<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" validUntil="2020-03-23T15:52:17.286Z" entityID="https://idp.ifw-kiel.de/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
<!-- Beschreibung und Logo aktivieren -->
        <Extensions>
            <shibmd:Scope regexp="false">ifw-kiel.de</shibmd:Scope>
<!--
    Fill in the details for your IdP here 

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">A Name for the IdP at idp.ifw-kiel.de</mdui:DisplayName>
                <mdui:Description xml:lang="en">Enter a description of your IdP at idp.ifw-kiel.de</mdui:Description>
                <mdui:Logo height="80" width="80">https://idp.ifw-kiel.de/Path/To/Logo.png</mdui:Logo>
            </mdui:UIInfo>
-->

	<mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">Kiel Institute for the world economy (Development)</mdui:DisplayName>
                <mdui:DisplayName xml:lang="de">Kiel Institut für Weltwirtschaft (Development)</mdui:DisplayName>
                <mdui:Description xml:lang="en">Identity Provider of the Kiel Institute</mdui:Description>
                <mdui:Description xml:lang="de">Identity Provider des Kiel Institut für Weltwirtschaft</mdui:Description>
                <mdui:Logo height="16" width="16">https://idp.ifw-kiel.de/favicon.ico</mdui:Logo>
                <mdui:Logo height="80" width="80">https://idp.ifw-kiel.de/idp/images/logo.png</mdui:Logo>
            </mdui:UIInfo>
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEKDCCApCgAwIBAgIVAIw5oqkJ6fiXKo2DsZfXitGnz9CfMA0GCSqGSIb3DQEB
CwUAMBoxGDAWBgNVBAMMD2lkcC5pZncta2llbC5kZTAeFw0yMDAzMjMxNTUwMzRa
Fw00MDAzMjMxNTUwMzRaMBoxGDAWBgNVBAMMD2lkcC5pZncta2llbC5kZTCCAaIw
DQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBANZ58s7l/B4RBGiL7Rz+L0u0pD5U
i0Qsf7exKNoBEwfWwT5DT/6p4Or3+ascsnKvHwoUJQbfKJmtlEl//4kzqq4iaJwM
Alkf3xndtdt9r7+dop1peZQqz0UipwtTZCpUiFvsxR3JExt7+WxHOHkdXkJAQGJC
24jAIQZ6s/fZub69JmB6DAO0d7HxArILrqYf7n3bQDbYtvW9O74fCjIPNdLkJQm2
oUPt07iZ2aD2ensNdj/7aWgFX3Ej3P6wtLLsFz+HX0qweR48p54pXhDszRlb6jW+
IkMlXaYlHSIPsLzm2LxTIxI7zJRMm0vlOO18QopJK15S+9YY78AJnXISUB2oG/J3
gb88lBljx4bIWqUckMQQXvyjx2jF3IH8QUwAtGFObrqu+QxQ9Bh1u7xhr6ggIR9g
UioL3/QL89LVkvosN41uGb1bhjdNUFbQJNYpSLErIo378jaGM3Ifcw/MLRqBx4Lr
WC8KY4OK1rahfdHV1oZq85fQOBnIM9zE/i5eQQIDAQABo2UwYzAdBgNVHQ4EFgQU
LghMKI83yoNEVrC1TM9Du6sHskUwQgYDVR0RBDswOYIPaWRwLmlmdy1raWVsLmRl
