<?xml version="1.0"?>
<EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://slcs.pca.dfn.de/shibboleth">
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
      <Extensions>
        <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://slcs.pca.dfn.de/Shibboleth.sso/DS" index="1"/>
      </Extensions>
      <KeyDescriptor use="encryption">
        <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
          <ds:KeyName>slcs.pca.dfn.de</ds:KeyName>
          <ds:X509Data>
            <ds:X509SubjectName>CN=slcs.pca.dfn.de,OU=DFN-PKI,O=DFN-Verein,C=DE</ds:X509SubjectName>
            <ds:X509Certificate>MIIFATCCA+mgAwIBAgIEDbn3WDANBgkqhkiG9w0BAQUFADBVMQswCQYDVQQGEwJE
RTETMBEGA1UEChMKREZOLVZlcmVpbjEQMA4GA1UECxMHREZOLVBLSTEfMB0GA1UE
AxMWREZOLVZlcmVpbiBDQSBTZXJ2aWNlczAeFw0wOTAyMTcwODQ4MDhaFw0xNDAy
MTYwODQ4MDhaME4xCzAJBgNVBAYTAkRFMRMwEQYDVQQKEwpERk4tVmVyZWluMRAw
DgYDVQQLEwdERk4tUEtJMRgwFgYDVQQDEw9zbGNzLnBjYS5kZm4uZGUwggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCw3Jc6eE6FdEoDHX4bGRTQ8tt2f65t
hR76ZN4o4WIMXlnKuUiPcj84bSnsToXi8CTZy0Y3IS/iqiG+VIhlwombfqgEJb1/
YXxW9hL3s38qobUNsSlv1cam6MjJVRRbvmnulqA2UkcXh0j8oXjMgMrvRscvc5Vr
R+qrLotFyEp3weKYTS03k6f2QN63pFCtwu+4db5g7DLAgf4T8LkCwPR1yrAjfIyQ
KZlilI1I+LIEepIbZ5Yi/HWxGJ4rE0QQzf595yiygtXL+lwgOjexnKOEoVNdRa3k
gDUoh5xyTkdnLDjV2J/fsHkzjy8mODDl9POPm+5xsLXLwGMn+ChU6CSrAgMBAAGj
ggHeMIIB2jAJBgNVHRMEAjAAMAsGA1UdDwQEAwIF4DAdBgNVHSUEFjAUBggrBgEF
BQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFJweQjSs1QUY3yB1FTgAhsULqiHTMB8G
A1UdIwQYMBaAFB2p8YYmdk3PXf1Qo27r8bwidW3rMCAGA1UdEQQZMBeBFXdlYm1h
c3RlckBkZm4tY2VydC5kZTCBkQYDVR0fBIGJMIGGMEGgP6A9hjtodHRwOi8vY2Rw
MS5wY2EuZGZuLmRlL2dsb2JhbC1zZXJ2aWNlcy1jYS9wdWIvY3JsL2NhY3JsLmNy
bDBBoD+gPYY7aHR0cDovL2NkcDIucGNhLmRmbi5kZS9nbG9iYWwtc2VydmljZXMt
Y2EvcHViL2NybC9jYWNybC5jcmwwgaoGCCsGAQUFBwEBBIGdMIGaMEsGCCsGAQUF
BzAChj9odHRwOi8vY2RwMS5wY2EuZGZuLmRlL2dsb2JhbC1zZXJ2aWNlcy1jYS9w
dWIvY2FjZXJ0L2NhY2VydC5jcnQwSwYIKwYBBQUHMAKGP2h0dHA6Ly9jZHAyLnBj
YS5kZm4uZGUvZ2xvYmFsLXNlcnZpY2VzLWNhL3B1Yi9jYWNlcnQvY2FjZXJ0LmNy
dDANBgkqhkiG9w0BAQUFAAOCAQEAilQf5k73NxqSFP81D51u6cnwE+ZW1WCPcUhd
IkQ+K85pP57nd4ClbL+mond011qRiyzA9txYuoxw6+J6mXU9MlKDgWh7ACVIjEZB
VeS/ROi0GvRKQBlUp4OgwFFMhoHp5wZbpL7cCp5NE7ZOMNZfGk095tEFEDZX7Csg
GlcR2n3wMi66UIFjaMKTdmh5kPFVtQNw8FltrO+qRJeTljDTB4Ct9SOCV7F2VnNo
/bBzPejsxto0mF0W/gqyfZqcQSnSGEFVDQsAEv2aLMHoFvuOIr4nHWTsimbKuidM
73o/AK2KZu86hs7mFt0tLOrUUlJJOtekqrPLWHFfLLBT8f9L+w==
</ds:X509Certificate>
          </ds:X509Data>
        </ds:KeyInfo>
      </KeyDescriptor>
      <KeyDescriptor use="signing">
        <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
          <ds:KeyName>slcs.pca.dfn.de</ds:KeyName>
          <ds:X509Data>
            <ds:X509SubjectName>CN=slcs.pca.dfn.de,OU=DFN-PKI,O=DFN-Verein,C=DE</ds:X509SubjectName>
            <ds:X509Certificate>MIIFATCCA+mgAwIBAgIEDbn3WDANBgkqhkiG9w0BAQUFADBVMQswCQYDVQQGEwJE
RTETMBEGA1UEChMKREZOLVZlcmVpbjEQMA4GA1UECxMHREZOLVBLSTEfMB0GA1UE
AxMWREZOLVZlcmVpbiBDQSBTZXJ2aWNlczAeFw0wOTAyMTcwODQ4MDhaFw0xNDAy
MTYwODQ4MDhaME4xCzAJBgNVBAYTAkRFMRMwEQYDVQQKEwpERk4tVmVyZWluMRAw
DgYDVQQLEwdERk4tUEtJMRgwFgYDVQQDEw9zbGNzLnBjYS5kZm4uZGUwggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCw3Jc6eE6FdEoDHX4bGRTQ8tt2f65t
hR76ZN4o4WIMXlnKuUiPcj84bSnsToXi8CTZy0Y3IS/iqiG+VIhlwombfqgEJb1/
YXxW9hL3s38qobUNsSlv1cam6MjJVRRbvmnulqA2UkcXh0j8oXjMgMrvRscvc5Vr
R+qrLotFyEp3weKYTS03k6f2QN63pFCtwu+4db5g7DLAgf4T8LkCwPR1yrAjfIyQ
