<?xml version="1.0" encoding="UTF-8"?>
<md:EntityDescriptor    entityID="https://iris-iam.stfc.ac.uk/sp-entityID"
                        xmlns:ds="http://www.w3.org/2000/09/xmldsig#"
                        xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
                        xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
                        xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui">

    <md:Extensions>
        <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
            <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
                            Name="http://macedir.org/entity-category"
                            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
                <saml:AttributeValue>
                    http://www.geant.net/uri/dataprotection-code-of-conduct/v1
                </saml:AttributeValue>
                <saml:AttributeValue>
                    http://refeds.org/category/research-and-scholarship
                </saml:AttributeValue>
            </saml:Attribute>
            <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
                            Name="urn:oasis:names:tc:SAML:attribute:assurance-certification"
                            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
                <saml:AttributeValue>
                    https://refeds.org/sirtfi
                </saml:AttributeValue>
            </saml:Attribute>
        </mdattr:EntityAttributes>
    </md:Extensions>

    <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">

        <md:Extensions>
            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">IRIS Identity and Access Management (IAM)</mdui:DisplayName>
                <mdui:Description xml:lang="en">The IRIS Identity and Access Management (IAM) is a central service used to manage identities and authorization policies for IRIS resources and services.</mdui:Description>
                <mdui:InformationURL xml:lang="en">https://iris-iam.stfc.ac.uk/privacypolicy/</mdui:InformationURL>
                <mdui:PrivacyStatementURL xml:lang="en">https://iris-iam.stfc.ac.uk/privacypolicy/</mdui:PrivacyStatementURL>
                <mdui:Logo height="150" width="150">https://www.iris.ac.uk/wp-content/uploads/2018/07/iris-circle-150x150.png</mdui:Logo>
            </mdui:UIInfo>
        </md:Extensions>

        <md:KeyDescriptor use="signing">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
                    MIIEIzCCAwugAwIBAgIUPlzr4lWp2HzSbnJOxw9H4tRMDIAwDQYJKoZIhvcNAQEL
                    BQAwgaAxCzAJBgNVBAYTAlVLMRQwEgYDVQQIDAtPeGZvcmRzaGlyZTEPMA0GA1UE
                    BwwGRGlkY290MQ0wCwYDVQQKDARTVEZDMQwwCgYDVQQLDANTQ0QxHDAaBgNVBAMM
                    E2lyaXMtaWFtLnN0ZmMuYWMudWsxLzAtBgkqhkiG9w0BCQEWIGlyaXMtaWFtLXN1
                    cHBvcnRAZ3JpZHBwLnJsLmFjLnVrMB4XDTI0MDcyNTEyNDIyNloXDTM0MDcyMzEy
                    NDIyNlowgaAxCzAJBgNVBAYTAlVLMRQwEgYDVQQIDAtPeGZvcmRzaGlyZTEPMA0G
                    A1UEBwwGRGlkY290MQ0wCwYDVQQKDARTVEZDMQwwCgYDVQQLDANTQ0QxHDAaBgNV
                    BAMME2lyaXMtaWFtLnN0ZmMuYWMudWsxLzAtBgkqhkiG9w0BCQEWIGlyaXMtaWFt
                    LXN1cHBvcnRAZ3JpZHBwLnJsLmFjLnVrMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
                    MIIBCgKCAQEA6z79wrMseIA2sNyVB95gG9/ilJD6/EVBYMTteZp6H9U+XgaS9FpU
                    f1HJM0YYEzsbJn9lsDaKQq8vQLjoW1d4NuHvLnf0HFdIaKO5Kwo0wcmg0F0ZLOI0
                    jUFRaW7Uiexi/7g5+IFn59+aUxc8eRPEVm/k7PJ+1eMzzujcFegzxyyZsOBtqQWG
                    rBRaOXhg08xe3PJKLFjbpQoEpMjw54Hdb0VOCapqDlUYotCv3Y2uhTcfglPribjO
                    1VhnG93ENo2k8gvRZYceIkMQhydq36kTEwR87fI6GGm5zaWQT+d84g9l1WjszrVJ
                    KLU6Hq1/aI7amzR1+zfEalUnJE9Hmn7QBwIDAQABo1MwUTAdBgNVHQ4EFgQUsGba
                    a2SOWTU6m6WjG+xz5S190AEwHwYDVR0jBBgwFoAUsGbaa2SOWTU6m6WjG+xz5S19
                    0AEwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAcaDlC3N2CJEU
                    R3TBFa76FZgRiuxzwOc5vSlozmH8hcUCJ978wbKLN1CAredqhE3bvebWikJnGH0G
                    +T8GT2Itpp9fEAY47qAbHjG0o0tXN7ubbHzqrh4Xbh8j44OpcaqwfgLMymZq/aIr
                    8Li8n3n7ZrziDWiZh5Qauu6IyFJXGdp1K6+c6qEYK3OmDnvEe3UGWhCwXUhboqBs
                    lR8pVaN00DCrM9xQEWizJ2F/NvDg4GN2VKcXyjSGVXruLBY1OLYzs9NEzUB+re+x
                    P8y+Zexsw+AdZy0aXfhLWb5b4gxkzXyQCEjrhFI288VMhORir/wzbSFDW5/dFko5
                    JNq7dwxnzw==
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </md:KeyDescriptor>

