<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.
--> 
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" entityID="https://shibboleth-idp.ukw.de/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">ukw.de</shibmd:Scope>
	     <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">Wuerzburg University Hospital</mdui:DisplayName>
		<mdui:DisplayName xml:lang="de">Universitätsklinikum Wuerzburg </mdui:DisplayName>
                <mdui:Description xml:lang="en">Identity Provider of Wuerzburg University Hospital</mdui:Description>
                <mdui:Description xml:lang="de">Identity Provider der Universitätsklinik Wuerzburg</mdui:Description>
                <mdui:Logo height="16" width="16">https://shibboleth-idp.ukw.de/idp/images/favicon.ico</mdui:Logo>
                <mdui:Logo height="80" width="80">https://shibboleth-idp.ukw.de/idp/images/logo.png</mdui:Logo>
            </mdui:UIInfo>	
<!--
    Fill in the details for your IdP here 

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">A Name for the IdP at shibboleth-idp.ukw.de</mdui:DisplayName>
                <mdui:Description xml:lang="en">Enter a description of your IdP at shibboleth-idp.ukw.de</mdui:Description>
                <mdui:Logo height="80" width="80">https://shibboleth-idp.ukw.de/Path/To/Logo.png</mdui:Logo>
            </mdui:UIInfo>
--> 
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel--> 


<!-- Cert bis 20260503 ATH -->

	<!-- 
	<KeyDescriptor>
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIFETCCAvmgAwIBAgIUVwHpy9Ao+5JyCJeHSswreM4aMvwwDQYJKoZIhvcNAQEL
BQAwIDEeMBwGA1UEAwwVc2hpYmJvbGV0aC1pZHAudWt3LmRlMB4XDTIzMDUwMzE0
NDUxNFoXDTI2MDUwMzE0NDUxNFowIDEeMBwGA1UEAwwVc2hpYmJvbGV0aC1pZHAu
dWt3LmRlMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAunnyX+Gz88Ds
wbH4AaigyT3h1jbp3RayxaioKrWK3CmkJhCBC+zjzYcn6tf+0c7UaKGndBz8DENj
dX7uee6HNr7Cg+v+mx3GFbg1Eyildo71jhD/ufQ2GrOlsBvSH5x3BYZWH96IxN/w
qNHS+lujRXafRwjhlJGVeF9eIUlxjRm/uqwbfE0fRgjpUoF5yVHx2ns2rkXjPf/e
AlmX9LscAHua60M3PCJ9BGhy1zeBK7RCYHotaqljTEEfGexUvGwpJbVf4PnZMt78
1mN1cmpIZhCXsUzjI7JqxQB+4wRoWqW4BaAj+7DZAjFRAyV/K766Ujm9s20kTOvS
yb16pyXkLKehSECSGBo/Ct0FLgBlYplPQ9ObZ1zRYCY3fEU/53USfLT0UwDGrJt1
gnzEIX4s01J4xRadzb1wHyclvZcmqBJyD3etgWbarU+WtIsDZUjLzD56j9Tv72eH
G331kBIPR3LU7gJ4VhZtBBhdoFXSqhWqeRGBJ1h2IxghJ6+qQc64hAPaA4f07ohA
lBc5GWbb7FtEDSll7PGOT8iaZSDoDXewiW+UUxgEVuqXCNV1g9G83GRRRr5fMEIw
qoM4LuEHFLhBK7DNI/Pjn997KtP+DyCw1g8EzOsuTCLStRxHnVXCskIVOYDK2Ivc
YorZFgAoDA2Q7w6hnqBBmAfufByR72kCAwEAAaNDMEEwHQYDVR0OBBYEFPFRmyAs
1jHUMLm4EUizJ0PQZeFrMCAGA1UdEQQZMBeCFXNoaWJib2xldGgtaWRwLnVrdy5k
ZTANBgkqhkiG9w0BAQsFAAOCAgEAiI14BQfMOX4LDyw+aOwHL3vMEsYL1L9cblrT
KIhqqUZSJHCEOvhZi9tm9aKlsg7Sef71MlyuhLQBea2/XMU/rXZRkCGAcDsiLgrq
pwwkLTILd5MdoWMbmikb7/ECGBifgocQJaVntzQ55kre9bexmt4ygnyqrv6lbpKi
xJKuWrCRKpKgFf8XQStwIa3kybdqd1UIWZqqR1jv7Utjw8rOZsIY2GZnUY/eHXr1
URG0MqyzvL/Y+Aab5nAZ968yw697ls51Z8mQ+Kt6T9+hon7803258BO0r9EPn/HR
5Uu7EAc+gzZ951CFhb6buw55uHHE7L8a1w/k5lDZXr0AEmwv3cGRz9F31Hog36II
dTq22n3TXDdgg4pu7jf4biPsS1vOggsnOKtFFaQk/PbC4twPLhYX398FtAZXLnTR
6iivBnY90VGVRiXvpcaq99Z7kXmu5i7WhLY/4Mx5DZTrdm0RWvNPPq0tiIB9eFDH
gwHnLdVKP/vqH3optxXIV4exmsCQWrpArszy7eumds+4e2hXVyYRcm91iFFbfoM+
uhLfoJw9TT5rfH6hAOD1pe7CXWQLigqt8xrh9Hkw2aigT94P3FoUiZTy+94KP2zn
Thtv/ZfnC7E1syD4bWRasqsT2KNhxSM+pqMBUgTPsjsImahrmHnwSyUSHdiAENJe
kIZeg84=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

