<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" entityID="https://idp.ust.hk/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">ust.hk</shibmd:Scope>
<!--
    Fill in the details for your IdP here 

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">A Name for the IdP at idp.ust.hk</mdui:DisplayName>
                <mdui:Description xml:lang="en">Enter a description of your IdP at idp.ust.hk</mdui:Description>
                <mdui:Logo height="80" width="80">https://idp.ust.hk/Path/To/Logo.png</mdui:Logo>
            </mdui:UIInfo>
-->
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDEzCCAfugAwIBAgIURFJ15L9/9brDVHKzTB8Taws/rW4wDQYJKoZIhvcNAQEL
BQAwFTETMBEGA1UEAwwKaWRwLnVzdC5oazAeFw0xNjEyMTMwNTAxMzlaFw0zNjEy
MTMwNTAxMzlaMBUxEzARBgNVBAMMCmlkcC51c3QuaGswggEiMA0GCSqGSIb3DQEB
AQUAA4IBDwAwggEKAoIBAQCkXVLFSNJzXMYsr/rUy0Q1qgvfxmYI+EUdekkL2SFd
NYLsdZtbrIu4YuOxiYV8v7GIfxPE+FTKUJNbO/8ODt/QcywOaffzwdfS+aaUJxVU
3NGE0RoVpVqtRiC8osadvDJlkZCa02calLNTLkrNZkHz2jNYkrha813Sgs6OfKFa
HsRhRo9uIYtgX7O1tLZZBPhZXaU3gznnNxcbTc/XrtJN4K1EHOr0W+HqnIca3aAV
l7MP0CPHOHxfYL1H1RiX+X6O93Mi3PRq2jRqRwN6WLFCJi0OhyorDRiMehlh0MQS
AnHFx+0Ibb4zUGBdR0cvNuccL4kWvT6z7JqxnjJtEZiPAgMBAAGjWzBZMB0GA1Ud
DgQWBBRa4l/9TqD1YlkKmYwGJgpoKGAIKjA4BgNVHREEMTAvggppZHAudXN0Lmhr
hiFodHRwczovL2lkcC51c3QuaGsvaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQEL
BQADggEBABb1FshtRkbFV0hNswuRGHa4vpCJ5ZUT1V51PwhT2ZRMr6E7162nRmJ6
nFWBKn1QdFVF2BoTYZ9A9clPWZGwz4sBYKjfqEqnImazWDWgkhZ5agLLca90F/ik
VGyMgq6XECKTLQJCHJxCrdZ6MdskUQPrhjDkKtXFTN/X72ExC8WAU/uz3tA3wMt0
cGVNhQ+NfUsMnWI7yHorhzjeDeFKNIsnKx7NMJ0QKwF8omN7V0VlNcWyn/72WewV
uqdgO2qt5YEpptTgU0ikuZ9Fxiz6b+p3YZlhnBRVpVUA9QvUh5FZEmKLoZYKT/h6
ic/4zRx0xX+G22NX6yFIQojg0Bm+uJU=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDFDCCAfygAwIBAgIVAM23MPp++4dkPFh9Br5UakIK4t29MA0GCSqGSIb3DQEB
CwUAMBUxEzARBgNVBAMMCmlkcC51c3QuaGswHhcNMTYxMjEzMDUwMTM5WhcNMzYx
MjEzMDUwMTM5WjAVMRMwEQYDVQQDDAppZHAudXN0LmhrMIIBIjANBgkqhkiG9w0B
AQEFAAOCAQ8AMIIBCgKCAQEA1fCS846vj3azHwxWBNsEaYCc5IKR+4qSq76MSUFB
KGTagmKw+w4q05aBFHrJxPTsVC0osPcz18n6ZFTybAXpMM/UHwwbfMubyk4Wz2Yv
