<?xml version="1.0" encoding="UTF-8"?>
<EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://slcs.pca.dfn.de/shibboleth">
  <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
    <Extensions>
      <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://slcs.pca.dfn.de/Shibboleth.sso/DS" index="1"/>
    </Extensions>
    <KeyDescriptor use="encryption">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:KeyName>slcs.pca.dfn.de</ds:KeyName>
        <ds:X509Data>
          <ds:X509SubjectName>CN=slcs.pca.dfn.de,OU=DFN-PKI,O=DFN-Verein,C=DE</ds:X509SubjectName>
          <ds:X509Certificate>MIIFATCCA+mgAwIBAgIEDbn3WDANBgkqhkiG9w0BAQUFADBVMQswCQYDVQQGEwJE
RTETMBEGA1UEChMKREZOLVZlcmVpbjEQMA4GA1UECxMHREZOLVBLSTEfMB0GA1UE
AxMWREZOLVZlcmVpbiBDQSBTZXJ2aWNlczAeFw0wOTAyMTcwODQ4MDhaFw0xNDAy
MTYwODQ4MDhaME4xCzAJBgNVBAYTAkRFMRMwEQYDVQQKEwpERk4tVmVyZWluMRAw
DgYDVQQLEwdERk4tUEtJMRgwFgYDVQQDEw9zbGNzLnBjYS5kZm4uZGUwggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCw3Jc6eE6FdEoDHX4bGRTQ8tt2f65t
hR76ZN4o4WIMXlnKuUiPcj84bSnsToXi8CTZy0Y3IS/iqiG+VIhlwombfqgEJb1/
YXxW9hL3s38qobUNsSlv1cam6MjJVRRbvmnulqA2UkcXh0j8oXjMgMrvRscvc5Vr
R+qrLotFyEp3weKYTS03k6f2QN63pFCtwu+4db5g7DLAgf4T8LkCwPR1yrAjfIyQ
KZlilI1I+LIEepIbZ5Yi/HWxGJ4rE0QQzf595yiygtXL+lwgOjexnKOEoVNdRa3k
gDUoh5xyTkdnLDjV2J/fsHkzjy8mODDl9POPm+5xsLXLwGMn+ChU6CSrAgMBAAGj
ggHeMIIB2jAJBgNVHRMEAjAAMAsGA1UdDwQEAwIF4DAdBgNVHSUEFjAUBggrBgEF
BQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFJweQjSs1QUY3yB1FTgAhsULqiHTMB8G
A1UdIwQYMBaAFB2p8YYmdk3PXf1Qo27r8bwidW3rMCAGA1UdEQQZMBeBFXdlYm1h
c3RlckBkZm4tY2VydC5kZTCBkQYDVR0fBIGJMIGGMEGgP6A9hjtodHRwOi8vY2Rw
MS5wY2EuZGZuLmRlL2dsb2JhbC1zZXJ2aWNlcy1jYS9wdWIvY3JsL2NhY3JsLmNy
bDBBoD+gPYY7aHR0cDovL2NkcDIucGNhLmRmbi5kZS9nbG9iYWwtc2VydmljZXMt
Y2EvcHViL2NybC9jYWNybC5jcmwwgaoGCCsGAQUFBwEBBIGdMIGaMEsGCCsGAQUF
BzAChj9odHRwOi8vY2RwMS5wY2EuZGZuLmRlL2dsb2JhbC1zZXJ2aWNlcy1jYS9w
dWIvY2FjZXJ0L2NhY2VydC5jcnQwSwYIKwYBBQUHMAKGP2h0dHA6Ly9jZHAyLnBj
YS5kZm4uZGUvZ2xvYmFsLXNlcnZpY2VzLWNhL3B1Yi9jYWNlcnQvY2FjZXJ0LmNy
dDANBgkqhkiG9w0BAQUFAAOCAQEAilQf5k73NxqSFP81D51u6cnwE+ZW1WCPcUhd
IkQ+K85pP57nd4ClbL+mond011qRiyzA9txYuoxw6+J6mXU9MlKDgWh7ACVIjEZB
VeS/ROi0GvRKQBlUp4OgwFFMhoHp5wZbpL7cCp5NE7ZOMNZfGk095tEFEDZX7Csg
GlcR2n3wMi66UIFjaMKTdmh5kPFVtQNw8FltrO+qRJeTljDTB4Ct9SOCV7F2VnNo
/bBzPejsxto0mF0W/gqyfZqcQSnSGEFVDQsAEv2aLMHoFvuOIr4nHWTsimbKuidM
73o/AK2KZu86hs7mFt0tLOrUUlJJOtekqrPLWHFfLLBT8f9L+w==
</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </KeyDescriptor>
    <KeyDescriptor use="signing">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:KeyName>slcs.pca.dfn.de</ds:KeyName>
        <ds:X509Data>
          <ds:X509SubjectName>CN=slcs.pca.dfn.de,OU=DFN-PKI,O=DFN-Verein,C=DE</ds:X509SubjectName>
          <ds:X509Certificate>MIIFATCCA+mgAwIBAgIEDbn3WDANBgkqhkiG9w0BAQUFADBVMQswCQYDVQQGEwJE
RTETMBEGA1UEChMKREZOLVZlcmVpbjEQMA4GA1UECxMHREZOLVBLSTEfMB0GA1UE
AxMWREZOLVZlcmVpbiBDQSBTZXJ2aWNlczAeFw0wOTAyMTcwODQ4MDhaFw0xNDAy
MTYwODQ4MDhaME4xCzAJBgNVBAYTAkRFMRMwEQYDVQQKEwpERk4tVmVyZWluMRAw
DgYDVQQLEwdERk4tUEtJMRgwFgYDVQQDEw9zbGNzLnBjYS5kZm4uZGUwggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCw3Jc6eE6FdEoDHX4bGRTQ8tt2f65t
hR76ZN4o4WIMXlnKuUiPcj84bSnsToXi8CTZy0Y3IS/iqiG+VIhlwombfqgEJb1/
YXxW9hL3s38qobUNsSlv1cam6MjJVRRbvmnulqA2UkcXh0j8oXjMgMrvRscvc5Vr
R+qrLotFyEp3weKYTS03k6f2QN63pFCtwu+4db5g7DLAgf4T8LkCwPR1yrAjfIyQ