hiZodHRwczovL2lkcC5pZncta2llbC5kZS9pZHAvc2hpYmJvbGV0aDANBgkqhkiG
9w0BAQsFAAOCAYEAcfCVyaH27WUbLQxDcBLh3bns19qc6ONwlNRyJGgLXGaX5rFt
xVhnk19K8+i3PETGHIw8JMbntkoAziiCGo2XxYA0EkIz7NKiiVt5pPsofQaDNmxZ
1bTrxiJ7IeaGRkflAppcMakGKLa6QIVm5h/v65bWihGbmrviOPIuMMdaSEX57Cj1
j/yNITx24uJbpzm0E8o55MxkrTQrkw+ueMvlnMf/t6Se/hbeBXErwk+5oWTRdMZe
qaLNR0IwWGwC/7amNF+/kvOPyIKbbktqrsUmq1vQAYHWpkP0ObyBvkWtSZSH7YQb
KAMVAmGmSreXHA97xbJxDeK3qDhKEIlA/SYr2qvpuu4W60HXKosyZbKZhiCoGH1y
hXEAUYb20HAdB7vr+j5DSN2hNLxwaQLszecffSFChGwfvg6rguMERH+KDrNqh9b8
fjqWvvJTUuWDjnKblKFXJMhLiA4ul/XOGavEBToT5URA3OXcCmaglexaScL4uyaq
GKU05zxLqwdb33So
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEJzCCAo+gAwIBAgIUG5fQqvUKneMweDcMaF7LyqFiTYAwDQYJKoZIhvcNAQEL
BQAwGjEYMBYGA1UEAwwPaWRwLmlmdy1raWVsLmRlMB4XDTIwMDMyMzE1NTAzNVoX
DTQwMDMyMzE1NTAzNVowGjEYMBYGA1UEAwwPaWRwLmlmdy1raWVsLmRlMIIBojAN
BgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEApapt6Vw5VQyoGKNUefnWQr+w3Gxm
KCskSaUbVLOgcSEBVdwegaGKgMTwbugYst1OxEKT2m/YYipzUXHOtlHJ2Bju/XTR
oe8R+7f5Z/X4oXrZ38LZieBEqiMKTfzSkbzlQGrxY2cEqNhbvCXkWiPWHIghcykS
FKYKuSf2BO5gpa0dvVSvqIYecioauvap/Cdfv39HpNGiV0O3abrBjd/hDi7aC5dS
R1n51+jrO3TpqmuFc8FAFQ9IFHCI31fb3C+D0bx7GiF/ZW01/+eQoLtle3xouNgF
janb0X0kDt7wDmbUV03AxbsEy4wzRP+vutThBE7x3HYIODdO9eiDXB9xspmulTaZ
jX6rI+gFAntgkd5SUqClVt3xbVn4+LVm4JJpkZ5tnl3o02Sf/QuvaBGhUQlgPMHy
BHqdH1+kn0nbrbaUWrafktAJjZ9QY+czAdP7Q2oTBoagV9K7A1AILM+yT9dN3F02
hmI5QPflYC31cAFTHWrEta20KFspSh77hKPhAgMBAAGjZTBjMB0GA1UdDgQWBBQd
3OhMO+d2irA0J93822r3MEOjGzBCBgNVHREEOzA5gg9pZHAuaWZ3LWtpZWwuZGWG
Jmh0dHBzOi8vaWRwLmlmdy1raWVsLmRlL2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3
DQEBCwUAA4IBgQCNSyS7K21x8jfItiYMjJoWP6vNm65qyhGtkVd8lfzz8iqlZLRE
i1FtaLolYZT9uzblgdCbjCwS6+4hwUZWj1ppv1ZhOoDaw8Nvaj+QJWgiYbtGlMzH
Nh0At25ukZbnHzMcbQdnlAn2fEo+wI7K93mvl02PRAunkqQePLHqiI8igmk23b7J
l4vMeXqAYGKL6QigStZXdp/uM0sgKNsERW/rPHeG5HPHMyKOmuyQgYj3byFn8n4Y
mApC6HTTdR0R9z9hKTfSrXDHigMiBDNG0vInIbyOgCjYgh4K1wui+CF6DZrI/bB1
CAHgkN5H1OP2neOVmAV3LNh1skugiFEnL2aB1uiCSFSA5drHiV9k4biVcifv8jAB
MR7gyeTO77WwUYce+f2k/mXLF2FDv2cj+zasCX5oTkuPWOHeJhSIN9eLQ7QsBU12
HQV6zKg2NxZ8TrbbNsuP/iQq4SNBYrHu7vyxeALPMIyh2w9eEFLbkdLgHvbKou6n
vHw0zcm8BIVCBFQ=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.ifw-kiel.de:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.ifw-kiel.de:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>

