<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.
     validUntil="2019-05-14T11:58:16.283Z"  
     This metadata is not dynamic - it will not change as your configuration changes.
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" entityID="https://idp2.maxrubner.de/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">maxrubner.de</shibmd:Scope>
	    <shibmd:Scope regexp="false">mri.bund.de</shibmd:Scope>
<!--
    Fill in the details for your IdP here 
-->
            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">Max Rubner-Institute (Neu)</mdui:DisplayName>
		<mdui:DisplayName xml:lang="de">Max Rubner-Institut (Neu)</mdui:DisplayName>
                <mdui:Description xml:lang="en">Identity Provider of Max Rubner-Institute</mdui:Description>
                <mdui:Description xml:lang="de">Identity Provider des Max Rubner-Instituts</mdui:Description>
		<mdui:Logo height="16" width="16">https://idp2.maxrubner.de/idp/images/favicon.ico</mdui:Logo>
		<mdui:Logo height="80" width="80">https://idp2.maxrubner.de/idp/images/mri_logo.png</mdui:Logo>
            </mdui:UIInfo>
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIIhzCCBm+gAwIBAgIQbbD3wS7cizDqf1ex35cGNDANBgkqhkiG9w0BAQwFADBE
MQswCQYDVQQGEwJOTDEZMBcGA1UEChMQR0VBTlQgVmVyZW5pZ2luZzEaMBgGA1UE
AxMRR0VBTlQgT1YgUlNBIENBIDQwHhcNMjMwNzA1MDAwMDAwWhcNMjQwNzA0MjM1
OTU5WjCBkTELMAkGA1UEBhMCREUxGzAZBgNVBAgMEkJhZGVuLVfDvHJ0dGVtYmVy
ZzFJMEcGA1UEChNATWF4IFJ1Ym5lci1JbnN0aXR1dCwgQnVuZGVzZm9yc2NoLi1J
bnN0LiBmLiBFcm4uIHUuIExlYmVuc21pdHRlbDEaMBgGA1UEAxMRaWRwMi5tYXhy
dWJuZXIuZGUwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDlMHTKgeR9
ddjJXf1u9Ga47FE4X5oTrYLIg8wHL2bSyFuPsJ51WhydqBrZdDx7Lp+lXDC3Xwqi
ncWW/uuzRBZmKOWEUydxrGl6j7ZuEY+3ZFnsc7+7AlqduKoc3mO6oZ6creB892WY
G6RebNsIZTFqVzoFQHrfLg+tXFJBN8yy8cNI84/qMvkfmT5K/P0xS8NMqBdgS7rq
6Nm4SyLgzf/+BSm+fwbNkCaddQJxjqqhZuTX8GYfWx6vC0qE/n6aK2rZr7c4i4vv
yA1A6sh4gn/ErHHEu5+8OGesXEHf654JbnFCHLYDbQI1HO3nXVGUdZF0JaWHHrs0
IiawFEmY1DUSnK5zf8m/BgdUaTFZNFtBQygUA/SGdnK74n8Gx39UKtxQcA9/h+38
ijx4/a/VGPGfqjG6sDtHIhVqFXqVqlJo4mPCr0wSMuelVJz0cDS2x/GlFPQ2boBA
/stwMzDtx5Ff/rh0xRYzH3cZP6AD2J7Pf326pFsgdwGOm7ACwtlEg3cG+TU7QNEh
