<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" entityID="https://idp.ipu-berlin.de/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">ipu-berlin.de</shibmd:Scope>
<!--
    Fill in the details for your IdP here 
-->

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="de">IPU Berlin</mdui:DisplayName>
                <mdui:DisplayName xml:lang="en">IPU Berlin</mdui:DisplayName>

                <mdui:Description xml:lang="de">Identity Provider der IPU Berlin</mdui:Description>
                <mdui:Description xml:lang="en">IPU Berlin Identity Provider</mdui:Description>
                <mdui:Logo height="16" width="16">https://idp.ipu-berlin.de/favicon.ico</mdui:Logo>
                <mdui:Logo height="80" width="80">https://idp.ipu-berlin.de/logo240.png</mdui:Logo>
            </mdui:UIInfo>
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIH6zCCBdOgAwIBAgIMJ9UFYawbFvwuT/TkMA0GCSqGSIb3DQEBCwUAMIGVMQsw
CQYDVQQGEwJERTFFMEMGA1UECgw8VmVyZWluIHp1ciBGb2VyZGVydW5nIGVpbmVz
IERldXRzY2hlbiBGb3JzY2h1bmdzbmV0emVzIGUuIFYuMRAwDgYDVQQLDAdERk4t
UEtJMS0wKwYDVQQDDCRERk4tVmVyZWluIENvbW11bml0eSBJc3N1aW5nIENBIDIw
MjIwHhcNMjMwMTA0MTQwNjA5WhcNMjYwMzE5MTQwNjA5WjCBijELMAkGA1UEBhMC
REUxDzANBgNVBAgMBkJlcmxpbjEPMA0GA1UEBwwGQmVybGluMT0wOwYDVQQKDDRJ
bnRlcm5hdGlvbmFsIFBzeWNob2FuYWx5dGljIFVuaXZlcnNpdHkgQmVybGluIGdH
bWJIMRowGAYDVQQDDBFpZHAuaXB1LWJlcmxpbi5kZTCCAiIwDQYJKoZIhvcNAQEB
BQADggIPADCCAgoCggIBAJyl7xOeacGQiHOS4wMYcApKGknHfDMJ0k6dg+nTRcLG
jgl/iM12R6T/dV9NqtmNcUmS3K3you4HKGPC3IJC2VmkhmN98SfPReEHfFZo45K9
tT2yNYC29oFq/JMnm3FoE28HergWfwPfSzZ0EQUi/yd1F7BfC+1M2bwHhq9D3iHH
XClP2+yaNNWzbXJe6OdAeA4DJrkHafCDFGdgODqrkk7jCzKT9tyfqY66BVB4AK9q
C1Tqc9U3Plz/RFDxrO6n3gdsPAEc1RaozrP+P2zHBjY0d91Nv7a7rUuArktr2gAd
GgyX3yA6P5ZElirQ3wx5IBmJAUcbWp4jXd1B6xAdoPdmf/fW6WbXv1VDiy42ORq0
2bQT131+ST35zZFi8RahyNtv8Rrx8Ox9+qWdu4RY33udSTmQmbPy+UITLEAbOjAO
rnu7RdB10e2qsUZ6uPOL0w4MPWfW2cNiwft4iP+dNdVdAM3aRbwc4JnMsHPvQjBp
0Ilj2cKRw7970tIv3ZfqgJORBNFTObtrgMcK1hPuhXvvfm3zUCqVQHlsABCrUZn2
pWbm0jx9rkcfkgFfIn+kLmknYosztBLj4uog/SueTtsk2teiu8hRHFbAu5HGk6UA
mD53Rcnfe7BjFKFLtqReFSDU+MizlGpTk6OdrOoP3To+H2NkP9ZPl+WjFosIGQPv
AgMBAAGjggJCMIICPjAJBgNVHRMEAjAAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUE
FjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFKM025coV0xzZbnISkrF
vok0Fj0LMB8GA1UdIwQYMBaAFMQoXYtDj1K14+2sq9w4cYi4gYwDMBwGA1UdEQQV
MBOCEWlkcC5pcHUtYmVybGluLmRlMIGbBgNVHR8EgZMwgZAwRqBEoEKGQGh0dHA6
Ly9jZHAxLnBjYS5kZm4uZGUvZGZuLXZlcmVpbi1jb21tdW5pdHktY2EvcHViL2Ny
