<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" entityID="https://afidp.eduhk.hk/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">eduhk.hk</shibmd:Scope>
<!--
    Fill in the details for your IdP here 

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">A Name for the IdP at afidp.eduhk.hk</mdui:DisplayName>
                <mdui:Description xml:lang="en">Enter a description of your IdP at afidp.eduhk.hk</mdui:Description>
                <mdui:Logo height="80" width="80">https://afidp.eduhk.hk/Path/To/Logo.png</mdui:Logo>
            </mdui:UIInfo>
-->
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDJDCCAgygAwIBAgIVANeaEbP11fm4WAjxvN/kYQRJTRVMMA0GCSqGSIb3DQEB
CwUAMBkxFzAVBgNVBAMMDmFmaWRwLmVkdWhrLmhrMB4XDTE2MTEyMTAyMjExNVoX
DTM2MTEyMTAyMjExNVowGTEXMBUGA1UEAwwOYWZpZHAuZWR1aGsuaGswggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCBjH9h45DUYLHH4Fk60mSvmYVd/ite
BBO3uepAicP+iK89YUQdrZpyonmYNidf9P4Idn9fOI5bWiPziZrcQLyogDS94Cm8
lVfxepAJDzmeHU82P+VXYDgD5s1G3Q7QpKbohxVRJIAxtQ8Z1XzReuCZdESYPvuv
ZH6DkM1XqxFJOrTXWrugor84Xp9Bqg46tQn2wwdamj6H03vRncplkBZsQ3p+WuQu
Y9GZx7qrql2V0EyrajZWOJEprl7bZhrDh62nq4goUBgDTxIkKeEZCrsfwBhDHcBm
ILc3w9y6zKBegpGEMxQFe12jWR1ISEktqXc+XS/ZI03He5Rsidj0VAelAgMBAAGj
YzBhMB0GA1UdDgQWBBQtCEFepB5BT74OIVRppVJtBqkwjjBABgNVHREEOTA3gg5h
ZmlkcC5lZHVoay5oa4YlaHR0cHM6Ly9hZmlkcC5lZHVoay5oay9pZHAvc2hpYmJv
bGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAC2C3Du3SGyxSOpS7ObQtawrMxeT97vE4
XPpumQ8uUyB4gkE0eSxyXPC+BHdY3eYkuhWsHEAd/yQtNvVGITsmdkE8wHen2RYU
T9sBvd9kgKNbC8Gz0D0e/CcAs2c9R2y6gDQM/liXMplUYDcmfrMLj7mqCqdbVqfv
phGUWf2f+ppZJGU1pNHZkL4U43fD1xdSyQer2SuLA/rH/100THrS+naXtL89QDjT
mo6ysUE7J9LVye0UiRCf/zSUeqrPK/Bm1t/divrwAM8VAJyHSA9/oxgYeJHvMaOl
bO9wOYvkC9RD5Nh1p2kMBM9lViXIIsCAKyFeHQMOeNKMQxDHsPdwCQ==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDIzCCAgugAwIBAgIUAecWE60nyejU92/SkZhoOiDSUEcwDQYJKoZIhvcNAQEL
BQAwGTEXMBUGA1UEAwwOYWZpZHAuZWR1aGsuaGswHhcNMTYxMTIxMDIyMTE0WhcN
MzYxMTIxMDIyMTE0WjAZMRcwFQYDVQQDDA5hZmlkcC5lZHVoay5oazCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAKEHXHDAPPIApOYZgj0dS5BdcWllm4Ar
vzb50/MDROd4OhsDEtCGQxlSlYbpuBh914uF0z4RLKPxwjTLOlE7lc9IflYoHAcb