KZlilI1I+LIEepIbZ5Yi/HWxGJ4rE0QQzf595yiygtXL+lwgOjexnKOEoVNdRa3k
gDUoh5xyTkdnLDjV2J/fsHkzjy8mODDl9POPm+5xsLXLwGMn+ChU6CSrAgMBAAGj
ggHeMIIB2jAJBgNVHRMEAjAAMAsGA1UdDwQEAwIF4DAdBgNVHSUEFjAUBggrBgEF
BQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFJweQjSs1QUY3yB1FTgAhsULqiHTMB8G
A1UdIwQYMBaAFB2p8YYmdk3PXf1Qo27r8bwidW3rMCAGA1UdEQQZMBeBFXdlYm1h
c3RlckBkZm4tY2VydC5kZTCBkQYDVR0fBIGJMIGGMEGgP6A9hjtodHRwOi8vY2Rw
MS5wY2EuZGZuLmRlL2dsb2JhbC1zZXJ2aWNlcy1jYS9wdWIvY3JsL2NhY3JsLmNy
bDBBoD+gPYY7aHR0cDovL2NkcDIucGNhLmRmbi5kZS9nbG9iYWwtc2VydmljZXMt
Y2EvcHViL2NybC9jYWNybC5jcmwwgaoGCCsGAQUFBwEBBIGdMIGaMEsGCCsGAQUF
BzAChj9odHRwOi8vY2RwMS5wY2EuZGZuLmRlL2dsb2JhbC1zZXJ2aWNlcy1jYS9w
dWIvY2FjZXJ0L2NhY2VydC5jcnQwSwYIKwYBBQUHMAKGP2h0dHA6Ly9jZHAyLnBj
YS5kZm4uZGUvZ2xvYmFsLXNlcnZpY2VzLWNhL3B1Yi9jYWNlcnQvY2FjZXJ0LmNy
dDANBgkqhkiG9w0BAQUFAAOCAQEAilQf5k73NxqSFP81D51u6cnwE+ZW1WCPcUhd
IkQ+K85pP57nd4ClbL+mond011qRiyzA9txYuoxw6+J6mXU9MlKDgWh7ACVIjEZB
VeS/ROi0GvRKQBlUp4OgwFFMhoHp5wZbpL7cCp5NE7ZOMNZfGk095tEFEDZX7Csg
GlcR2n3wMi66UIFjaMKTdmh5kPFVtQNw8FltrO+qRJeTljDTB4Ct9SOCV7F2VnNo
/bBzPejsxto0mF0W/gqyfZqcQSnSGEFVDQsAEv2aLMHoFvuOIr4nHWTsimbKuidM
73o/AK2KZu86hs7mFt0tLOrUUlJJOtekqrPLWHFfLLBT8f9L+w==
</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </KeyDescriptor>
    <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SLO/Artifact"/>
    <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SLO/POST"/>
    <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SLO/Redirect"/>
    <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SLO/SOAP"/>
    <ManageNameIDService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://slcs.pca.dfn.de/Shibboleth.sso/NIM/Artifact"/>
    <ManageNameIDService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://slcs.pca.dfn.de/Shibboleth.sso/NIM/POST"/>
    <ManageNameIDService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://slcs.pca.dfn.de/Shibboleth.sso/NIM/Redirect"/>
    <ManageNameIDService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://slcs.pca.dfn.de/Shibboleth.sso/NIM/SOAP"/>
    <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SAML2/POST" index="1"/>
    <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SAML2/POST-SimpleSign" index="2"/>
    <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SAML2/Artifact" index="3"/>
    <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SAML2/ECP" index="4"/>
    <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SAML/POST" index="5"/>
    <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SAML/Artifact" index="6"/>
  </SPSSODescriptor>
  <Organization>
    <OrganizationName xml:lang="de">DFN-CERT Services GmbH</OrganizationName>
    <OrganizationDisplayName xml:lang="de">DFN Short-Lived Credential Service (DFN-SLCS)</OrganizationDisplayName>
    <OrganizationURL xml:lang="de">http://www.dfn-cert.de</OrganizationURL>
  </Organization>
  <ContactPerson contactType="administrative">
    <GivenName>Reimer</GivenName>
    <SurName>Karlsen-Masur</SurName>
    <EmailAddress>dfnpca@dfn-cert.de</EmailAddress>
  </ContactPerson>
  <ContactPerson contactType="technical">
    <GivenName>Reimer</GivenName>
    <SurName>Karlsen-Masur</SurName>
    <EmailAddress>dfnpca@dfn-cert.de</EmailAddress>
  </ContactPerson>
</EntityDescriptor>