bC9jYWNybC5jcmwwRqBEoEKGQGh0dHA6Ly9jZHAyLnBjYS5kZm4uZGUvZGZuLXZl
cmVpbi1jb21tdW5pdHktY2EvcHViL2NybC9jYWNybC5jcmwwgekGCCsGAQUFBwEB
BIHcMIHZMDMGCCsGAQUFBzABhidodHRwOi8vb2NzcC5wY2EuZGZuLmRlL09DU1At
U2VydmVyL09DU1AwUAYIKwYBBQUHMAKGRGh0dHA6Ly9jZHAxLnBjYS5kZm4uZGUv
ZGZuLXZlcmVpbi1jb21tdW5pdHktY2EvcHViL2NhY2VydC9jYWNlcnQuY3J0MFAG
CCsGAQUFBzAChkRodHRwOi8vY2RwMi5wY2EuZGZuLmRlL2Rmbi12ZXJlaW4tY29t
bXVuaXR5LWNhL3B1Yi9jYWNlcnQvY2FjZXJ0LmNydDAaBgNVHSAEEzARMA8GDSsG
AQQBga0hgiwCAQcwDQYJKoZIhvcNAQELBQADggIBAJg5nHbMxJi4Dmyj28e1jE6Z
vLPGjRiIgoa9ou4M8CZtSPh/KOtYVS66ArcoHx30BBEuQ0z+iRLyESXI4SZUdvoY
kot9Hpp5QqcbN3X9KXbP728b9mtT1t2mLY6BirQsKz+SqVFHteAfYJbGTz5aoLDq
V117ro/oQ11YS5Ja9pkCgcICIZRh2k79C/KhEjNb3l3zZU9Cbgg6ndQ7w9H+Tyvr
Munr5Q/QVsThM5oiqjULOkFwXblvKHX0/mBqZYJjGrEZlPMCLtrpHp8KvzVKXy1O
XN3ED96G5MPPbUK30zFBtodVPHbUJaNKoimp67Cfv9O7j1P+OmO9zN/izvhEkuPW
hYpDAeJ/76SNaczUq7l0dUpGkrkjmiacm2zwTDBmOA1ox4li1SAOCFJXwIuEGsvd
vl7seBnM7e/zTZfWf7QnHta9g39l/WYImZpQKXRcHcHF/vvTNVBXFXmAjDQnaVe/
EICPWFQYja1Is54a3tFS9yzIvKbw6KKLE1ZdIyqD8b/CcdMmtnUuT9dd8ljIujZq
3XZCYFqJMODIAvVd3dQjLoc974nOLPiZ38eSHsBvs4E4kCBmEsBuIMDi1Q4XFdyE
ziX0a5CkHXcxPPS923N6kReupYf8QTJa8D9unckrFZCVxUn74FBSfMoXV6P5g57O
1Bhq5X5rWB2lt8wRVXmE
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIH6zCCBdOgAwIBAgIMJ9UFYawbFvwuT/TkMA0GCSqGSIb3DQEBCwUAMIGVMQsw
CQYDVQQGEwJERTFFMEMGA1UECgw8VmVyZWluIHp1ciBGb2VyZGVydW5nIGVpbmVz
IERldXRzY2hlbiBGb3JzY2h1bmdzbmV0emVzIGUuIFYuMRAwDgYDVQQLDAdERk4t
UEtJMS0wKwYDVQQDDCRERk4tVmVyZWluIENvbW11bml0eSBJc3N1aW5nIENBIDIw
MjIwHhcNMjMwMTA0MTQwNjA5WhcNMjYwMzE5MTQwNjA5WjCBijELMAkGA1UEBhMC
REUxDzANBgNVBAgMBkJlcmxpbjEPMA0GA1UEBwwGQmVybGluMT0wOwYDVQQKDDRJ
bnRlcm5hdGlvbmFsIFBzeWNob2FuYWx5dGljIFVuaXZlcnNpdHkgQmVybGluIGdH
bWJIMRowGAYDVQQDDBFpZHAuaXB1LWJlcmxpbi5kZTCCAiIwDQYJKoZIhvcNAQEB
BQADggIPADCCAgoCggIBAJyl7xOeacGQiHOS4wMYcApKGknHfDMJ0k6dg+nTRcLG
jgl/iM12R6T/dV9NqtmNcUmS3K3you4HKGPC3IJC2VmkhmN98SfPReEHfFZo45K9
tT2yNYC29oFq/JMnm3FoE28HergWfwPfSzZ0EQUi/yd1F7BfC+1M2bwHhq9D3iHH
XClP2+yaNNWzbXJe6OdAeA4DJrkHafCDFGdgODqrkk7jCzKT9tyfqY66BVB4AK9q
C1Tqc9U3Plz/RFDxrO6n3gdsPAEc1RaozrP+P2zHBjY0d91Nv7a7rUuArktr2gAd
GgyX3yA6P5ZElirQ3wx5IBmJAUcbWp4jXd1B6xAdoPdmf/fW6WbXv1VDiy42ORq0
2bQT131+ST35zZFi8RahyNtv8Rrx8Ox9+qWdu4RY33udSTmQmbPy+UITLEAbOjAO
rnu7RdB10e2qsUZ6uPOL0w4MPWfW2cNiwft4iP+dNdVdAM3aRbwc4JnMsHPvQjBp
0Ilj2cKRw7970tIv3ZfqgJORBNFTObtrgMcK1hPuhXvvfm3zUCqVQHlsABCrUZn2
pWbm0jx9rkcfkgFfIn+kLmknYosztBLj4uog/SueTtsk2teiu8hRHFbAu5HGk6UA
mD53Rcnfe7BjFKFLtqReFSDU+MizlGpTk6OdrOoP3To+H2NkP9ZPl+WjFosIGQPv