zRh26WtJ48tkBijRYo0M4UpzE84I6X9ZZfelJSPMHX3LBo1HwGDIfL6RAbCw6brs
nAAmg1FrKbhtNJBGrVDAIcD21LZLUFTNiUGPLKyj6BDxBED0zccApmZJlhIvq/6L
rbgz1s6bDkXNy+fk0WgInmhS/5J1CksS/1JQ+jZsMpiXQDQZUnju5GbkBgxp8GsU
2al0h/HKZtE4DgHlcsf2yZt/yFw2iT3oQQyDNG3vntNR90YFmxFvq68CAwEAAaNj
MGEwHQYDVR0OBBYEFKZir7CNR+m0oko27R8mpLqfpQivMEAGA1UdEQQ5MDeCDmFm
aWRwLmVkdWhrLmhrhiVodHRwczovL2FmaWRwLmVkdWhrLmhrL2lkcC9zaGliYm9s
ZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQBegvb/iQ2ylTGYpNNsRQydltEm7AYIjWoI
3oQTqlXoeGHryGngX3nGWUN5mWrB4wHTbBUva9mmXACbBWHLYQvaz3Lf/4OIqB4/
QRAA8T9zlIulyWMtP1kZzwFwGmFQrrkH/OZehIO1loeEZ0dQ7pz9N0ySnzR22WD8
E4G7E1Hu8cUTw4D4e5WMfxxTIeGvTs4fFChCD0gtmylLkmdDM0aaE2RO3P58xhTQ
R38Mnw2xE7v8nE2wBY/azODnSvKcr/XyJ4Uc8Vd6ittr/w5V/XAjuThzpgxvGcmx
oQI+D/hNXDypSBABH7NrKQfNzTx6TCJcmOV/vnod4fYTMLIEawca
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDJDCCAgygAwIBAgIVAIAFe/SzhV7Umfu68waV5ncu44NOMA0GCSqGSIb3DQEB
CwUAMBkxFzAVBgNVBAMMDmFmaWRwLmVkdWhrLmhrMB4XDTE2MTEyMTAyMjExNFoX
DTM2MTEyMTAyMjExNFowGTEXMBUGA1UEAwwOYWZpZHAuZWR1aGsuaGswggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQD6L7slXjCaxHVIQ4Fy1Soodlwr+lVX
L3dU+EobJUREb6NQEGu9/vvedNwzFTNp7WAbOQONq7CR/Il7PspwLmW3H+im9EOh
xP30ShOMdohBm+pHUzIm3AReDxDSk/kl/2ap/mtRxIWjqbUtHl50EV9aT8obvuLb
fghpUm1P9fEgHVhldG5t6raNkmaesrxOx//tgwOEF3Kk74Yhg9zFh7wApGaMrwft
pe9COzho4Nz7zpmLTbY/cI4MR5WqaxUVkpgThDrcokI3nVPLFklmzQGwLlAkwsWP
Q7KtguIq6M4H50xitfCLZ0Tanhf9HUvQqiBp0dRgkHZNLg/pYAU12q+9AgMBAAGj
YzBhMB0GA1UdDgQWBBSkslKsT4vax6mpLZy/PyVh1h8ytDBABgNVHREEOTA3gg5h
ZmlkcC5lZHVoay5oa4YlaHR0cHM6Ly9hZmlkcC5lZHVoay5oay9pZHAvc2hpYmJv
bGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAyliwQmY+xTWlJ8ecHrvh8e8CNksAY85b
UnATj2haNvZdPCQtU/UfA7MmuJXi20hbLc7xF09JFc2D1rYhbh+yqy7Ym+L1Yrwb
Np6SWVrbJ3loj8hhk9Izd1BlrecpSfQ6L6utQ64Hn5YZUWlUwGSnoB/aIX3o6fSc
D4PDFaBy5xzHHhKYNy9NNqw4pOAk6Hbp5XBFfU5BFDcKt3VyYErhpA8NQhH2hYsw
m1WQnA7ddqE38zzgIZ7BVuYlyDtI9Iw8kfqpctCcF4XDFjdxoAaRjEkiUkp2AIHS
zmWKAgOko9P1d1Ysa6FN9YF5mY5s/5SFJMgU9BviBK1HfUyvinlCJg==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://afidp.eduhk.hk:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://afidp.eduhk.hk:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>