eRXWZPQmfLQIHqciLF5VbgTp7nm2bsxQiDL3BvWGmGFJhWwynw3MMVQdrgm0RrzZ
yECw2QIRTFKW5zdsGcV35mSc/gEGakP9ElpP17LEzDlScxEYy04TEDPOxg5aMzMr
fVvNMWh2W7iRdhNaDHfFeWRYFQ2t4+B5lo19nJknoAQqTwLgHERmkUPILy3RQfr9
bOK4C7TRhjrWpAPQEaXuxe7qzu/j4vvHNL7BatpawZIBjQIDAQABo1swWTAdBgNV
HQ4EFgQUE8IZ+6Un9ktDSBpO/nNFMGzLlK4wOAYDVR0RBDEwL4IKaWRwLnVzdC5o
a4YhaHR0cHM6Ly9pZHAudXN0LmhrL2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEB
CwUAA4IBAQCs8B65njLmhj85AdjEUNgZpOZGTrkzO4ivgnR1TXJik9UshFiKXKW8
RZCFMQ9QO/k04mfnvvyva25O067t8uUrQqIfC7ZeTOqFDY4hDzQ0HdV73SvPXAxy
2UMURZLI8T3SsSho+0eeUZb3VxSMdS5jo2ahRvW62ai7DaqXFCeiJ8Fm3LhWJay3
dLR2KsNVHVt90yIgS7nKh3sGbaWwa3utqJoN//2Vn8SbJcGdZ7xRF/zcVmL+y9AV
T5cGsVGY1LJbuGYXY0LbdqK2AIf6xKWfRa5/Mia0glmugajNnjjDXW108YOFQL7i
/EqAEWAQcQ95pUz5BGpswhAO+j4OzhUy
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDFDCCAfygAwIBAgIVAP5+WhGBzJxmxEQN/rBpzY44KzIWMA0GCSqGSIb3DQEB
CwUAMBUxEzARBgNVBAMMCmlkcC51c3QuaGswHhcNMTYxMjEzMDUwMTM5WhcNMzYx
MjEzMDUwMTM5WjAVMRMwEQYDVQQDDAppZHAudXN0LmhrMIIBIjANBgkqhkiG9w0B
AQEFAAOCAQ8AMIIBCgKCAQEAlHSNfSsSlO+DbP1Prpv5VTIRJPIIURrwkR5eRCxo
lVkXmTT6EqEOnKp0gdJF0wyWiWm6GHrTcOa+wuYQQIVNWE+cNvGf93mvuKyiszGh
ZnSNfb0cSQFrXHvMi1yoFxoUcVv4hxJs7L9LAlg1EpQ6vBLWSKSXrpiODhg9x7mA
lfvwZlfH/xYiumwGOB9+gRS0v2c1huJm5S6IMhEjnFMToWP5z3HMloCkKai0IbHd
mphsyPZCnjkeXcensqOWwxurql4S+/cKON4iiwmZWENFPADqfIfkYcw9hnJUPUOi
oU9sudknCP+zXcwvvjWDDQaI1u7N2frpoolkiAKF307XRQIDAQABo1swWTAdBgNV
HQ4EFgQUyMAbZNbOEAbb45CzrdkhdxI8/bIwOAYDVR0RBDEwL4IKaWRwLnVzdC5o
a4YhaHR0cHM6Ly9pZHAudXN0LmhrL2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEB
CwUAA4IBAQB1NViBJQFOnEhF3HHOcO6vcZR+bJglkmogtLJ9HBbEl08wZnqYdaM5
1/JVQCjjosAcCXSZb9Q7sEQ379XyUqKLj8g9d/AGk7SIt+7wCds2lCkR/qaewOSP
AVFIoXZbFwkUZz8XpoOU8CkjfGx9vy9czBRz4ygu4NkZOCJ3tD01meshPH73MJOF
jNCSTmX1wyjNfNveqAlQtO0zy+WrCym/dPTuNburTG951+5DfYOP8xvxnCVhFWi3
2LFFEMLY1ZStvTPadpEFww4e0L0k7csUovgiq2/7ifPOJNJvR/GIqODlB+ag4i2f
gauAuzm/KQcB2Va7lgRPn8CCSl6d0oxU
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.ust.hk:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.ust.hk:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>

