswCQYDVQQGEwJERTEPMA0GA1UECAwGQmVybGluMQ8wDQYDVQQHDAZCZXJsaW4x
RTBDBgNVBAoMPFZlcmVpbiB6dXIgRm9lcmRlcnVuZyBlaW5lcyBEZXV0c2NoZW4g
Rm9yc2NodW5nc25ldHplcyBlLiBWLjEQMA4GA1UECwwHREZOLUFBSTESMBAGA1UE
AwwJc3AyLmxvY2FsMB4XDTIwMTAyODA4NDUwOFoXDTI1MTAyNzA4NDUwOFowgZwx
CzAJBgNVBAYTAkRFMQ8wDQYDVQQIDAZCZXJsaW4xDzANBgNVBAcMBkJlcmxpbjFF
MEMGA1UECgw8VmVyZWluIHp1ciBGb2VyZGVydW5nIGVpbmVzIERldXRzY2hlbiBG
b3JzY2h1bmdzbmV0emVzIGUuIFYuMRAwDgYDVQQLDAdERk4tQUFJMRIwEAYDVQQD
DAlzcDIubG9jYWwwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCdUwk2
UWiv35kbGn2Mwob3dkZR0QOt/1SbI8gjjFeRpzSkguAgrDjmekzbA9VwnkRiRkFh
moGIJYSG1bL5+qq1OzY1q1Xn/eNXINofij2UPXlVnoM8Od2Mx8LvlqdDHcdCvOgc
jc6AmuVw6xXpdrWMXnkZqjROpuvaT6WWXeOSp44s4U1GcWtYKzIvny0gtzS1Eb0T
iAexhIJbMwbXgZEABZ3ezBo5qI8e4+gGSUjtPd4rAFTJn4CWoAyCjIHbBm8fxMlN
ikJUC7E0cd+Bw6F82pCwgMCr8a9g0lCkSR1tZGK4RA6tvFqLBI44MSb/CPKbMMCE
ETbuaU/SRegIyEHGfi1RrKCGsjMlZiHfE0Kw50SPKIEvJ8UX1vGVUKhFB2GJxn1f
1FsGVqhOlKfI/ftE36mZ1rQshizGRsCcBbBr+iaCFzkxRuijiDGzXZSeyWXQkVDk
2gBO0Ibh+zZ8LT/gJINMLPjNp9w8AaPsZFq0mwsBPW5GPWPiwYChtT9bK6Rj/DBx
+uWmCshJgYeaUoknBAH6X83XGjYK6/4al6A8PkG3CbM8jluKvbsecXSmRiUUNy/Y
q94DfKEPE6j7E2bsLAhc99tjh4mq7au/j5n22c6v+nskFGTMSYfBcgUN320+5WTk
xj2lyIGeEXgGi6YiJJh9kfJe6EHx+TYEp6z+FQIDAQABMA0GCSqGSIb3DQEBCwUA
A4ICAQAKgHbc55O1Lp1tmrq+hfq1fFiGYWccyfZ3F/AfUztOMjDjewdKYPaWkCW+
8maXT+IMILVRW6fbR8Jdi3EPNOpL3q8kUhRN0obzqGfufJ8d4s8rLryoTd7h2q4D
6kK2qaKQ3GDPS4tFjA3sDuFpKOaa6MJeLXqbNB4MPMYOQ1cPWLLFB7AzUkoYFJZd
Az+Vx//gMvJliM52V86DZnZy35YcjgJCC7SpJoqG7A3z+sLM5QQjYJEDQYDFKxxo
7bGN2owbHLM+qk1aI+JbKwau9+PayVp2SAyjKO3a2nuhGqy3ksSde1jK7+eKxqn5
IKWgy4+j9Z5w5f8raLvMFjoQ12k7uROSAkooS6qoUkqF1EfuY3hkbw86/AJ95jOf
GdHsj/+t0MF82cs/3UcVHCHDf4glxXHYGR7cs12wZSYE00x87rszBRp19zwtNuu/
gshEDjm3Qv2hnGT2EKRvEdDOnLqC2AkJpetq91FFoWmsvLnpzQVASbgNFMc6kU/2
3aJX2Ta34wLNgOCwsPjhmO+6bYj0aavITzODkbPbhI+1EjZ716Rr3hqXprB6ZX9Q
EGVv4ADQdr47UreZGtG8QxvhKl6Jj68PPG+iSoYx3oMqzmErBylRmniLHbyReX5I
O/2+h/IEp6YoBWXR+HwlCtJseoTsS3Es1Out6FtvoKn0OjfncQ==
</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/>
      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
    </md:KeyDescriptor>
    <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://sp2.local/Shibboleth.sso/Artifact/SOAP" index="1"/>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://sp2.local/Shibboleth.sso/SLO/SOAP"/>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://sp2.local/Shibboleth.sso/SLO/Redirect"/>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://sp2.local/Shibboleth.sso/SLO/POST"/>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://sp2.local/Shibboleth.sso/SLO/Artifact"/>
    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://sp2.local/Shibboleth.sso/SAML2/POST" index="1"/>
    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://sp2.local/Shibboleth.sso/SAML2/POST-SimpleSign" index="2"/>
    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://sp2.local/Shibboleth.sso/SAML2/Artifact" index="3"/>
    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://sp2.local/Shibboleth.sso/SAML2/ECP" index="4"/>
  </md:SPSSODescriptor>

</md:EntityDescriptor>