       
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.ifw-kiel.de/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.ifw-kiel.de/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.ifw-kiel.de/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.ifw-kiel.de:8443/idp/profile/SAML2/SOAP/SLO"/>
        

        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://idp.ifw-kiel.de/idp/profile/SAML2/Redirect/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://idp.ifw-kiel.de/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://idp.ifw-kiel.de/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.ifw-kiel.de/idp/profile/Shibboleth/SSO"/>
	<SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.ifw-kiel.de/idp/profile/SAML2/SOAP/ECP"/>

	<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>
    </IDPSSODescriptor>


    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">ifw-kiel.de</shibmd:Scope>
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEKDCCApCgAwIBAgIVAIw5oqkJ6fiXKo2DsZfXitGnz9CfMA0GCSqGSIb3DQEB
CwUAMBoxGDAWBgNVBAMMD2lkcC5pZncta2llbC5kZTAeFw0yMDAzMjMxNTUwMzRa
Fw00MDAzMjMxNTUwMzRaMBoxGDAWBgNVBAMMD2lkcC5pZncta2llbC5kZTCCAaIw
DQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBANZ58s7l/B4RBGiL7Rz+L0u0pD5U
i0Qsf7exKNoBEwfWwT5DT/6p4Or3+ascsnKvHwoUJQbfKJmtlEl//4kzqq4iaJwM
Alkf3xndtdt9r7+dop1peZQqz0UipwtTZCpUiFvsxR3JExt7+WxHOHkdXkJAQGJC
24jAIQZ6s/fZub69JmB6DAO0d7HxArILrqYf7n3bQDbYtvW9O74fCjIPNdLkJQm2
oUPt07iZ2aD2ensNdj/7aWgFX3Ej3P6wtLLsFz+HX0qweR48p54pXhDszRlb6jW+
IkMlXaYlHSIPsLzm2LxTIxI7zJRMm0vlOO18QopJK15S+9YY78AJnXISUB2oG/J3
gb88lBljx4bIWqUckMQQXvyjx2jF3IH8QUwAtGFObrqu+QxQ9Bh1u7xhr6ggIR9g
UioL3/QL89LVkvosN41uGb1bhjdNUFbQJNYpSLErIo378jaGM3Ifcw/MLRqBx4Lr
WC8KY4OK1rahfdHV1oZq85fQOBnIM9zE/i5eQQIDAQABo2UwYzAdBgNVHQ4EFgQU
LghMKI83yoNEVrC1TM9Du6sHskUwQgYDVR0RBDswOYIPaWRwLmlmdy1raWVsLmRl
hiZodHRwczovL2lkcC5pZncta2llbC5kZS9pZHAvc2hpYmJvbGV0aDANBgkqhkiG
9w0BAQsFAAOCAYEAcfCVyaH27WUbLQxDcBLh3bns19qc6ONwlNRyJGgLXGaX5rFt
xVhnk19K8+i3PETGHIw8JMbntkoAziiCGo2XxYA0EkIz7NKiiVt5pPsofQaDNmxZ
1bTrxiJ7IeaGRkflAppcMakGKLa6QIVm5h/v65bWihGbmrviOPIuMMdaSEX57Cj1
j/yNITx24uJbpzm0E8o55MxkrTQrkw+ueMvlnMf/t6Se/hbeBXErwk+5oWTRdMZe
qaLNR0IwWGwC/7amNF+/kvOPyIKbbktqrsUmq1vQAYHWpkP0ObyBvkWtSZSH7YQb
KAMVAmGmSreXHA97xbJxDeK3qDhKEIlA/SYr2qvpuu4W60HXKosyZbKZhiCoGH1y