        <!--
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.ust.hk/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.ust.hk/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.ust.hk/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.ust.hk:8443/idp/profile/SAML2/SOAP/SLO"/>
        -->

        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>

        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.ust.hk/idp/profile/Shibboleth/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.ust.hk/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.ust.hk/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.ust.hk/idp/profile/SAML2/Redirect/SSO"/>

    </IDPSSODescriptor>


    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">ust.hk</shibmd:Scope>
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDEzCCAfugAwIBAgIURFJ15L9/9brDVHKzTB8Taws/rW4wDQYJKoZIhvcNAQEL
BQAwFTETMBEGA1UEAwwKaWRwLnVzdC5oazAeFw0xNjEyMTMwNTAxMzlaFw0zNjEy
MTMwNTAxMzlaMBUxEzARBgNVBAMMCmlkcC51c3QuaGswggEiMA0GCSqGSIb3DQEB
AQUAA4IBDwAwggEKAoIBAQCkXVLFSNJzXMYsr/rUy0Q1qgvfxmYI+EUdekkL2SFd
NYLsdZtbrIu4YuOxiYV8v7GIfxPE+FTKUJNbO/8ODt/QcywOaffzwdfS+aaUJxVU
3NGE0RoVpVqtRiC8osadvDJlkZCa02calLNTLkrNZkHz2jNYkrha813Sgs6OfKFa
HsRhRo9uIYtgX7O1tLZZBPhZXaU3gznnNxcbTc/XrtJN4K1EHOr0W+HqnIca3aAV
l7MP0CPHOHxfYL1H1RiX+X6O93Mi3PRq2jRqRwN6WLFCJi0OhyorDRiMehlh0MQS
AnHFx+0Ibb4zUGBdR0cvNuccL4kWvT6z7JqxnjJtEZiPAgMBAAGjWzBZMB0GA1Ud
DgQWBBRa4l/9TqD1YlkKmYwGJgpoKGAIKjA4BgNVHREEMTAvggppZHAudXN0Lmhr
hiFodHRwczovL2lkcC51c3QuaGsvaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQEL
BQADggEBABb1FshtRkbFV0hNswuRGHa4vpCJ5ZUT1V51PwhT2ZRMr6E7162nRmJ6
nFWBKn1QdFVF2BoTYZ9A9clPWZGwz4sBYKjfqEqnImazWDWgkhZ5agLLca90F/ik
VGyMgq6XECKTLQJCHJxCrdZ6MdskUQPrhjDkKtXFTN/X72ExC8WAU/uz3tA3wMt0
cGVNhQ+NfUsMnWI7yHorhzjeDeFKNIsnKx7NMJ0QKwF8omN7V0VlNcWyn/72WewV
uqdgO2qt5YEpptTgU0ikuZ9Fxiz6b+p3YZlhnBRVpVUA9QvUh5FZEmKLoZYKT/h6
ic/4zRx0xX+G22NX6yFIQojg0Bm+uJU=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDFDCCAfygAwIBAgIVAM23MPp++4dkPFh9Br5UakIK4t29MA0GCSqGSIb3DQEB
CwUAMBUxEzARBgNVBAMMCmlkcC51c3QuaGswHhcNMTYxMjEzMDUwMTM5WhcNMzYx
MjEzMDUwMTM5WjAVMRMwEQYDVQQDDAppZHAudXN0LmhrMIIBIjANBgkqhkiG9w0B
AQEFAAOCAQ8AMIIBCgKCAQEA1fCS846vj3azHwxWBNsEaYCc5IKR+4qSq76MSUFB
KGTagmKw+w4q05aBFHrJxPTsVC0osPcz18n6ZFTybAXpMM/UHwwbfMubyk4Wz2Yv
