<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" entityID="https://idp.cuhk.edu.hk/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">cuhk.edu.hk</shibmd:Scope>
<!--
    Fill in the details for your IdP here 

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">A Name for the IdP at idp.cuhk.edu.hk</mdui:DisplayName>
                <mdui:Description xml:lang="en">Enter a description of your IdP at idp.cuhk.edu.hk</mdui:Description>
                <mdui:Logo height="80" width="80">https://idp.cuhk.edu.hk/Path/To/Logo.png</mdui:Logo>
            </mdui:UIInfo>
-->
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDKDCCAhCgAwIBAgIVAPaRgyNcEkMUWodOlAqR3aU7b7X+MA0GCSqGSIb3DQEB
CwUAMBoxGDAWBgNVBAMMD2lkcC5jdWhrLmVkdS5oazAeFw0xNjEyMDkwOTU0NDRa
Fw0zNjEyMDkwOTU0NDRaMBoxGDAWBgNVBAMMD2lkcC5jdWhrLmVkdS5oazCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJFv4BmzoREiHxx6QjA3FLJnEV5B
JmostuwgwZlIgLt/d07QyH1s312sOXZZz3g4dcOUKPN3+V+o1iAmYcRSBzfT8gKy
DoTvpMGwJEomtFpp1rtdUe0WpwKn6xqvWEGdMTiViXqKNI79onIS/PzOwH02pqMI
E4si1OCxYQo7dx/Gb/S/t+NVnkQn/S4Tw/4si2hDi3emDPzIsAerwKZ9Q8R5+iYx
8Ots4EvP2q37hmStGBCPiyJbmwiDjIIvU256iMfyEiSvVmKDOVTNWTTJpgLzu8hN
NNEtMCAyGBYgwnvzYXsybGnuSHvN8bK3TtvJG37nbMJ5fk8DaDEgJnIvn9kCAwEA
AaNlMGMwHQYDVR0OBBYEFEw6hmn27S6ABuf0feMhjB3UpFElMEIGA1UdEQQ7MDmC
D2lkcC5jdWhrLmVkdS5oa4YmaHR0cHM6Ly9pZHAuY3Voay5lZHUuaGsvaWRwL3No
aWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBADqoxMHeGeIanlGZRFUsNcjk0+VT
CsfUI3FZp9ur883OnCamIhOgkLztxK7PJnIm+wbo8vzklyJ5GUaiJ4NYbOXVqpnJ
4j7VV+3UtXfPVoGIdRw0wRv3L1au+SrZMWeGWu85HfLuSDuOjhv8mjo16sVlxIMv
cXw9+6jC/QTG99zuYZj2rxxEnrLT4leNVO5kwFdixyJjnCf2tDALzIX2E+mNsY4u
TYIikUt2yprQQY5BaXj6bvrrsEKDNi9e44XsQy21uXwexD5fuiGoVoOtA7CV2znh
C1RSOe0yUxPL2WSbsg4imkd2mTNaUXTUMU6EOjPuhkR0J7gL5GyQdBJ9TwI=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDKDCCAhCgAwIBAgIVAOrXIHnafLADfxipNmhQGVQg/rOVMA0GCSqGSIb3DQEB
CwUAMBoxGDAWBgNVBAMMD2lkcC5jdWhrLmVkdS5oazAeFw0xNjEyMDkwOTU0NDJa
Fw0zNjEyMDkwOTU0NDJaMBoxGDAWBgNVBAMMD2lkcC5jdWhrLmVkdS5oazCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI7ErBPIQ2vKDO79us1lvnfVvmDu
XdtIKvGDZd5+nzio8QaWih6866cA5daGj130G4+Fa401O360NoY8tCXiQSdNIkAM
