<?xml version="1.0" encoding="UTF-8"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://www.digicert.com/sso">
  <md:Extensions>
    <mdrpi:RegistrationInfo xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" registrationAuthority="http://eduid.at" registrationInstant="2015-04-09T08:51:55Z"/>
  </md:Extensions>
  <md:SPSSODescriptor AuthnRequestsSigned="true" WantAssertionsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
    <md:Extensions>
      <mdui:UIInfo xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui">
        <mdui:DisplayName xml:lang="en">GÉANT Trusted Certificate Service (TCS)</mdui:DisplayName>
        <mdui:Description xml:lang="en">Members from TCS-subscribing institutions can request personal, e-science personal, and e-science robot certificates here.</mdui:Description>
        <mdui:Logo height="58" width="224">https://www.digicert.com/images/d3/digicert-logo.png</mdui:Logo>
      </mdui:UIInfo>
    </md:Extensions>
    <md:KeyDescriptor use="signing">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:X509Data>
          <ds:X509Certificate>MIIFHzCCBAegAwIBAgIQDSPffA+3kdjXI6kqvoyBtDANBgkqhkiG9w0BAQsFADBl
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
d3cuZGlnaWNlcnQuY29tMSQwIgYDVQQDExtEaWdpQ2VydCBTSEEyIEFzc3VyZWQg
SUQgQ0EwHhcNMTUwNDA3MDAwMDAwWhcNMTgwNzA1MTIwMDAwWjBtMQswCQYDVQQG
EwJVUzENMAsGA1UECBMEVXRhaDENMAsGA1UEBxMETGVoaTEXMBUGA1UEChMORGln
aUNlcnQsIEluYy4xJzAlBgNVBAMTHkRpZ2lDZXJ0IFNBTUwgU2VydmljZSBQcm92
aWRlcjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAN/+/QfL6NXaO4Ob
gIzarBuLusqybTeFB5aRQRaTjYUGwTxbVSZWcKZFrfoki0InkQ4ez4+NGTglmObF
AUXafigKICJx7D1LzKfHSETIZmxODC7ztS1LAEa2YF+bSny+UqjC8iBpVSnOPuzY
emIntQGlgTC60QbGZ4jWGpAh/E4vuV+1ZEJlBMdo8OyVX7OKLqx0IZYnc5Ms8Q+P
8fQVAMmmkxqnDWQJG7+Dg95Ir8yP9IqBPFgW/oYmiiu9hJgg5Fw79FRVSbR4AM7m
H43grZdYwh2QhiBHe1RNMqSq8iqwRfQdgHCaXvTrAYRetXPAYl2aDZ5v+hiwYFeU
Da+yfCECAwEAAaOCAcEwggG9MB8GA1UdIwQYMBaAFOcCI4AAT9jXvJQL2T90OUky
PIp5MB0GA1UdDgQWBBTSQiXTihRDi2udzXW9NIwsexMenTAMBgNVHRMBAf8EAjAA
MA4GA1UdDwEB/wQEAwIEsDATBgNVHSUEDDAKBggrBgEFBQcDAjBCBgNVHSAEOzA5
MDcGCWCGSAGG/WwGATAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2Vy
dC5jb20vQ1BTMIGIBgNVHR8EgYAwfjA9oDugOYY3aHR0cDovL2NybDMuZGlnaWNl
cnQuY29tL0RpZ2lDZXJ0U0hBMkFzc3VyZWRJRENBLWcxLmNybDA9oDugOYY3aHR0
cDovL2NybDQuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFzc3VyZWRJRENBLWcx
LmNybDB5BggrBgEFBQcBAQRtMGswJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmRp
Z2ljZXJ0LmNvbTBDBggrBgEFBQcwAoY3aHR0cDovL2NhY2VydHMuZGlnaWNlcnQu
Y29tL0RpZ2lDZXJ0U0hBMkFzc3VyZWRJRENBLmNydDANBgkqhkiG9w0BAQsFAAOC
AQEAza2jiq0WUEas3Ou70GkX9A2U9IkgFhYj7LsR2hxfwlnl/vDvHHxzZWuOJLIR
YN4VEY6B+/vl8P2p2OdjIMATba5rqMmho+UkF7p7I0Auwc18oQ9fzZRq8ul+xtIX
OiC2mZ2dG5VUXk1eR7qAKafGoNkOWzY6K0yb7NlUtGQDbZ5kBUqxH7z1uIPtjEBx
jv9ka0zHozKT+/vtNbAta7iuQtM05y2fSjXLeGpcTxnootfcFJtbpxiODd77a1Ax
0b2CWHv1aZaDQHlMjsf1ZaVPjHkgLlTFAtgzceimrdGM7PM/EHUFHP94H1EggcYt
n4mgYE+xr/VoR6tzNtvfyLXqxA==</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:KeyDescriptor use="encryption">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:X509Data>
          <ds:X509Certificate>MIIFHzCCBAegAwIBAgIQDSPffA+3kdjXI6kqvoyBtDANBgkqhkiG9w0BAQsFADBl
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
d3cuZGlnaWNlcnQuY29tMSQwIgYDVQQDExtEaWdpQ2VydCBTSEEyIEFzc3VyZWQg
SUQgQ0EwHhcNMTUwNDA3MDAwMDAwWhcNMTgwNzA1MTIwMDAwWjBtMQswCQYDVQQG
EwJVUzENMAsGA1UECBMEVXRhaDENMAsGA1UEBxMETGVoaTEXMBUGA1UEChMORGln
aUNlcnQsIEluYy4xJzAlBgNVBAMTHkRpZ2lDZXJ0IFNBTUwgU2VydmljZSBQcm92
aWRlcjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAN/+/QfL6NXaO4Ob
gIzarBuLusqybTeFB5aRQRaTjYUGwTxbVSZWcKZFrfoki0InkQ4ez4+NGTglmObF
AUXafigKICJx7D1LzKfHSETIZmxODC7ztS1LAEa2YF+bSny+UqjC8iBpVSnOPuzY
emIntQGlgTC60QbGZ4jWGpAh/E4vuV+1ZEJlBMdo8OyVX7OKLqx0IZYnc5Ms8Q+P
8fQVAMmmkxqnDWQJG7+Dg95Ir8yP9IqBPFgW/oYmiiu9hJgg5Fw79FRVSbR4AM7m