eRXWZPQmfLQIHqciLF5VbgTp7nm2bsxQiDL3BvWGmGFJhWwynw3MMVQdrgm0RrzZ
yECw2QIRTFKW5zdsGcV35mSc/gEGakP9ElpP17LEzDlScxEYy04TEDPOxg5aMzMr
fVvNMWh2W7iRdhNaDHfFeWRYFQ2t4+B5lo19nJknoAQqTwLgHERmkUPILy3RQfr9
bOK4C7TRhjrWpAPQEaXuxe7qzu/j4vvHNL7BatpawZIBjQIDAQABo1swWTAdBgNV
HQ4EFgQUE8IZ+6Un9ktDSBpO/nNFMGzLlK4wOAYDVR0RBDEwL4IKaWRwLnVzdC5o
a4YhaHR0cHM6Ly9pZHAudXN0LmhrL2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEB
CwUAA4IBAQCs8B65njLmhj85AdjEUNgZpOZGTrkzO4ivgnR1TXJik9UshFiKXKW8
RZCFMQ9QO/k04mfnvvyva25O067t8uUrQqIfC7ZeTOqFDY4hDzQ0HdV73SvPXAxy
2UMURZLI8T3SsSho+0eeUZb3VxSMdS5jo2ahRvW62ai7DaqXFCeiJ8Fm3LhWJay3
dLR2KsNVHVt90yIgS7nKh3sGbaWwa3utqJoN//2Vn8SbJcGdZ7xRF/zcVmL+y9AV
T5cGsVGY1LJbuGYXY0LbdqK2AIf6xKWfRa5/Mia0glmugajNnjjDXW108YOFQL7i
/EqAEWAQcQ95pUz5BGpswhAO+j4OzhUy
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDFDCCAfygAwIBAgIVAP5+WhGBzJxmxEQN/rBpzY44KzIWMA0GCSqGSIb3DQEB
CwUAMBUxEzARBgNVBAMMCmlkcC51c3QuaGswHhcNMTYxMjEzMDUwMTM5WhcNMzYx
MjEzMDUwMTM5WjAVMRMwEQYDVQQDDAppZHAudXN0LmhrMIIBIjANBgkqhkiG9w0B
AQEFAAOCAQ8AMIIBCgKCAQEAlHSNfSsSlO+DbP1Prpv5VTIRJPIIURrwkR5eRCxo
lVkXmTT6EqEOnKp0gdJF0wyWiWm6GHrTcOa+wuYQQIVNWE+cNvGf93mvuKyiszGh
ZnSNfb0cSQFrXHvMi1yoFxoUcVv4hxJs7L9LAlg1EpQ6vBLWSKSXrpiODhg9x7mA
lfvwZlfH/xYiumwGOB9+gRS0v2c1huJm5S6IMhEjnFMToWP5z3HMloCkKai0IbHd
mphsyPZCnjkeXcensqOWwxurql4S+/cKON4iiwmZWENFPADqfIfkYcw9hnJUPUOi
oU9sudknCP+zXcwvvjWDDQaI1u7N2frpoolkiAKF307XRQIDAQABo1swWTAdBgNV
HQ4EFgQUyMAbZNbOEAbb45CzrdkhdxI8/bIwOAYDVR0RBDEwL4IKaWRwLnVzdC5o
a4YhaHR0cHM6Ly9pZHAudXN0LmhrL2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEB
CwUAA4IBAQB1NViBJQFOnEhF3HHOcO6vcZR+bJglkmogtLJ9HBbEl08wZnqYdaM5
1/JVQCjjosAcCXSZb9Q7sEQ379XyUqKLj8g9d/AGk7SIt+7wCds2lCkR/qaewOSP
AVFIoXZbFwkUZz8XpoOU8CkjfGx9vy9czBRz4ygu4NkZOCJ3tD01meshPH73MJOF
jNCSTmX1wyjNfNveqAlQtO0zy+WrCym/dPTuNburTG951+5DfYOP8xvxnCVhFWi3
2LFFEMLY1ZStvTPadpEFww4e0L0k7csUovgiq2/7ifPOJNJvR/GIqODlB+ag4i2f
gauAuzm/KQcB2Va7lgRPn8CCSl6d0oxU
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.ust.hk:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
        <!-- <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.ust.hk:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> -->
        <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->

    </AttributeAuthorityDescriptor>

</EntityDescriptor>