S/1sF7rfh6B+J2cYqfuJpuVOZZAeBdQFGSDyYOtXiAwY37TuP+VTVqe4f/m4GNLu
UO6ORjaq7Xn8qKfCmx9amCyum8w2gaTNhO/9G4p4L5kLHLo4uT0KqlxQd7d9l92y
d2SE1vnb19VKeC4Lmax5X+oEPqMgejaAwIE++daSrsM8CIXhPVQI76ZB3wjNN34G
aTzoAEtZdfRpMoyb5Teokgwglt/HQQ3P+olBWMG3vDUmZ7ohz1YIXaSrsqkCAwEA
AaNlMGMwHQYDVR0OBBYEFAnJe1IW9vbwIJ6Kgk6rL5lFVLAgMEIGA1UdEQQ7MDmC
D2lkcC5jdWhrLmVkdS5oa4YmaHR0cHM6Ly9pZHAuY3Voay5lZHUuaGsvaWRwL3No
aWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBADLZl77CDDQ8uQhPgN9c9B3hjZDS
yoXuIq5YHIOaEGl03/Ak0AqSGgydApc8Fmv0Q2TvrWTq50/MVvpjm+xmqe/34tO7
950r1dweW1ZsrsOClGsROyjg04z/dajRJSI3bsuvulZc5WgpSk7IuZ3TmtIt696n
fhmKSEzfTwdmSedAYPnFVhYSLgoyUVXraD0fCSEqi9E2W7XKuL/CDCY7stKm9bbz
mPy0GP3sCFKtsq9JccGqIOtF0qAHrNrcOjUxh73a1uaO4eNYtO3Wd5/sE/kPYojZ
HPuf+xZeDwAfslBD1E+u2O17PTp5jL2VkLrO60+MSBR3oo+oQVO1rmyFGq4=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDKDCCAhCgAwIBAgIVAJ2vQvwZJqRbm8O5AItqJFTY8BI2MA0GCSqGSIb3DQEB
CwUAMBoxGDAWBgNVBAMMD2lkcC5jdWhrLmVkdS5oazAeFw0xNjEyMDkwOTU0NDNa
Fw0zNjEyMDkwOTU0NDNaMBoxGDAWBgNVBAMMD2lkcC5jdWhrLmVkdS5oazCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJjLZ+kHe8pmn7F2j2WWnD/mBHFG
x+/+Pv+hmV2qQXSCfmreuMNisupJZ9AjomyF2CpUkI7bOwg8T4qEQB89O6Rp/nx3
RKHg+VTsEgWigMxb8NlesLOnr0nL9Wd0zyJhr7oKKSPzWN5PQjpU7zqM75JtrtML
RDIZ+tyr8eOgRiATNtwFBKkVSxRmiEpQET4X0g4Oy/UuFDI3T4sIkPZ4iK1iGou8
1T9mQ2MQAISuNVXi0wV6HJKjbKjSbHtSaT1I19zZ6NXAKa7sI95SlIrOTsyLuS5X
UZl5zd4EGT4am+dVveog04kywk2DkwUYqVSGmG379uAZ2eMTqnLztDupheMCAwEA
AaNlMGMwHQYDVR0OBBYEFFrBoe/0pNOajUiXyzOIKf8PHEc3MEIGA1UdEQQ7MDmC
D2lkcC5jdWhrLmVkdS5oa4YmaHR0cHM6Ly9pZHAuY3Voay5lZHUuaGsvaWRwL3No
aWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBAHecllYNw/chaKQGb3TjZQwGodJm
5iLxRE5Ynu/yTyBdT2AUx2Ir/E61CM9m4FIJR1K48+Pb/o2kbgmaLZ+KYMN/vKwJ
u+soxYToDCgQpj9Q7w5hZYdjzoH3AJpO2eDXPk4FGo22BBSJlpL4z4sajmIBMmgw
9tF+Rvl9WKXO8+ulL6UjEMhVK1CeietPRJDcHYsZ6Pm1xBF5RVM4sD2dGZahbFOY
LdvMbhYK/osbUiKHmg8yO733dp8DgDjpS9qysFGXNkORlKPKmp8A9ADv5XDWb1IE
sFdWaPYRMFngf9RxL7HzyoLR1JJmacf92QS1+mZyTDDD2gyh8e8y2jW8JHQ=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.cuhk.edu.hk:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.cuhk.edu.hk:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>