AgMBAAGjggJCMIICPjAJBgNVHRMEAjAAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUE
FjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFKM025coV0xzZbnISkrF
vok0Fj0LMB8GA1UdIwQYMBaAFMQoXYtDj1K14+2sq9w4cYi4gYwDMBwGA1UdEQQV
MBOCEWlkcC5pcHUtYmVybGluLmRlMIGbBgNVHR8EgZMwgZAwRqBEoEKGQGh0dHA6
Ly9jZHAxLnBjYS5kZm4uZGUvZGZuLXZlcmVpbi1jb21tdW5pdHktY2EvcHViL2Ny
bC9jYWNybC5jcmwwRqBEoEKGQGh0dHA6Ly9jZHAyLnBjYS5kZm4uZGUvZGZuLXZl
cmVpbi1jb21tdW5pdHktY2EvcHViL2NybC9jYWNybC5jcmwwgekGCCsGAQUFBwEB
BIHcMIHZMDMGCCsGAQUFBzABhidodHRwOi8vb2NzcC5wY2EuZGZuLmRlL09DU1At
U2VydmVyL09DU1AwUAYIKwYBBQUHMAKGRGh0dHA6Ly9jZHAxLnBjYS5kZm4uZGUv
ZGZuLXZlcmVpbi1jb21tdW5pdHktY2EvcHViL2NhY2VydC9jYWNlcnQuY3J0MFAG
CCsGAQUFBzAChkRodHRwOi8vY2RwMi5wY2EuZGZuLmRlL2Rmbi12ZXJlaW4tY29t
bXVuaXR5LWNhL3B1Yi9jYWNlcnQvY2FjZXJ0LmNydDAaBgNVHSAEEzARMA8GDSsG
AQQBga0hgiwCAQcwDQYJKoZIhvcNAQELBQADggIBAJg5nHbMxJi4Dmyj28e1jE6Z
vLPGjRiIgoa9ou4M8CZtSPh/KOtYVS66ArcoHx30BBEuQ0z+iRLyESXI4SZUdvoY
kot9Hpp5QqcbN3X9KXbP728b9mtT1t2mLY6BirQsKz+SqVFHteAfYJbGTz5aoLDq
V117ro/oQ11YS5Ja9pkCgcICIZRh2k79C/KhEjNb3l3zZU9Cbgg6ndQ7w9H+Tyvr
Munr5Q/QVsThM5oiqjULOkFwXblvKHX0/mBqZYJjGrEZlPMCLtrpHp8KvzVKXy1O
XN3ED96G5MPPbUK30zFBtodVPHbUJaNKoimp67Cfv9O7j1P+OmO9zN/izvhEkuPW
hYpDAeJ/76SNaczUq7l0dUpGkrkjmiacm2zwTDBmOA1ox4li1SAOCFJXwIuEGsvd
vl7seBnM7e/zTZfWf7QnHta9g39l/WYImZpQKXRcHcHF/vvTNVBXFXmAjDQnaVe/
EICPWFQYja1Is54a3tFS9yzIvKbw6KKLE1ZdIyqD8b/CcdMmtnUuT9dd8ljIujZq
3XZCYFqJMODIAvVd3dQjLoc974nOLPiZ38eSHsBvs4E4kCBmEsBuIMDi1Q4XFdyE
ziX0a5CkHXcxPPS923N6kReupYf8QTJa8D9unckrFZCVxUn74FBSfMoXV6P5g57O
1Bhq5X5rWB2lt8wRVXmE
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIH6zCCBdOgAwIBAgIMJ9UFYawbFvwuT/TkMA0GCSqGSIb3DQEBCwUAMIGVMQsw
CQYDVQQGEwJERTFFMEMGA1UECgw8VmVyZWluIHp1ciBGb2VyZGVydW5nIGVpbmVz
IERldXRzY2hlbiBGb3JzY2h1bmdzbmV0emVzIGUuIFYuMRAwDgYDVQQLDAdERk4t
UEtJMS0wKwYDVQQDDCRERk4tVmVyZWluIENvbW11bml0eSBJc3N1aW5nIENBIDIw
MjIwHhcNMjMwMTA0MTQwNjA5WhcNMjYwMzE5MTQwNjA5WjCBijELMAkGA1UEBhMC
REUxDzANBgNVBAgMBkJlcmxpbjEPMA0GA1UEBwwGQmVybGluMT0wOwYDVQQKDDRJ
bnRlcm5hdGlvbmFsIFBzeWNob2FuYWx5dGljIFVuaXZlcnNpdHkgQmVybGluIGdH
bWJIMRowGAYDVQQDDBFpZHAuaXB1LWJlcmxpbi5kZTCCAiIwDQYJKoZIhvcNAQEB
BQADggIPADCCAgoCggIBAJyl7xOeacGQiHOS4wMYcApKGknHfDMJ0k6dg+nTRcLG
jgl/iM12R6T/dV9NqtmNcUmS3K3you4HKGPC3IJC2VmkhmN98SfPReEHfFZo45K9
tT2yNYC29oFq/JMnm3FoE28HergWfwPfSzZ0EQUi/yd1F7BfC+1M2bwHhq9D3iHH
XClP2+yaNNWzbXJe6OdAeA4DJrkHafCDFGdgODqrkk7jCzKT9tyfqY66BVB4AK9q
C1Tqc9U3Plz/RFDxrO6n3gdsPAEc1RaozrP+P2zHBjY0d91Nv7a7rUuArktr2gAd