H43grZdYwh2QhiBHe1RNMqSq8iqwRfQdgHCaXvTrAYRetXPAYl2aDZ5v+hiwYFeU
Da+yfCECAwEAAaOCAcEwggG9MB8GA1UdIwQYMBaAFOcCI4AAT9jXvJQL2T90OUky
PIp5MB0GA1UdDgQWBBTSQiXTihRDi2udzXW9NIwsexMenTAMBgNVHRMBAf8EAjAA
MA4GA1UdDwEB/wQEAwIEsDATBgNVHSUEDDAKBggrBgEFBQcDAjBCBgNVHSAEOzA5
MDcGCWCGSAGG/WwGATAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2Vy
dC5jb20vQ1BTMIGIBgNVHR8EgYAwfjA9oDugOYY3aHR0cDovL2NybDMuZGlnaWNl
cnQuY29tL0RpZ2lDZXJ0U0hBMkFzc3VyZWRJRENBLWcxLmNybDA9oDugOYY3aHR0
cDovL2NybDQuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkFzc3VyZWRJRENBLWcx
LmNybDB5BggrBgEFBQcBAQRtMGswJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmRp
Z2ljZXJ0LmNvbTBDBggrBgEFBQcwAoY3aHR0cDovL2NhY2VydHMuZGlnaWNlcnQu
Y29tL0RpZ2lDZXJ0U0hBMkFzc3VyZWRJRENBLmNydDANBgkqhkiG9w0BAQsFAAOC
AQEAza2jiq0WUEas3Ou70GkX9A2U9IkgFhYj7LsR2hxfwlnl/vDvHHxzZWuOJLIR
YN4VEY6B+/vl8P2p2OdjIMATba5rqMmho+UkF7p7I0Auwc18oQ9fzZRq8ul+xtIX
OiC2mZ2dG5VUXk1eR7qAKafGoNkOWzY6K0yb7NlUtGQDbZ5kBUqxH7z1uIPtjEBx
jv9ka0zHozKT+/vtNbAta7iuQtM05y2fSjXLeGpcTxnootfcFJtbpxiODd77a1Ax
0b2CWHv1aZaDQHlMjsf1ZaVPjHkgLlTFAtgzceimrdGM7PM/EHUFHP94H1EggcYt
n4mgYE+xr/VoR6tzNtvfyLXqxA==</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://www.digicert.com/sso/saml/SingleLogout"/>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://www.digicert.com/sso/saml/SingleLogout"/>
    <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
    <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</md:NameIDFormat>
    <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat>
    <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName</md:NameIDFormat>
    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://www.digicert.com/sso/saml/SSO" index="0" isDefault="true"/>
    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://www.digicert.com/sso/saml/SSO" index="1"/>
    <md:AttributeConsumingService index="0">
      <md:ServiceName xml:lang="en">DigiCert's TCS Portal</md:ServiceName>
      <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
      <md:RequestedAttribute FriendlyName="displayName" Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
      <md:RequestedAttribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
      <md:RequestedAttribute FriendlyName="schacHomeOrganization" Name="urn:oid:1.3.6.1.4.1.25178.1.2.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
      <md:RequestedAttribute FriendlyName="eduPersonEntitlement" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.7" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true">
        <saml:AttributeValue xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">urn:mace:terena.org:tcs:personal-user</saml:AttributeValue>
        <saml:AttributeValue xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">urn:mace:terena.org:tcs:escience-user</saml:AttributeValue>
      </md:RequestedAttribute>
    </md:AttributeConsumingService>
  </md:SPSSODescriptor>
  <md:Organization>
    <md:OrganizationName xml:lang="en">DigiCert Inc.</md:OrganizationName>
    <md:OrganizationDisplayName xml:lang="en">DigiCert</md:OrganizationDisplayName>
    <md:OrganizationURL xml:lang="en">https://www.digicert.com/</md:OrganizationURL>
  </md:Organization>
  <md:ContactPerson contactType="support">
    <md:GivenName>DigiCert</md:GivenName>
    <md:SurName>Support</md:SurName>
    <md:EmailAddress>mailto:support@digicert.com</md:EmailAddress>
  </md:ContactPerson>
  <md:ContactPerson contactType="administrative">
    <md:GivenName>GÉANT</md:GivenName>
    <md:SurName>TCS Policy Management Authority</md:SurName>
    <md:EmailAddress>mailto:tcs-pma@lists.geant.org</md:EmailAddress>
  </md:ContactPerson>
  <md:ContactPerson contactType="technical">
    <md:GivenName>DigiCert</md:GivenName>
    <md:SurName>Support</md:SurName>
    <md:EmailAddress>mailto:support@digicert.com</md:EmailAddress>
  </md:ContactPerson>
</md:EntityDescriptor>