hXEAUYb20HAdB7vr+j5DSN2hNLxwaQLszecffSFChGwfvg6rguMERH+KDrNqh9b8
fjqWvvJTUuWDjnKblKFXJMhLiA4ul/XOGavEBToT5URA3OXcCmaglexaScL4uyaq
GKU05zxLqwdb33So
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEJzCCAo+gAwIBAgIUG5fQqvUKneMweDcMaF7LyqFiTYAwDQYJKoZIhvcNAQEL
BQAwGjEYMBYGA1UEAwwPaWRwLmlmdy1raWVsLmRlMB4XDTIwMDMyMzE1NTAzNVoX
DTQwMDMyMzE1NTAzNVowGjEYMBYGA1UEAwwPaWRwLmlmdy1raWVsLmRlMIIBojAN
BgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEApapt6Vw5VQyoGKNUefnWQr+w3Gxm
KCskSaUbVLOgcSEBVdwegaGKgMTwbugYst1OxEKT2m/YYipzUXHOtlHJ2Bju/XTR
oe8R+7f5Z/X4oXrZ38LZieBEqiMKTfzSkbzlQGrxY2cEqNhbvCXkWiPWHIghcykS
FKYKuSf2BO5gpa0dvVSvqIYecioauvap/Cdfv39HpNGiV0O3abrBjd/hDi7aC5dS
R1n51+jrO3TpqmuFc8FAFQ9IFHCI31fb3C+D0bx7GiF/ZW01/+eQoLtle3xouNgF
janb0X0kDt7wDmbUV03AxbsEy4wzRP+vutThBE7x3HYIODdO9eiDXB9xspmulTaZ
jX6rI+gFAntgkd5SUqClVt3xbVn4+LVm4JJpkZ5tnl3o02Sf/QuvaBGhUQlgPMHy
BHqdH1+kn0nbrbaUWrafktAJjZ9QY+czAdP7Q2oTBoagV9K7A1AILM+yT9dN3F02
hmI5QPflYC31cAFTHWrEta20KFspSh77hKPhAgMBAAGjZTBjMB0GA1UdDgQWBBQd
3OhMO+d2irA0J93822r3MEOjGzBCBgNVHREEOzA5gg9pZHAuaWZ3LWtpZWwuZGWG
Jmh0dHBzOi8vaWRwLmlmdy1raWVsLmRlL2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3
DQEBCwUAA4IBgQCNSyS7K21x8jfItiYMjJoWP6vNm65qyhGtkVd8lfzz8iqlZLRE
i1FtaLolYZT9uzblgdCbjCwS6+4hwUZWj1ppv1ZhOoDaw8Nvaj+QJWgiYbtGlMzH
Nh0At25ukZbnHzMcbQdnlAn2fEo+wI7K93mvl02PRAunkqQePLHqiI8igmk23b7J
l4vMeXqAYGKL6QigStZXdp/uM0sgKNsERW/rPHeG5HPHMyKOmuyQgYj3byFn8n4Y
mApC6HTTdR0R9z9hKTfSrXDHigMiBDNG0vInIbyOgCjYgh4K1wui+CF6DZrI/bB1
CAHgkN5H1OP2neOVmAV3LNh1skugiFEnL2aB1uiCSFSA5drHiV9k4biVcifv8jAB
MR7gyeTO77WwUYce+f2k/mXLF2FDv2cj+zasCX5oTkuPWOHeJhSIN9eLQ7QsBU12
HQV6zKg2NxZ8TrbbNsuP/iQq4SNBYrHu7vyxeALPMIyh2w9eEFLbkdLgHvbKou6n
vHw0zcm8BIVCBFQ=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>

        <!-- <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.ifw-kiel.de:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> -->
        <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->
        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.ifw-kiel.de:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
	<AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.ifw-kiel.de:8443/idp/profile/SAML2/SOAP/AttributeQuery"/>
   	
	<!-- die fehlenden NameID-Formate hinzufügen -->
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>


	 </AttributeAuthorityDescriptor>

</EntityDescriptor>