GgyX3yA6P5ZElirQ3wx5IBmJAUcbWp4jXd1B6xAdoPdmf/fW6WbXv1VDiy42ORq0
2bQT131+ST35zZFi8RahyNtv8Rrx8Ox9+qWdu4RY33udSTmQmbPy+UITLEAbOjAO
rnu7RdB10e2qsUZ6uPOL0w4MPWfW2cNiwft4iP+dNdVdAM3aRbwc4JnMsHPvQjBp
0Ilj2cKRw7970tIv3ZfqgJORBNFTObtrgMcK1hPuhXvvfm3zUCqVQHlsABCrUZn2
pWbm0jx9rkcfkgFfIn+kLmknYosztBLj4uog/SueTtsk2teiu8hRHFbAu5HGk6UA
mD53Rcnfe7BjFKFLtqReFSDU+MizlGpTk6OdrOoP3To+H2NkP9ZPl+WjFosIGQPv
AgMBAAGjggJCMIICPjAJBgNVHRMEAjAAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUE
FjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFKM025coV0xzZbnISkrF
vok0Fj0LMB8GA1UdIwQYMBaAFMQoXYtDj1K14+2sq9w4cYi4gYwDMBwGA1UdEQQV
MBOCEWlkcC5pcHUtYmVybGluLmRlMIGbBgNVHR8EgZMwgZAwRqBEoEKGQGh0dHA6
Ly9jZHAxLnBjYS5kZm4uZGUvZGZuLXZlcmVpbi1jb21tdW5pdHktY2EvcHViL2Ny
bC9jYWNybC5jcmwwRqBEoEKGQGh0dHA6Ly9jZHAyLnBjYS5kZm4uZGUvZGZuLXZl
cmVpbi1jb21tdW5pdHktY2EvcHViL2NybC9jYWNybC5jcmwwgekGCCsGAQUFBwEB
BIHcMIHZMDMGCCsGAQUFBzABhidodHRwOi8vb2NzcC5wY2EuZGZuLmRlL09DU1At
U2VydmVyL09DU1AwUAYIKwYBBQUHMAKGRGh0dHA6Ly9jZHAxLnBjYS5kZm4uZGUv
ZGZuLXZlcmVpbi1jb21tdW5pdHktY2EvcHViL2NhY2VydC9jYWNlcnQuY3J0MFAG
CCsGAQUFBzAChkRodHRwOi8vY2RwMi5wY2EuZGZuLmRlL2Rmbi12ZXJlaW4tY29t
bXVuaXR5LWNhL3B1Yi9jYWNlcnQvY2FjZXJ0LmNydDAaBgNVHSAEEzARMA8GDSsG
AQQBga0hgiwCAQcwDQYJKoZIhvcNAQELBQADggIBAJg5nHbMxJi4Dmyj28e1jE6Z
vLPGjRiIgoa9ou4M8CZtSPh/KOtYVS66ArcoHx30BBEuQ0z+iRLyESXI4SZUdvoY
kot9Hpp5QqcbN3X9KXbP728b9mtT1t2mLY6BirQsKz+SqVFHteAfYJbGTz5aoLDq
V117ro/oQ11YS5Ja9pkCgcICIZRh2k79C/KhEjNb3l3zZU9Cbgg6ndQ7w9H+Tyvr
Munr5Q/QVsThM5oiqjULOkFwXblvKHX0/mBqZYJjGrEZlPMCLtrpHp8KvzVKXy1O
XN3ED96G5MPPbUK30zFBtodVPHbUJaNKoimp67Cfv9O7j1P+OmO9zN/izvhEkuPW
hYpDAeJ/76SNaczUq7l0dUpGkrkjmiacm2zwTDBmOA1ox4li1SAOCFJXwIuEGsvd
vl7seBnM7e/zTZfWf7QnHta9g39l/WYImZpQKXRcHcHF/vvTNVBXFXmAjDQnaVe/
EICPWFQYja1Is54a3tFS9yzIvKbw6KKLE1ZdIyqD8b/CcdMmtnUuT9dd8ljIujZq
3XZCYFqJMODIAvVd3dQjLoc974nOLPiZ38eSHsBvs4E4kCBmEsBuIMDi1Q4XFdyE
ziX0a5CkHXcxPPS923N6kReupYf8QTJa8D9unckrFZCVxUn74FBSfMoXV6P5g57O
1Bhq5X5rWB2lt8wRVXmE
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.ipu-berlin.de:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.ipu-berlin.de:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>

        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.ipu-berlin.de/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.ipu-berlin.de/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.ipu-berlin.de:8443/idp/profile/SAML2/SOAP/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.ipu-berlin.de/idp/profile/SAML2/Redirect/SLO"/>