        <md:KeyDescriptor use="encryption">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
                    MIIEIzCCAwugAwIBAgIUPlzr4lWp2HzSbnJOxw9H4tRMDIAwDQYJKoZIhvcNAQEL
                    BQAwgaAxCzAJBgNVBAYTAlVLMRQwEgYDVQQIDAtPeGZvcmRzaGlyZTEPMA0GA1UE
                    BwwGRGlkY290MQ0wCwYDVQQKDARTVEZDMQwwCgYDVQQLDANTQ0QxHDAaBgNVBAMM
                    E2lyaXMtaWFtLnN0ZmMuYWMudWsxLzAtBgkqhkiG9w0BCQEWIGlyaXMtaWFtLXN1
                    cHBvcnRAZ3JpZHBwLnJsLmFjLnVrMB4XDTI0MDcyNTEyNDIyNloXDTM0MDcyMzEy
                    NDIyNlowgaAxCzAJBgNVBAYTAlVLMRQwEgYDVQQIDAtPeGZvcmRzaGlyZTEPMA0G
                    A1UEBwwGRGlkY290MQ0wCwYDVQQKDARTVEZDMQwwCgYDVQQLDANTQ0QxHDAaBgNV
                    BAMME2lyaXMtaWFtLnN0ZmMuYWMudWsxLzAtBgkqhkiG9w0BCQEWIGlyaXMtaWFt
                    LXN1cHBvcnRAZ3JpZHBwLnJsLmFjLnVrMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
                    MIIBCgKCAQEA6z79wrMseIA2sNyVB95gG9/ilJD6/EVBYMTteZp6H9U+XgaS9FpU
                    f1HJM0YYEzsbJn9lsDaKQq8vQLjoW1d4NuHvLnf0HFdIaKO5Kwo0wcmg0F0ZLOI0
                    jUFRaW7Uiexi/7g5+IFn59+aUxc8eRPEVm/k7PJ+1eMzzujcFegzxyyZsOBtqQWG
                    rBRaOXhg08xe3PJKLFjbpQoEpMjw54Hdb0VOCapqDlUYotCv3Y2uhTcfglPribjO
                    1VhnG93ENo2k8gvRZYceIkMQhydq36kTEwR87fI6GGm5zaWQT+d84g9l1WjszrVJ
                    KLU6Hq1/aI7amzR1+zfEalUnJE9Hmn7QBwIDAQABo1MwUTAdBgNVHQ4EFgQUsGba
                    a2SOWTU6m6WjG+xz5S190AEwHwYDVR0jBBgwFoAUsGbaa2SOWTU6m6WjG+xz5S19
                    0AEwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAcaDlC3N2CJEU
                    R3TBFa76FZgRiuxzwOc5vSlozmH8hcUCJ978wbKLN1CAredqhE3bvebWikJnGH0G
                    +T8GT2Itpp9fEAY47qAbHjG0o0tXN7ubbHzqrh4Xbh8j44OpcaqwfgLMymZq/aIr
                    8Li8n3n7ZrziDWiZh5Qauu6IyFJXGdp1K6+c6qEYK3OmDnvEe3UGWhCwXUhboqBs
                    lR8pVaN00DCrM9xQEWizJ2F/NvDg4GN2VKcXyjSGVXruLBY1OLYzs9NEzUB+re+x
                    P8y+Zexsw+AdZy0aXfhLWb5b4gxkzXyQCEjrhFI288VMhORir/wzbSFDW5/dFko5
                    JNq7dwxnzw==
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </md:KeyDescriptor>

        <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://iris-iam.stfc.ac.uk/saml/SingleLogout" />
        <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://iris-iam.stfc.ac.uk/saml/SingleLogout" />

        <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat>

        <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://iris-iam.stfc.ac.uk/saml/SSO" index="0" isDefault="true" />
        <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://iris-iam.stfc.ac.uk/saml/SSO" index="1" />

        <md:AttributeConsumingService index="0">
            <md:ServiceName xml:lang="en">IRIS Identity and Access Management (IAM)</md:ServiceName>
            <md:ServiceDescription xml:lang="en">The IRIS Identity and Access Management (IAM) is a central service used to manage identities and authorization policies for IRIS resources and services.</md:ServiceDescription>
            <md:RequestedAttribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true" />
            <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true" />
            <md:RequestedAttribute FriendlyName="givenName" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true" />
            <md:RequestedAttribute FriendlyName="sn" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true" />
            <md:RequestedAttribute FriendlyName="eduPersonScopedAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.1" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true" />
            <md:RequestedAttribute FriendlyName="eduPersonTargetedID" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="false" />
            <md:RequestedAttribute FriendlyName="eduPersonUniqueId" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.13" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="false" />
        </md:AttributeConsumingService>

    </md:SPSSODescriptor>

    <md:Organization>
        <md:OrganizationName xml:lang="en">Science and Technology Facilities Council</md:OrganizationName>
        <md:OrganizationDisplayName xml:lang="en">Science and Technology Facilities Council</md:OrganizationDisplayName>
        <md:OrganizationURL xml:lang="en">http://www.stfc.ac.uk/</md:OrganizationURL>
    </md:Organization>

    <md:ContactPerson contactType="technical">
        <md:EmailAddress>mailto:thomas.dack@stfc.ac.uk</md:EmailAddress>
    </md:ContactPerson>

    <md:ContactPerson contactType="technical">
        <md:EmailAddress>mailto:donald.chung@stfc.ac.uk</md:EmailAddress>
    </md:ContactPerson>

    <md:ContactPerson contactType="support">
        <md:EmailAddress>mailto:iris-iam-support@gridpp.rl.ac.uk</md:EmailAddress>
    </md:ContactPerson>

    <md:ContactPerson  xmlns:remd="http://refeds.org/metadata"
                    contactType="other"
                    remd:contactType="http://refeds.org/metadata/contactType/security">
        <md:GivenName>Thomas Dack</md:GivenName>
        <md:EmailAddress>mailto:thomas.dack@stfc.ac.uk</md:EmailAddress>
    </md:ContactPerson>

</md:EntityDescriptor>