	</KeyDescriptor>   -->


<!-- Neues Cert 2026 - 2029 ATH -->

       <KeyDescriptor>
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIFHDCCAwSgAwIBAgIUXw2Ka0qAeCE7+wtHm/M7q+jYYHYwDQYJKoZIhvcNAQEL
BQAwIDEeMBwGA1UEAwwVc2hpYmJvbGV0aC1pZHAudWt3LmRlMB4XDTI2MDQxNzEz
MTkxMFoXDTI5MDQxNzEzMTkxMFowIDEeMBwGA1UEAwwVc2hpYmJvbGV0aC1pZHAu
dWt3LmRlMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAjLGWt31FURCs
Ng9aQhxydQHZZkVIYj6kDAgYSVAD7OI/Ppa6tukJk3fLRbog3mvdyd9yQOdazK3/
TKkfCNm1q3EgZeaSEC7OhZKc6S3T9LHAstiaiB7k/5pNiQgaYSnCcki9d3Aedm6F
lpz5a+EH246xy3YSz8i+pyXKlOVF8HH1P4s7JPgPsI8uXVV+AryJgC4roEpEjrCt
VeLU8xk+yBpLRNz5Ofxx8UaU50B7CkUoA8BYYtMKSm8J/JfaAAAm8+2HjVbl3ztA
WpbNpkWwNhCrMjift7DPt9H28gKXiDnz0IZ5ZkwLI7LW2Lhr2uVkxPKnZreL/mlo
ZNAkpKlucB8pb8v0TcNI3UhhH12oEx48SIpjwLBnig1OHGm59WSRPLW4G0cR992f
8h3XwQGwAg4VS5EBSV/Ll8gQCcDmvcPe8ztlg+sOoTociiJIkA79Adrkwrj2GYpc
1AEFHvno7JsqTWMZlyn11fEs8WuDL2DIO7cV15n9fzsyCesRy6FuIMktm3co15ql
YdCj83btsf581cJYn43+P66KAR4sSveyr96z+9VIzAvD9dj6PcHvoMvD5uAJZGPG
hFVSvO+BotCo7fhsqA84FITb2CM3vH7TzUlPeBIv1yZ6e8zjH2W9/UdO37vJt3sJ
33BXNdzNlDG9hKEcANdMFcKf1GsMeDsCAwEAAaNOMEwwHQYDVR0OBBYEFHNvtMl0
4uaBnpkNFOGkpeqfpTHWMCAGA1UdEQQZMBeCFXNoaWJib2xldGgtaWRwLnVrdy5k
ZTAJBgNVHRMEAjAAMA0GCSqGSIb3DQEBCwUAA4ICAQAYE1tySvHj8oWZ+kolIDj0
vR6Hav8XncH3HQ+KryE8XIa+zox+m7fRIhc9DWJHHwk/ZFHclLTLlSsJm1PPL1Se
HoipRoNhg4VouRv+IRoY/D4RpXi2jcEDBn+UEDV7qNcyYql+IDpdOCEcBfRS7AAT
Qv5qPyjjKxNJiqTohz4VnhfLl5972maOVuSjJpnYwsYTVBaSXpKx9GtAhWu8M7Lu
4gpgxNAkeNT/U660Ta2xpNuDft2tdORwwnBsTIpme0at4+t10jXQzJ57X1DabDwp
M1VDfOSjFU8FBlzR337eTwhySoC3YF8KKnUVoP4O1Z14ji/ruxiVOzqOh57nd272
Uu9IU4avasykhaqdmBGSWP0UxURtKmKfz0BeOL493WxPb+Z5oxmBmulCH1WbyULk
I7G1D21mupe6CFz0Pown0RBSV980NTuS+P9flOBuhe/PEotC7ln3sV/PtQdU5SXN
EISDHkEaKn83NofBVDUgB3EA/D1aFv6DD/QnpWy0UIOrLq7e1AbnJloDW9vyfGXH
i0x4ssXZMo0C5Xzc3KMfja986BgrmvXJB3oey+Rbcv9TBfTR83MjMygPofRNxLGN
suOPGPfpBZ7sOwCz8Y3aY/JDWVqDmjxend4s53foH/HQYCQKu6eFrHuweMsE8V5b
Nh1nt3PRwLh7lsOQckPw2w==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>


        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://shibboleth-idp.ukw.de:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>
        <!--<ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://shibboleth-idp.ukw.de:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
--> 
<!--
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://shibboleth-idp.ukw.de/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://shibboleth-idp.ukw.de/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://shibboleth-idp.ukw.de/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://shibboleth-idp.ukw.de:8443/idp/profile/SAML2/SOAP/SLO"/>
--> 

        <!--<SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://shibboleth-idp.ukw.de/idp/profile/Shibboleth/SSO"/>
-->         <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://shibboleth-idp.ukw.de/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://shibboleth-idp.ukw.de/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://shibboleth-idp.ukw.de/idp/profile/SAML2/Redirect/SSO"/>

    </IDPSSODescriptor>


<!--    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">ukw.de</shibmd:Scope>
        </Extensions>

        --> <!-- First signing certificate is BackChannel, the Second is FrontChannel-->  <!--
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        --> <!--<AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://shibboleth-idp.ukw.de:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>-->  <!--
        --> <!--<AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://shibboleth-idp.ukw.de:8443/idp/profile/SAML2/SOAP/AttributeQuery"/>-->  <!--
        --> <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above-->  <!--

    </AttributeAuthorityDescriptor>--> 

</EntityDescriptor>