        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.ipu-berlin.de/idp/profile/Shibboleth/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://idp.ipu-berlin.de/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://idp.ipu-berlin.de/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://idp.ipu-berlin.de/idp/profile/SAML2/Redirect/SSO"/>

  <!-- den fehlenden ECP-Endpoint hinzufügen -->
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.ipu-berlin.de/idp/profile/SAML2/SOAP/ECP"/>
 
        <!-- die fehlenden NameID-Formate hinzufügen -->
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>

    </IDPSSODescriptor>


    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">ipu-berlin.de</shibmd:Scope>
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIH6zCCBdOgAwIBAgIMJ9UFYawbFvwuT/TkMA0GCSqGSIb3DQEBCwUAMIGVMQsw
CQYDVQQGEwJERTFFMEMGA1UECgw8VmVyZWluIHp1ciBGb2VyZGVydW5nIGVpbmVz
IERldXRzY2hlbiBGb3JzY2h1bmdzbmV0emVzIGUuIFYuMRAwDgYDVQQLDAdERk4t
UEtJMS0wKwYDVQQDDCRERk4tVmVyZWluIENvbW11bml0eSBJc3N1aW5nIENBIDIw
MjIwHhcNMjMwMTA0MTQwNjA5WhcNMjYwMzE5MTQwNjA5WjCBijELMAkGA1UEBhMC
REUxDzANBgNVBAgMBkJlcmxpbjEPMA0GA1UEBwwGQmVybGluMT0wOwYDVQQKDDRJ
bnRlcm5hdGlvbmFsIFBzeWNob2FuYWx5dGljIFVuaXZlcnNpdHkgQmVybGluIGdH
bWJIMRowGAYDVQQDDBFpZHAuaXB1LWJlcmxpbi5kZTCCAiIwDQYJKoZIhvcNAQEB
BQADggIPADCCAgoCggIBAJyl7xOeacGQiHOS4wMYcApKGknHfDMJ0k6dg+nTRcLG
jgl/iM12R6T/dV9NqtmNcUmS3K3you4HKGPC3IJC2VmkhmN98SfPReEHfFZo45K9
tT2yNYC29oFq/JMnm3FoE28HergWfwPfSzZ0EQUi/yd1F7BfC+1M2bwHhq9D3iHH
XClP2+yaNNWzbXJe6OdAeA4DJrkHafCDFGdgODqrkk7jCzKT9tyfqY66BVB4AK9q
C1Tqc9U3Plz/RFDxrO6n3gdsPAEc1RaozrP+P2zHBjY0d91Nv7a7rUuArktr2gAd
GgyX3yA6P5ZElirQ3wx5IBmJAUcbWp4jXd1B6xAdoPdmf/fW6WbXv1VDiy42ORq0
2bQT131+ST35zZFi8RahyNtv8Rrx8Ox9+qWdu4RY33udSTmQmbPy+UITLEAbOjAO
rnu7RdB10e2qsUZ6uPOL0w4MPWfW2cNiwft4iP+dNdVdAM3aRbwc4JnMsHPvQjBp
0Ilj2cKRw7970tIv3ZfqgJORBNFTObtrgMcK1hPuhXvvfm3zUCqVQHlsABCrUZn2
pWbm0jx9rkcfkgFfIn+kLmknYosztBLj4uog/SueTtsk2teiu8hRHFbAu5HGk6UA
mD53Rcnfe7BjFKFLtqReFSDU+MizlGpTk6OdrOoP3To+H2NkP9ZPl+WjFosIGQPv
AgMBAAGjggJCMIICPjAJBgNVHRMEAjAAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUE
FjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFKM025coV0xzZbnISkrF
vok0Fj0LMB8GA1UdIwQYMBaAFMQoXYtDj1K14+2sq9w4cYi4gYwDMBwGA1UdEQQV
MBOCEWlkcC5pcHUtYmVybGluLmRlMIGbBgNVHR8EgZMwgZAwRqBEoEKGQGh0dHA6
Ly9jZHAxLnBjYS5kZm4uZGUvZGZuLXZlcmVpbi1jb21tdW5pdHktY2EvcHViL2Ny
bC9jYWNybC5jcmwwRqBEoEKGQGh0dHA6Ly9jZHAyLnBjYS5kZm4uZGUvZGZuLXZl