        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.cuhk.edu.hk/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.cuhk.edu.hk/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.cuhk.edu.hk/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.cuhk.edu.hk:8443/idp/profile/SAML2/SOAP/SLO"/>

        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.cuhk.edu.hk/idp/profile/Shibboleth/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.cuhk.edu.hk/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.cuhk.edu.hk/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.cuhk.edu.hk/idp/profile/SAML2/Redirect/SSO"/>

    </IDPSSODescriptor>


    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">cuhk.edu.hk</shibmd:Scope>
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDKDCCAhCgAwIBAgIVAPaRgyNcEkMUWodOlAqR3aU7b7X+MA0GCSqGSIb3DQEB
CwUAMBoxGDAWBgNVBAMMD2lkcC5jdWhrLmVkdS5oazAeFw0xNjEyMDkwOTU0NDRa
Fw0zNjEyMDkwOTU0NDRaMBoxGDAWBgNVBAMMD2lkcC5jdWhrLmVkdS5oazCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJFv4BmzoREiHxx6QjA3FLJnEV5B
JmostuwgwZlIgLt/d07QyH1s312sOXZZz3g4dcOUKPN3+V+o1iAmYcRSBzfT8gKy
DoTvpMGwJEomtFpp1rtdUe0WpwKn6xqvWEGdMTiViXqKNI79onIS/PzOwH02pqMI
E4si1OCxYQo7dx/Gb/S/t+NVnkQn/S4Tw/4si2hDi3emDPzIsAerwKZ9Q8R5+iYx
8Ots4EvP2q37hmStGBCPiyJbmwiDjIIvU256iMfyEiSvVmKDOVTNWTTJpgLzu8hN
NNEtMCAyGBYgwnvzYXsybGnuSHvN8bK3TtvJG37nbMJ5fk8DaDEgJnIvn9kCAwEA
AaNlMGMwHQYDVR0OBBYEFEw6hmn27S6ABuf0feMhjB3UpFElMEIGA1UdEQQ7MDmC
D2lkcC5jdWhrLmVkdS5oa4YmaHR0cHM6Ly9pZHAuY3Voay5lZHUuaGsvaWRwL3No
aWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBADqoxMHeGeIanlGZRFUsNcjk0+VT
CsfUI3FZp9ur883OnCamIhOgkLztxK7PJnIm+wbo8vzklyJ5GUaiJ4NYbOXVqpnJ
4j7VV+3UtXfPVoGIdRw0wRv3L1au+SrZMWeGWu85HfLuSDuOjhv8mjo16sVlxIMv
cXw9+6jC/QTG99zuYZj2rxxEnrLT4leNVO5kwFdixyJjnCf2tDALzIX2E+mNsY4u
TYIikUt2yprQQY5BaXj6bvrrsEKDNi9e44XsQy21uXwexD5fuiGoVoOtA7CV2znh
C1RSOe0yUxPL2WSbsg4imkd2mTNaUXTUMU6EOjPuhkR0J7gL5GyQdBJ9TwI=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDKDCCAhCgAwIBAgIVAOrXIHnafLADfxipNmhQGVQg/rOVMA0GCSqGSIb3DQEB
CwUAMBoxGDAWBgNVBAMMD2lkcC5jdWhrLmVkdS5oazAeFw0xNjEyMDkwOTU0NDJa
Fw0zNjEyMDkwOTU0NDJaMBoxGDAWBgNVBAMMD2lkcC5jdWhrLmVkdS5oazCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI7ErBPIQ2vKDO79us1lvnfVvmDu
XdtIKvGDZd5+nzio8QaWih6866cA5daGj130G4+Fa401O360NoY8tCXiQSdNIkAM