        <!--
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://afidp.eduhk.hk/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://afidp.eduhk.hk/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://afidp.eduhk.hk/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://afidp.eduhk.hk:8443/idp/profile/SAML2/SOAP/SLO"/>
        -->

        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>

        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://afidp.eduhk.hk/idp/profile/Shibboleth/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://afidp.eduhk.hk/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://afidp.eduhk.hk/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://afidp.eduhk.hk/idp/profile/SAML2/Redirect/SSO"/>

    </IDPSSODescriptor>


    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">eduhk.hk</shibmd:Scope>
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDJDCCAgygAwIBAgIVANeaEbP11fm4WAjxvN/kYQRJTRVMMA0GCSqGSIb3DQEB
CwUAMBkxFzAVBgNVBAMMDmFmaWRwLmVkdWhrLmhrMB4XDTE2MTEyMTAyMjExNVoX
DTM2MTEyMTAyMjExNVowGTEXMBUGA1UEAwwOYWZpZHAuZWR1aGsuaGswggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCBjH9h45DUYLHH4Fk60mSvmYVd/ite
BBO3uepAicP+iK89YUQdrZpyonmYNidf9P4Idn9fOI5bWiPziZrcQLyogDS94Cm8
lVfxepAJDzmeHU82P+VXYDgD5s1G3Q7QpKbohxVRJIAxtQ8Z1XzReuCZdESYPvuv
ZH6DkM1XqxFJOrTXWrugor84Xp9Bqg46tQn2wwdamj6H03vRncplkBZsQ3p+WuQu
Y9GZx7qrql2V0EyrajZWOJEprl7bZhrDh62nq4goUBgDTxIkKeEZCrsfwBhDHcBm
ILc3w9y6zKBegpGEMxQFe12jWR1ISEktqXc+XS/ZI03He5Rsidj0VAelAgMBAAGj
YzBhMB0GA1UdDgQWBBQtCEFepB5BT74OIVRppVJtBqkwjjBABgNVHREEOTA3gg5h
ZmlkcC5lZHVoay5oa4YlaHR0cHM6Ly9hZmlkcC5lZHVoay5oay9pZHAvc2hpYmJv
bGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAC2C3Du3SGyxSOpS7ObQtawrMxeT97vE4
XPpumQ8uUyB4gkE0eSxyXPC+BHdY3eYkuhWsHEAd/yQtNvVGITsmdkE8wHen2RYU
T9sBvd9kgKNbC8Gz0D0e/CcAs2c9R2y6gDQM/liXMplUYDcmfrMLj7mqCqdbVqfv
phGUWf2f+ppZJGU1pNHZkL4U43fD1xdSyQer2SuLA/rH/100THrS+naXtL89QDjT
mo6ysUE7J9LVye0UiRCf/zSUeqrPK/Bm1t/divrwAM8VAJyHSA9/oxgYeJHvMaOl
bO9wOYvkC9RD5Nh1p2kMBM9lViXIIsCAKyFeHQMOeNKMQxDHsPdwCQ==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDIzCCAgugAwIBAgIUAecWE60nyejU92/SkZhoOiDSUEcwDQYJKoZIhvcNAQEL
BQAwGTEXMBUGA1UEAwwOYWZpZHAuZWR1aGsuaGswHhcNMTYxMTIxMDIyMTE0WhcN
MzYxMTIxMDIyMTE0WjAZMRcwFQYDVQQDDA5hZmlkcC5lZHVoay5oazCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAKEHXHDAPPIApOYZgj0dS5BdcWllm4Ar