cmVpbi1jb21tdW5pdHktY2EvcHViL2NybC9jYWNybC5jcmwwgekGCCsGAQUFBwEB
BIHcMIHZMDMGCCsGAQUFBzABhidodHRwOi8vb2NzcC5wY2EuZGZuLmRlL09DU1At
U2VydmVyL09DU1AwUAYIKwYBBQUHMAKGRGh0dHA6Ly9jZHAxLnBjYS5kZm4uZGUv
ZGZuLXZlcmVpbi1jb21tdW5pdHktY2EvcHViL2NhY2VydC9jYWNlcnQuY3J0MFAG
CCsGAQUFBzAChkRodHRwOi8vY2RwMi5wY2EuZGZuLmRlL2Rmbi12ZXJlaW4tY29t
bXVuaXR5LWNhL3B1Yi9jYWNlcnQvY2FjZXJ0LmNydDAaBgNVHSAEEzARMA8GDSsG
AQQBga0hgiwCAQcwDQYJKoZIhvcNAQELBQADggIBAJg5nHbMxJi4Dmyj28e1jE6Z
vLPGjRiIgoa9ou4M8CZtSPh/KOtYVS66ArcoHx30BBEuQ0z+iRLyESXI4SZUdvoY
kot9Hpp5QqcbN3X9KXbP728b9mtT1t2mLY6BirQsKz+SqVFHteAfYJbGTz5aoLDq
V117ro/oQ11YS5Ja9pkCgcICIZRh2k79C/KhEjNb3l3zZU9Cbgg6ndQ7w9H+Tyvr
Munr5Q/QVsThM5oiqjULOkFwXblvKHX0/mBqZYJjGrEZlPMCLtrpHp8KvzVKXy1O
XN3ED96G5MPPbUK30zFBtodVPHbUJaNKoimp67Cfv9O7j1P+OmO9zN/izvhEkuPW
hYpDAeJ/76SNaczUq7l0dUpGkrkjmiacm2zwTDBmOA1ox4li1SAOCFJXwIuEGsvd
vl7seBnM7e/zTZfWf7QnHta9g39l/WYImZpQKXRcHcHF/vvTNVBXFXmAjDQnaVe/
EICPWFQYja1Is54a3tFS9yzIvKbw6KKLE1ZdIyqD8b/CcdMmtnUuT9dd8ljIujZq
3XZCYFqJMODIAvVd3dQjLoc974nOLPiZ38eSHsBvs4E4kCBmEsBuIMDi1Q4XFdyE
ziX0a5CkHXcxPPS923N6kReupYf8QTJa8D9unckrFZCVxUn74FBSfMoXV6P5g57O
1Bhq5X5rWB2lt8wRVXmE
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIH6zCCBdOgAwIBAgIMJ9UFYawbFvwuT/TkMA0GCSqGSIb3DQEBCwUAMIGVMQsw
CQYDVQQGEwJERTFFMEMGA1UECgw8VmVyZWluIHp1ciBGb2VyZGVydW5nIGVpbmVz
IERldXRzY2hlbiBGb3JzY2h1bmdzbmV0emVzIGUuIFYuMRAwDgYDVQQLDAdERk4t
UEtJMS0wKwYDVQQDDCRERk4tVmVyZWluIENvbW11bml0eSBJc3N1aW5nIENBIDIw
MjIwHhcNMjMwMTA0MTQwNjA5WhcNMjYwMzE5MTQwNjA5WjCBijELMAkGA1UEBhMC
REUxDzANBgNVBAgMBkJlcmxpbjEPMA0GA1UEBwwGQmVybGluMT0wOwYDVQQKDDRJ
bnRlcm5hdGlvbmFsIFBzeWNob2FuYWx5dGljIFVuaXZlcnNpdHkgQmVybGluIGdH
bWJIMRowGAYDVQQDDBFpZHAuaXB1LWJlcmxpbi5kZTCCAiIwDQYJKoZIhvcNAQEB
BQADggIPADCCAgoCggIBAJyl7xOeacGQiHOS4wMYcApKGknHfDMJ0k6dg+nTRcLG
jgl/iM12R6T/dV9NqtmNcUmS3K3you4HKGPC3IJC2VmkhmN98SfPReEHfFZo45K9
tT2yNYC29oFq/JMnm3FoE28HergWfwPfSzZ0EQUi/yd1F7BfC+1M2bwHhq9D3iHH
XClP2+yaNNWzbXJe6OdAeA4DJrkHafCDFGdgODqrkk7jCzKT9tyfqY66BVB4AK9q
C1Tqc9U3Plz/RFDxrO6n3gdsPAEc1RaozrP+P2zHBjY0d91Nv7a7rUuArktr2gAd
GgyX3yA6P5ZElirQ3wx5IBmJAUcbWp4jXd1B6xAdoPdmf/fW6WbXv1VDiy42ORq0
2bQT131+ST35zZFi8RahyNtv8Rrx8Ox9+qWdu4RY33udSTmQmbPy+UITLEAbOjAO
rnu7RdB10e2qsUZ6uPOL0w4MPWfW2cNiwft4iP+dNdVdAM3aRbwc4JnMsHPvQjBp
0Ilj2cKRw7970tIv3ZfqgJORBNFTObtrgMcK1hPuhXvvfm3zUCqVQHlsABCrUZn2
pWbm0jx9rkcfkgFfIn+kLmknYosztBLj4uog/SueTtsk2teiu8hRHFbAu5HGk6UA
mD53Rcnfe7BjFKFLtqReFSDU+MizlGpTk6OdrOoP3To+H2NkP9ZPl+WjFosIGQPv