yB8+dPu1Au75WQIEJ4+aKpMdSmmGh+Ki8a5MihB8qJV+uJ+1PukfB3cbshgqMqk6
k8mhUYPFXnBuDu8jLpBIbodh/ih9M5l+qt0FZzGZ0P2G30uia1k7J1gpsYDzIzPO
veuCfIquzLSimxScg80n4sm0p1LBh1nfAwIDAQABo4IDJTCCAyEwHwYDVR0jBBgw
FoAUbx01SRBsMvpZoJ68iugflb5xegwwHQYDVR0OBBYEFOsrgmVCwZ61vR0nV32u
9XmWMDdnMA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMB0GA1UdJQQWMBQG
CCsGAQUFBwMBBggrBgEFBQcDAjBJBgNVHSAEQjBAMDQGCysGAQQBsjEBAgJPMCUw
IwYIKwYBBQUHAgEWF2h0dHBzOi8vc2VjdGlnby5jb20vQ1BTMAgGBmeBDAECAjA/
BgNVHR8EODA2MDSgMqAwhi5odHRwOi8vR0VBTlQuY3JsLnNlY3RpZ28uY29tL0dF
QU5UT1ZSU0FDQTQuY3JsMHUGCCsGAQUFBwEBBGkwZzA6BggrBgEFBQcwAoYuaHR0
cDovL0dFQU5ULmNydC5zZWN0aWdvLmNvbS9HRUFOVE9WUlNBQ0E0LmNydDApBggr
BgEFBQcwAYYdaHR0cDovL0dFQU5ULm9jc3Auc2VjdGlnby5jb20wggF/BgorBgEE
AdZ5AgQCBIIBbwSCAWsBaQB3AHb/iD8KtvuVUcJhzPWHujS0pM27KdxoQgqf5mdM
Wjp0AAABiSXlgiEAAAQDAEgwRgIhANgOzJn1e6NMnbshMAf2+43aCnx1voips4m4
TrvjBOfmAiEAvCGEcxoMCM8PrdKMa5rMwDi7VegwKSbEX4mQnexvqBMAdgDatr9r
P7W2Ip+bwrtca+hwkXFsu1GEhTS9pD0wSNf7qwAAAYkl5YJ8AAAEAwBHMEUCIFRP
d1VQXUK+pg6lMIU6tA38rgPAV4l7xB49pa5El9URAiEAlgp7bo9yv3WXzyikiryR
zFo4U7ChmyhqyCTRg5aArAkAdgDuzdBk1dsazsVct520zROiModGfLzs3sNRSFlG
cR+1mwAAAYkl5YJOAAAEAwBHMEUCIQCeCJnKYFBrriXYsLN4RLGTVygl1wrsZP++
6rReksHccQIgdPM47y2Ymbl6+ncnJWWwKW3WRSBDbWTnlHZWAOsSD3AwHAYDVR0R
BBUwE4IRaWRwMi5tYXhydWJuZXIuZGUwDQYJKoZIhvcNAQEMBQADggIBAFT3w/91
wlmzdvyQ3HyubZOWt8If/hVp4GP9zd8e5BHKrs/kMdrTeuSOeTyj5pZNL5GYLOWj
qkmD5OwAVq2BpWcG+7644t30E197OKGcvb6j3DEHCUOl6esmOmuvceDfVdapSaTJ
XhLnrOaxSoZK1HfdBDF4aZKKFS6sAa/dS4iWsm+sanTiZabSYyYfCKKQlihptThZ
qpep6+k/842mcYloUe/hdEiBVKp8uxKQeEUBZpDQzuPjKfqW92q7ewnK92H9K3gK
6dyh+JE6U3evcBqX5EYQWvICXGrfwL+pVzLqWStqKViahAfl0yvYXK8B5WTGVlSE
wEwi1w3COkIXtwXxm09nBs6QrWQhEQZpbOVEK+gLQ+cNUvhfx9OcA8w28z7HDdBw
Bm0mEeOQxVkpRafg2AVX8/tzI7l24xFSDghyssNqpGvMzBHpbgNgU5S9NcrZqqLN
5Abe0+JMDIKy67uCkNxuBpr9qC+L6zfltM9CNaWissXbJbeFhSES+savpGr4yxH9
Iovc8aGbHDKjoBVdv959N32YNT+q/uEnUFgCmR9inMV6TmGa9SWHhHQCC4aWv4Kt
j0IyNM1xaBduvkhgDFUdibU/gGH8o+cqjdBjXDvkJxVG+ZcwpVTR/TkSAx+eaTEn
zkz8KhTq9pF53i8dNM+upaYqNqtS3CWUycWT
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp2.maxrubner.de:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp2.maxrubner.de:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>