vzb50/MDROd4OhsDEtCGQxlSlYbpuBh914uF0z4RLKPxwjTLOlE7lc9IflYoHAcb
zRh26WtJ48tkBijRYo0M4UpzE84I6X9ZZfelJSPMHX3LBo1HwGDIfL6RAbCw6brs
nAAmg1FrKbhtNJBGrVDAIcD21LZLUFTNiUGPLKyj6BDxBED0zccApmZJlhIvq/6L
rbgz1s6bDkXNy+fk0WgInmhS/5J1CksS/1JQ+jZsMpiXQDQZUnju5GbkBgxp8GsU
2al0h/HKZtE4DgHlcsf2yZt/yFw2iT3oQQyDNG3vntNR90YFmxFvq68CAwEAAaNj
MGEwHQYDVR0OBBYEFKZir7CNR+m0oko27R8mpLqfpQivMEAGA1UdEQQ5MDeCDmFm
aWRwLmVkdWhrLmhrhiVodHRwczovL2FmaWRwLmVkdWhrLmhrL2lkcC9zaGliYm9s
ZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQBegvb/iQ2ylTGYpNNsRQydltEm7AYIjWoI
3oQTqlXoeGHryGngX3nGWUN5mWrB4wHTbBUva9mmXACbBWHLYQvaz3Lf/4OIqB4/
QRAA8T9zlIulyWMtP1kZzwFwGmFQrrkH/OZehIO1loeEZ0dQ7pz9N0ySnzR22WD8
E4G7E1Hu8cUTw4D4e5WMfxxTIeGvTs4fFChCD0gtmylLkmdDM0aaE2RO3P58xhTQ
R38Mnw2xE7v8nE2wBY/azODnSvKcr/XyJ4Uc8Vd6ittr/w5V/XAjuThzpgxvGcmx
oQI+D/hNXDypSBABH7NrKQfNzTx6TCJcmOV/vnod4fYTMLIEawca
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDJDCCAgygAwIBAgIVAIAFe/SzhV7Umfu68waV5ncu44NOMA0GCSqGSIb3DQEB
CwUAMBkxFzAVBgNVBAMMDmFmaWRwLmVkdWhrLmhrMB4XDTE2MTEyMTAyMjExNFoX
DTM2MTEyMTAyMjExNFowGTEXMBUGA1UEAwwOYWZpZHAuZWR1aGsuaGswggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQD6L7slXjCaxHVIQ4Fy1Soodlwr+lVX
L3dU+EobJUREb6NQEGu9/vvedNwzFTNp7WAbOQONq7CR/Il7PspwLmW3H+im9EOh
xP30ShOMdohBm+pHUzIm3AReDxDSk/kl/2ap/mtRxIWjqbUtHl50EV9aT8obvuLb
fghpUm1P9fEgHVhldG5t6raNkmaesrxOx//tgwOEF3Kk74Yhg9zFh7wApGaMrwft
pe9COzho4Nz7zpmLTbY/cI4MR5WqaxUVkpgThDrcokI3nVPLFklmzQGwLlAkwsWP
Q7KtguIq6M4H50xitfCLZ0Tanhf9HUvQqiBp0dRgkHZNLg/pYAU12q+9AgMBAAGj
YzBhMB0GA1UdDgQWBBSkslKsT4vax6mpLZy/PyVh1h8ytDBABgNVHREEOTA3gg5h
ZmlkcC5lZHVoay5oa4YlaHR0cHM6Ly9hZmlkcC5lZHVoay5oay9pZHAvc2hpYmJv
bGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAyliwQmY+xTWlJ8ecHrvh8e8CNksAY85b
UnATj2haNvZdPCQtU/UfA7MmuJXi20hbLc7xF09JFc2D1rYhbh+yqy7Ym+L1Yrwb
Np6SWVrbJ3loj8hhk9Izd1BlrecpSfQ6L6utQ64Hn5YZUWlUwGSnoB/aIX3o6fSc
D4PDFaBy5xzHHhKYNy9NNqw4pOAk6Hbp5XBFfU5BFDcKt3VyYErhpA8NQhH2hYsw
m1WQnA7ddqE38zzgIZ7BVuYlyDtI9Iw8kfqpctCcF4XDFjdxoAaRjEkiUkp2AIHS
zmWKAgOko9P1d1Ysa6FN9YF5mY5s/5SFJMgU9BviBK1HfUyvinlCJg==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://afidp.eduhk.hk:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
        <!-- <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://afidp.eduhk.hk:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> -->
        <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->

    </AttributeAuthorityDescriptor>

</EntityDescriptor>