AgMBAAGjggJCMIICPjAJBgNVHRMEAjAAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUE
FjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFKM025coV0xzZbnISkrF
vok0Fj0LMB8GA1UdIwQYMBaAFMQoXYtDj1K14+2sq9w4cYi4gYwDMBwGA1UdEQQV
MBOCEWlkcC5pcHUtYmVybGluLmRlMIGbBgNVHR8EgZMwgZAwRqBEoEKGQGh0dHA6
Ly9jZHAxLnBjYS5kZm4uZGUvZGZuLXZlcmVpbi1jb21tdW5pdHktY2EvcHViL2Ny
bC9jYWNybC5jcmwwRqBEoEKGQGh0dHA6Ly9jZHAyLnBjYS5kZm4uZGUvZGZuLXZl
cmVpbi1jb21tdW5pdHktY2EvcHViL2NybC9jYWNybC5jcmwwgekGCCsGAQUFBwEB
BIHcMIHZMDMGCCsGAQUFBzABhidodHRwOi8vb2NzcC5wY2EuZGZuLmRlL09DU1At
U2VydmVyL09DU1AwUAYIKwYBBQUHMAKGRGh0dHA6Ly9jZHAxLnBjYS5kZm4uZGUv
ZGZuLXZlcmVpbi1jb21tdW5pdHktY2EvcHViL2NhY2VydC9jYWNlcnQuY3J0MFAG
CCsGAQUFBzAChkRodHRwOi8vY2RwMi5wY2EuZGZuLmRlL2Rmbi12ZXJlaW4tY29t
bXVuaXR5LWNhL3B1Yi9jYWNlcnQvY2FjZXJ0LmNydDAaBgNVHSAEEzARMA8GDSsG
AQQBga0hgiwCAQcwDQYJKoZIhvcNAQELBQADggIBAJg5nHbMxJi4Dmyj28e1jE6Z
vLPGjRiIgoa9ou4M8CZtSPh/KOtYVS66ArcoHx30BBEuQ0z+iRLyESXI4SZUdvoY
kot9Hpp5QqcbN3X9KXbP728b9mtT1t2mLY6BirQsKz+SqVFHteAfYJbGTz5aoLDq
V117ro/oQ11YS5Ja9pkCgcICIZRh2k79C/KhEjNb3l3zZU9Cbgg6ndQ7w9H+Tyvr
Munr5Q/QVsThM5oiqjULOkFwXblvKHX0/mBqZYJjGrEZlPMCLtrpHp8KvzVKXy1O
XN3ED96G5MPPbUK30zFBtodVPHbUJaNKoimp67Cfv9O7j1P+OmO9zN/izvhEkuPW
hYpDAeJ/76SNaczUq7l0dUpGkrkjmiacm2zwTDBmOA1ox4li1SAOCFJXwIuEGsvd
vl7seBnM7e/zTZfWf7QnHta9g39l/WYImZpQKXRcHcHF/vvTNVBXFXmAjDQnaVe/
EICPWFQYja1Is54a3tFS9yzIvKbw6KKLE1ZdIyqD8b/CcdMmtnUuT9dd8ljIujZq
3XZCYFqJMODIAvVd3dQjLoc974nOLPiZ38eSHsBvs4E4kCBmEsBuIMDi1Q4XFdyE
ziX0a5CkHXcxPPS923N6kReupYf8QTJa8D9unckrFZCVxUn74FBSfMoXV6P5g57O
1Bhq5X5rWB2lt8wRVXmE
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
-----BEGIN CERTIFICATE-----
MIIH6zCCBdOgAwIBAgIMJ9UFYawbFvwuT/TkMA0GCSqGSIb3DQEBCwUAMIGVMQsw
CQYDVQQGEwJERTFFMEMGA1UECgw8VmVyZWluIHp1ciBGb2VyZGVydW5nIGVpbmVz
IERldXRzY2hlbiBGb3JzY2h1bmdzbmV0emVzIGUuIFYuMRAwDgYDVQQLDAdERk4t
UEtJMS0wKwYDVQQDDCRERk4tVmVyZWluIENvbW11bml0eSBJc3N1aW5nIENBIDIw
MjIwHhcNMjMwMTA0MTQwNjA5WhcNMjYwMzE5MTQwNjA5WjCBijELMAkGA1UEBhMC
REUxDzANBgNVBAgMBkJlcmxpbjEPMA0GA1UEBwwGQmVybGluMT0wOwYDVQQKDDRJ
bnRlcm5hdGlvbmFsIFBzeWNob2FuYWx5dGljIFVuaXZlcnNpdHkgQmVybGluIGdH
bWJIMRowGAYDVQQDDBFpZHAuaXB1LWJlcmxpbi5kZTCCAiIwDQYJKoZIhvcNAQEB
BQADggIPADCCAgoCggIBAJyl7xOeacGQiHOS4wMYcApKGknHfDMJ0k6dg+nTRcLG
jgl/iM12R6T/dV9NqtmNcUmS3K3you4HKGPC3IJC2VmkhmN98SfPReEHfFZo45K9
tT2yNYC29oFq/JMnm3FoE28HergWfwPfSzZ0EQUi/yd1F7BfC+1M2bwHhq9D3iHH
XClP2+yaNNWzbXJe6OdAeA4DJrkHafCDFGdgODqrkk7jCzKT9tyfqY66BVB4AK9q
C1Tqc9U3Plz/RFDxrO6n3gdsPAEc1RaozrP+P2zHBjY0d91Nv7a7rUuArktr2gAd