S/1sF7rfh6B+J2cYqfuJpuVOZZAeBdQFGSDyYOtXiAwY37TuP+VTVqe4f/m4GNLu
UO6ORjaq7Xn8qKfCmx9amCyum8w2gaTNhO/9G4p4L5kLHLo4uT0KqlxQd7d9l92y
d2SE1vnb19VKeC4Lmax5X+oEPqMgejaAwIE++daSrsM8CIXhPVQI76ZB3wjNN34G
aTzoAEtZdfRpMoyb5Teokgwglt/HQQ3P+olBWMG3vDUmZ7ohz1YIXaSrsqkCAwEA
AaNlMGMwHQYDVR0OBBYEFAnJe1IW9vbwIJ6Kgk6rL5lFVLAgMEIGA1UdEQQ7MDmC
D2lkcC5jdWhrLmVkdS5oa4YmaHR0cHM6Ly9pZHAuY3Voay5lZHUuaGsvaWRwL3No
aWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBADLZl77CDDQ8uQhPgN9c9B3hjZDS
yoXuIq5YHIOaEGl03/Ak0AqSGgydApc8Fmv0Q2TvrWTq50/MVvpjm+xmqe/34tO7
950r1dweW1ZsrsOClGsROyjg04z/dajRJSI3bsuvulZc5WgpSk7IuZ3TmtIt696n
fhmKSEzfTwdmSedAYPnFVhYSLgoyUVXraD0fCSEqi9E2W7XKuL/CDCY7stKm9bbz
mPy0GP3sCFKtsq9JccGqIOtF0qAHrNrcOjUxh73a1uaO4eNYtO3Wd5/sE/kPYojZ
HPuf+xZeDwAfslBD1E+u2O17PTp5jL2VkLrO60+MSBR3oo+oQVO1rmyFGq4=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDKDCCAhCgAwIBAgIVAJ2vQvwZJqRbm8O5AItqJFTY8BI2MA0GCSqGSIb3DQEB
CwUAMBoxGDAWBgNVBAMMD2lkcC5jdWhrLmVkdS5oazAeFw0xNjEyMDkwOTU0NDNa
Fw0zNjEyMDkwOTU0NDNaMBoxGDAWBgNVBAMMD2lkcC5jdWhrLmVkdS5oazCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJjLZ+kHe8pmn7F2j2WWnD/mBHFG
x+/+Pv+hmV2qQXSCfmreuMNisupJZ9AjomyF2CpUkI7bOwg8T4qEQB89O6Rp/nx3
RKHg+VTsEgWigMxb8NlesLOnr0nL9Wd0zyJhr7oKKSPzWN5PQjpU7zqM75JtrtML
RDIZ+tyr8eOgRiATNtwFBKkVSxRmiEpQET4X0g4Oy/UuFDI3T4sIkPZ4iK1iGou8
1T9mQ2MQAISuNVXi0wV6HJKjbKjSbHtSaT1I19zZ6NXAKa7sI95SlIrOTsyLuS5X
UZl5zd4EGT4am+dVveog04kywk2DkwUYqVSGmG379uAZ2eMTqnLztDupheMCAwEA
AaNlMGMwHQYDVR0OBBYEFFrBoe/0pNOajUiXyzOIKf8PHEc3MEIGA1UdEQQ7MDmC
D2lkcC5jdWhrLmVkdS5oa4YmaHR0cHM6Ly9pZHAuY3Voay5lZHUuaGsvaWRwL3No
aWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBAHecllYNw/chaKQGb3TjZQwGodJm
5iLxRE5Ynu/yTyBdT2AUx2Ir/E61CM9m4FIJR1K48+Pb/o2kbgmaLZ+KYMN/vKwJ
u+soxYToDCgQpj9Q7w5hZYdjzoH3AJpO2eDXPk4FGo22BBSJlpL4z4sajmIBMmgw
9tF+Rvl9WKXO8+ulL6UjEMhVK1CeietPRJDcHYsZ6Pm1xBF5RVM4sD2dGZahbFOY
LdvMbhYK/osbUiKHmg8yO733dp8DgDjpS9qysFGXNkORlKPKmp8A9ADv5XDWb1IE
sFdWaPYRMFngf9RxL7HzyoLR1JJmacf92QS1+mZyTDDD2gyh8e8y2jW8JHQ=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.cuhk.edu.hk:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
        <!-- <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.cuhk.edu.hk:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> -->
        <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->

    </AttributeAuthorityDescriptor>

</EntityDescriptor>