        <!-- vier Single-Logout-Services aktivieren -->
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp2.maxrubner.de/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp2.maxrubner.de/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp2.maxrubner.de/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp2.maxrubner.de:8443/idp/profile/SAML2/SOAP/SLO"/>
        

        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp2.maxrubner.de/idp/profile/Shibboleth/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://idp2.maxrubner.de/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://idp2.maxrubner.de/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://idp2.maxrubner.de/idp/profile/SAML2/Redirect/SSO"/>
	<!-- den fehlenden ECP-Endpoint hinzufügen -->
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp2.maxrubner.de/idp/profile/SAML2/SOAP/ECP"/>


	<!-- die fehlenden NameID-Formate hinzufügen -->
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>

    </IDPSSODescriptor>

    <!-- Protocol-Support für SAML2-Queries im AA-Descriptor aktivieren -->	
    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">maxrubner.de</shibmd:Scope>
	    <shibmd:Scope regexp="false">mri.bund.de</shibmd:Scope>
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIIhzCCBm+gAwIBAgIQbbD3wS7cizDqf1ex35cGNDANBgkqhkiG9w0BAQwFADBE
MQswCQYDVQQGEwJOTDEZMBcGA1UEChMQR0VBTlQgVmVyZW5pZ2luZzEaMBgGA1UE
AxMRR0VBTlQgT1YgUlNBIENBIDQwHhcNMjMwNzA1MDAwMDAwWhcNMjQwNzA0MjM1
OTU5WjCBkTELMAkGA1UEBhMCREUxGzAZBgNVBAgMEkJhZGVuLVfDvHJ0dGVtYmVy
ZzFJMEcGA1UEChNATWF4IFJ1Ym5lci1JbnN0aXR1dCwgQnVuZGVzZm9yc2NoLi1J
bnN0LiBmLiBFcm4uIHUuIExlYmVuc21pdHRlbDEaMBgGA1UEAxMRaWRwMi5tYXhy
dWJuZXIuZGUwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDlMHTKgeR9
ddjJXf1u9Ga47FE4X5oTrYLIg8wHL2bSyFuPsJ51WhydqBrZdDx7Lp+lXDC3Xwqi
ncWW/uuzRBZmKOWEUydxrGl6j7ZuEY+3ZFnsc7+7AlqduKoc3mO6oZ6creB892WY
G6RebNsIZTFqVzoFQHrfLg+tXFJBN8yy8cNI84/qMvkfmT5K/P0xS8NMqBdgS7rq
6Nm4SyLgzf/+BSm+fwbNkCaddQJxjqqhZuTX8GYfWx6vC0qE/n6aK2rZr7c4i4vv
yA1A6sh4gn/ErHHEu5+8OGesXEHf654JbnFCHLYDbQI1HO3nXVGUdZF0JaWHHrs0
IiawFEmY1DUSnK5zf8m/BgdUaTFZNFtBQygUA/SGdnK74n8Gx39UKtxQcA9/h+38
ijx4/a/VGPGfqjG6sDtHIhVqFXqVqlJo4mPCr0wSMuelVJz0cDS2x/GlFPQ2boBA
/stwMzDtx5Ff/rh0xRYzH3cZP6AD2J7Pf326pFsgdwGOm7ACwtlEg3cG+TU7QNEh
yB8+dPu1Au75WQIEJ4+aKpMdSmmGh+Ki8a5MihB8qJV+uJ+1PukfB3cbshgqMqk6
k8mhUYPFXnBuDu8jLpBIbodh/ih9M5l+qt0FZzGZ0P2G30uia1k7J1gpsYDzIzPO