GgyX3yA6P5ZElirQ3wx5IBmJAUcbWp4jXd1B6xAdoPdmf/fW6WbXv1VDiy42ORq0
2bQT131+ST35zZFi8RahyNtv8Rrx8Ox9+qWdu4RY33udSTmQmbPy+UITLEAbOjAO
rnu7RdB10e2qsUZ6uPOL0w4MPWfW2cNiwft4iP+dNdVdAM3aRbwc4JnMsHPvQjBp
0Ilj2cKRw7970tIv3ZfqgJORBNFTObtrgMcK1hPuhXvvfm3zUCqVQHlsABCrUZn2
pWbm0jx9rkcfkgFfIn+kLmknYosztBLj4uog/SueTtsk2teiu8hRHFbAu5HGk6UA
mD53Rcnfe7BjFKFLtqReFSDU+MizlGpTk6OdrOoP3To+H2NkP9ZPl+WjFosIGQPv
AgMBAAGjggJCMIICPjAJBgNVHRMEAjAAMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUE
FjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFKM025coV0xzZbnISkrF
vok0Fj0LMB8GA1UdIwQYMBaAFMQoXYtDj1K14+2sq9w4cYi4gYwDMBwGA1UdEQQV
MBOCEWlkcC5pcHUtYmVybGluLmRlMIGbBgNVHR8EgZMwgZAwRqBEoEKGQGh0dHA6
Ly9jZHAxLnBjYS5kZm4uZGUvZGZuLXZlcmVpbi1jb21tdW5pdHktY2EvcHViL2Ny
bC9jYWNybC5jcmwwRqBEoEKGQGh0dHA6Ly9jZHAyLnBjYS5kZm4uZGUvZGZuLXZl
cmVpbi1jb21tdW5pdHktY2EvcHViL2NybC9jYWNybC5jcmwwgekGCCsGAQUFBwEB
BIHcMIHZMDMGCCsGAQUFBzABhidodHRwOi8vb2NzcC5wY2EuZGZuLmRlL09DU1At
U2VydmVyL09DU1AwUAYIKwYBBQUHMAKGRGh0dHA6Ly9jZHAxLnBjYS5kZm4uZGUv
ZGZuLXZlcmVpbi1jb21tdW5pdHktY2EvcHViL2NhY2VydC9jYWNlcnQuY3J0MFAG
CCsGAQUFBzAChkRodHRwOi8vY2RwMi5wY2EuZGZuLmRlL2Rmbi12ZXJlaW4tY29t
bXVuaXR5LWNhL3B1Yi9jYWNlcnQvY2FjZXJ0LmNydDAaBgNVHSAEEzARMA8GDSsG
AQQBga0hgiwCAQcwDQYJKoZIhvcNAQELBQADggIBAJg5nHbMxJi4Dmyj28e1jE6Z
vLPGjRiIgoa9ou4M8CZtSPh/KOtYVS66ArcoHx30BBEuQ0z+iRLyESXI4SZUdvoY
kot9Hpp5QqcbN3X9KXbP728b9mtT1t2mLY6BirQsKz+SqVFHteAfYJbGTz5aoLDq
V117ro/oQ11YS5Ja9pkCgcICIZRh2k79C/KhEjNb3l3zZU9Cbgg6ndQ7w9H+Tyvr
Munr5Q/QVsThM5oiqjULOkFwXblvKHX0/mBqZYJjGrEZlPMCLtrpHp8KvzVKXy1O
XN3ED96G5MPPbUK30zFBtodVPHbUJaNKoimp67Cfv9O7j1P+OmO9zN/izvhEkuPW
hYpDAeJ/76SNaczUq7l0dUpGkrkjmiacm2zwTDBmOA1ox4li1SAOCFJXwIuEGsvd
vl7seBnM7e/zTZfWf7QnHta9g39l/WYImZpQKXRcHcHF/vvTNVBXFXmAjDQnaVe/
EICPWFQYja1Is54a3tFS9yzIvKbw6KKLE1ZdIyqD8b/CcdMmtnUuT9dd8ljIujZq
3XZCYFqJMODIAvVd3dQjLoc974nOLPiZ38eSHsBvs4E4kCBmEsBuIMDi1Q4XFdyE
ziX0a5CkHXcxPPS923N6kReupYf8QTJa8D9unckrFZCVxUn74FBSfMoXV6P5g57O
1Bhq5X5rWB2lt8wRVXmE
-----END CERTIFICATE-----
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.ipu-berlin.de:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
        <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.ipu-berlin.de:8443/idp/profile/SAML2/SOAP/AttributeQuery"/>
        <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->

        <!-- die fehlenden NameID-Formate hinzufügen -->
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>

    </AttributeAuthorityDescriptor>

</EntityDescriptor>