KZlilI1I+LIEepIbZ5Yi/HWxGJ4rE0QQzf595yiygtXL+lwgOjexnKOEoVNdRa3k
gDUoh5xyTkdnLDjV2J/fsHkzjy8mODDl9POPm+5xsLXLwGMn+ChU6CSrAgMBAAGj
ggHeMIIB2jAJBgNVHRMEAjAAMAsGA1UdDwQEAwIF4DAdBgNVHSUEFjAUBggrBgEF
BQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFJweQjSs1QUY3yB1FTgAhsULqiHTMB8G
A1UdIwQYMBaAFB2p8YYmdk3PXf1Qo27r8bwidW3rMCAGA1UdEQQZMBeBFXdlYm1h
c3RlckBkZm4tY2VydC5kZTCBkQYDVR0fBIGJMIGGMEGgP6A9hjtodHRwOi8vY2Rw
MS5wY2EuZGZuLmRlL2dsb2JhbC1zZXJ2aWNlcy1jYS9wdWIvY3JsL2NhY3JsLmNy
bDBBoD+gPYY7aHR0cDovL2NkcDIucGNhLmRmbi5kZS9nbG9iYWwtc2VydmljZXMt
Y2EvcHViL2NybC9jYWNybC5jcmwwgaoGCCsGAQUFBwEBBIGdMIGaMEsGCCsGAQUF
BzAChj9odHRwOi8vY2RwMS5wY2EuZGZuLmRlL2dsb2JhbC1zZXJ2aWNlcy1jYS9w
dWIvY2FjZXJ0L2NhY2VydC5jcnQwSwYIKwYBBQUHMAKGP2h0dHA6Ly9jZHAyLnBj
YS5kZm4uZGUvZ2xvYmFsLXNlcnZpY2VzLWNhL3B1Yi9jYWNlcnQvY2FjZXJ0LmNy
dDANBgkqhkiG9w0BAQUFAAOCAQEAilQf5k73NxqSFP81D51u6cnwE+ZW1WCPcUhd
IkQ+K85pP57nd4ClbL+mond011qRiyzA9txYuoxw6+J6mXU9MlKDgWh7ACVIjEZB
VeS/ROi0GvRKQBlUp4OgwFFMhoHp5wZbpL7cCp5NE7ZOMNZfGk095tEFEDZX7Csg
GlcR2n3wMi66UIFjaMKTdmh5kPFVtQNw8FltrO+qRJeTljDTB4Ct9SOCV7F2VnNo
/bBzPejsxto0mF0W/gqyfZqcQSnSGEFVDQsAEv2aLMHoFvuOIr4nHWTsimbKuidM
73o/AK2KZu86hs7mFt0tLOrUUlJJOtekqrPLWHFfLLBT8f9L+w==
</ds:X509Certificate>
          </ds:X509Data>
        </ds:KeyInfo>
      </KeyDescriptor>
      <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SLO/Artifact"/>
      <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SLO/POST"/>
      <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SLO/Redirect"/>
      <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SLO/SOAP"/>
      <ManageNameIDService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://slcs.pca.dfn.de/Shibboleth.sso/NIM/Artifact"/>
      <ManageNameIDService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://slcs.pca.dfn.de/Shibboleth.sso/NIM/POST"/>
      <ManageNameIDService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://slcs.pca.dfn.de/Shibboleth.sso/NIM/Redirect"/>
      <ManageNameIDService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://slcs.pca.dfn.de/Shibboleth.sso/NIM/SOAP"/>
      <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SAML2/POST" index="1"/>
      <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SAML2/POST-SimpleSign" index="2"/>
      <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SAML2/Artifact" index="3"/>
      <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SAML2/ECP" index="4"/>
      <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SAML/POST" index="5"/>
      <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://slcs.pca.dfn.de/Shibboleth.sso/SAML/Artifact" index="6"/>
    </SPSSODescriptor>
    <Organization>
      <OrganizationName xml:lang="de">DFN-CERT Services GmbH</OrganizationName>
      <OrganizationDisplayName xml:lang="de">DFN Short-Lived Credential Service (DFN-SLCS)</OrganizationDisplayName>
      <OrganizationURL xml:lang="de">http://www.dfn-cert.de</OrganizationURL>
    </Organization>
    <ContactPerson contactType="administrative">
      <GivenName>Reimer</GivenName>
      <SurName>Karlsen-Masur</SurName>
      <EmailAddress>dfnpca@dfn-cert.de</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="technical">
      <GivenName>Reimer</GivenName>
      <SurName>Karlsen-Masur</SurName>
      <EmailAddress>dfnpca@dfn-cert.de</EmailAddress>
    </ContactPerson>
  </EntityDescriptor>