veuCfIquzLSimxScg80n4sm0p1LBh1nfAwIDAQABo4IDJTCCAyEwHwYDVR0jBBgw
FoAUbx01SRBsMvpZoJ68iugflb5xegwwHQYDVR0OBBYEFOsrgmVCwZ61vR0nV32u
9XmWMDdnMA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMB0GA1UdJQQWMBQG
CCsGAQUFBwMBBggrBgEFBQcDAjBJBgNVHSAEQjBAMDQGCysGAQQBsjEBAgJPMCUw
IwYIKwYBBQUHAgEWF2h0dHBzOi8vc2VjdGlnby5jb20vQ1BTMAgGBmeBDAECAjA/
BgNVHR8EODA2MDSgMqAwhi5odHRwOi8vR0VBTlQuY3JsLnNlY3RpZ28uY29tL0dF
QU5UT1ZSU0FDQTQuY3JsMHUGCCsGAQUFBwEBBGkwZzA6BggrBgEFBQcwAoYuaHR0
cDovL0dFQU5ULmNydC5zZWN0aWdvLmNvbS9HRUFOVE9WUlNBQ0E0LmNydDApBggr
BgEFBQcwAYYdaHR0cDovL0dFQU5ULm9jc3Auc2VjdGlnby5jb20wggF/BgorBgEE
AdZ5AgQCBIIBbwSCAWsBaQB3AHb/iD8KtvuVUcJhzPWHujS0pM27KdxoQgqf5mdM
Wjp0AAABiSXlgiEAAAQDAEgwRgIhANgOzJn1e6NMnbshMAf2+43aCnx1voips4m4
TrvjBOfmAiEAvCGEcxoMCM8PrdKMa5rMwDi7VegwKSbEX4mQnexvqBMAdgDatr9r
P7W2Ip+bwrtca+hwkXFsu1GEhTS9pD0wSNf7qwAAAYkl5YJ8AAAEAwBHMEUCIFRP
d1VQXUK+pg6lMIU6tA38rgPAV4l7xB49pa5El9URAiEAlgp7bo9yv3WXzyikiryR
zFo4U7ChmyhqyCTRg5aArAkAdgDuzdBk1dsazsVct520zROiModGfLzs3sNRSFlG
cR+1mwAAAYkl5YJOAAAEAwBHMEUCIQCeCJnKYFBrriXYsLN4RLGTVygl1wrsZP++
6rReksHccQIgdPM47y2Ymbl6+ncnJWWwKW3WRSBDbWTnlHZWAOsSD3AwHAYDVR0R
BBUwE4IRaWRwMi5tYXhydWJuZXIuZGUwDQYJKoZIhvcNAQEMBQADggIBAFT3w/91
wlmzdvyQ3HyubZOWt8If/hVp4GP9zd8e5BHKrs/kMdrTeuSOeTyj5pZNL5GYLOWj
qkmD5OwAVq2BpWcG+7644t30E197OKGcvb6j3DEHCUOl6esmOmuvceDfVdapSaTJ
XhLnrOaxSoZK1HfdBDF4aZKKFS6sAa/dS4iWsm+sanTiZabSYyYfCKKQlihptThZ
qpep6+k/842mcYloUe/hdEiBVKp8uxKQeEUBZpDQzuPjKfqW92q7ewnK92H9K3gK
6dyh+JE6U3evcBqX5EYQWvICXGrfwL+pVzLqWStqKViahAfl0yvYXK8B5WTGVlSE
wEwi1w3COkIXtwXxm09nBs6QrWQhEQZpbOVEK+gLQ+cNUvhfx9OcA8w28z7HDdBw
Bm0mEeOQxVkpRafg2AVX8/tzI7l24xFSDghyssNqpGvMzBHpbgNgU5S9NcrZqqLN
5Abe0+JMDIKy67uCkNxuBpr9qC+L6zfltM9CNaWissXbJbeFhSES+savpGr4yxH9
Iovc8aGbHDKjoBVdv959N32YNT+q/uEnUFgCmR9inMV6TmGa9SWHhHQCC4aWv4Kt
j0IyNM1xaBduvkhgDFUdibU/gGH8o+cqjdBjXDvkJxVG+ZcwpVTR/TkSAx+eaTEn
zkz8KhTq9pF53i8dNM+upaYqNqtS3CWUycWT
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp2.maxrubner.de:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
        <!-- SAML2-Attribute-Service aktivieren -->
	<AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp2.maxrubner.de:8443/idp/profile/SAML2/SOAP/AttributeQuery"/>
        <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->

	<!-- die fehlenden NameID-Formate hinzufügen -->
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>

    </AttributeAuthorityDescriptor>

</EntityDescriptor>
