<EntityDescriptor entityID="https://shibidp.amherst.edu/idp/shibboleth"
                  xmlns="urn:oasis:names:tc:SAML:2.0:metadata"
                  xmlns:ds="http://www.w3.org/2000/09/xmldsig#"
                  xmlns:shibmd="urn:mace:shibboleth:metadata:1.0"
                  xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">

    <IDPSSODescriptor protocolSupportEnumeration="urn:mace:shibboleth:1.0 urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol" errorURL="https://www.amherst.edu/offices/it/services/help/help-desk">

        <Extensions>
            <shibmd:Scope regexp="false">amherst.edu</shibmd:Scope>
            <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
              <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
                    NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"
                    Name="urn:oasis:names:tc:SAML:attribute:assurance-certification">
                <saml:AttributeValue>https://refeds.org/sirtfi</saml:AttributeValue>
              </saml:Attribute>
            </mdattr:EntityAttributes>
        </Extensions>

        <KeyDescriptor>
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
MIIDODCCAiCgAwIBAgIVAKMvGP/vH0uzAwPfsNR+8twMxr8nMA0GCSqGSIb3DQEB
BQUAMB4xHDAaBgNVBAMTE3NoaWJpZHAuYW1oZXJzdC5lZHUwHhcNMTAwMzI5MTc0
MDIzWhcNMzAwMzI5MTc0MDIzWjAeMRwwGgYDVQQDExNzaGliaWRwLmFtaGVyc3Qu
ZWR1MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkNJ1nVz/FM/CchMM
NfgW4ROHyNf3K15dT4LB1x+GVivrpYuvOHAY4eyhwoBfkm0t5NM19EHpsdFIVePO
Cm80WYFwCpR1lCPcN/3/JelfCTKKcjKJM6RCHUiM7e0JUlTTV/f0PEdiDrNn01wM
9kknwkAxkXCyN4TNKT/KTMhYNwxhCqTa4QVDThJMQWXJkIbOA7pJbgmVmCfdcJub
4E8C9gtgPTWnQPXtXxRtfH2YYd8fRwPIIx6ASW9VThOSk+FNmcbEGLpxFSRjnfMO
+SPdVahROAhP6IAgASEBzjgp9qb4deqLjIpk1hIQhHkoKZELlUq5lezaraxOemJI
KFoG4wIDAQABo20wazBKBgNVHREEQzBBghNzaGliaWRwLmFtaGVyc3QuZWR1hipo
dHRwczovL3NoaWJpZHAuYW1oZXJzdC5lZHUvaWRwL3NoaWJib2xldGgwHQYDVR0O
BBYEFMj2O62lcU/Ny7iWyJ/vDyYkzMJOMA0GCSqGSIb3DQEBBQUAA4IBAQAkppMI
tdfWe60+4ipCZ+aT/Fg30auva3YgKZsWEsTRcJ8cMLcst27AvswP16DtKp+eksN1
Pgq+CEj6ahY1O4Rtic8hKwBsyHlMY47VdjZK2lvWBA3Dh81636jmOePQVRFqIAfQ
EpKiUdqXNpwy61ODSFRJ/XEyod2tN+J2f5Rq2Cej6VWSNZ5FatuemjZMlxEXNi5s
gl7fU1fEoCtBURaLf/tkzMKykipuzzSpZVS3uq8slt2jVsQlddIXR60pkGyQgr6/
Is8EDBRpRFjVojjmYbLxcdbgEVA3CteakwkNe5Gb4gJuhFiq6nGhxFOron13TF69
fuOjmWpbYZwDGqld

                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
        
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
                                   Location="https://shibidp.amherst.edu:8443/idp/profile/SAML1/SOAP/ArtifactResolution" 
                                   index="1"/>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"
                                   Location="https://shibidp.amherst.edu:8443/idp/profile/SAML2/SOAP/ArtifactResolution" 
                                   index="2"/>
                                   
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>

        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" 
                             Location="https://shibidp.amherst.edu/idp/profile/Shibboleth/SSO" />
        
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" 
                             Location="https://shibidp.amherst.edu/idp/profile/SAML2/POST/SSO" />

        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" 
                             Location="https://shibidp.amherst.edu/idp/profile/SAML2/POST-SimpleSign/SSO" />
        
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" 
                             Location="https://shibidp.amherst.edu/idp/profile/SAML2/Redirect/SSO" />
    </IDPSSODescriptor>

    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">amherst.edu</shibmd:Scope>
        </Extensions>

        <KeyDescriptor>
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
MIIDODCCAiCgAwIBAgIVAKMvGP/vH0uzAwPfsNR+8twMxr8nMA0GCSqGSIb3DQEB
BQUAMB4xHDAaBgNVBAMTE3NoaWJpZHAuYW1oZXJzdC5lZHUwHhcNMTAwMzI5MTc0
MDIzWhcNMzAwMzI5MTc0MDIzWjAeMRwwGgYDVQQDExNzaGliaWRwLmFtaGVyc3Qu
ZWR1MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkNJ1nVz/FM/CchMM
NfgW4ROHyNf3K15dT4LB1x+GVivrpYuvOHAY4eyhwoBfkm0t5NM19EHpsdFIVePO
Cm80WYFwCpR1lCPcN/3/JelfCTKKcjKJM6RCHUiM7e0JUlTTV/f0PEdiDrNn01wM
9kknwkAxkXCyN4TNKT/KTMhYNwxhCqTa4QVDThJMQWXJkIbOA7pJbgmVmCfdcJub
4E8C9gtgPTWnQPXtXxRtfH2YYd8fRwPIIx6ASW9VThOSk+FNmcbEGLpxFSRjnfMO
+SPdVahROAhP6IAgASEBzjgp9qb4deqLjIpk1hIQhHkoKZELlUq5lezaraxOemJI
KFoG4wIDAQABo20wazBKBgNVHREEQzBBghNzaGliaWRwLmFtaGVyc3QuZWR1hipo
dHRwczovL3NoaWJpZHAuYW1oZXJzdC5lZHUvaWRwL3NoaWJib2xldGgwHQYDVR0O
BBYEFMj2O62lcU/Ny7iWyJ/vDyYkzMJOMA0GCSqGSIb3DQEBBQUAA4IBAQAkppMI
tdfWe60+4ipCZ+aT/Fg30auva3YgKZsWEsTRcJ8cMLcst27AvswP16DtKp+eksN1
Pgq+CEj6ahY1O4Rtic8hKwBsyHlMY47VdjZK2lvWBA3Dh81636jmOePQVRFqIAfQ
EpKiUdqXNpwy61ODSFRJ/XEyod2tN+J2f5Rq2Cej6VWSNZ5FatuemjZMlxEXNi5s
gl7fU1fEoCtBURaLf/tkzMKykipuzzSpZVS3uq8slt2jVsQlddIXR60pkGyQgr6/
Is8EDBRpRFjVojjmYbLxcdbgEVA3CteakwkNe5Gb4gJuhFiq6nGhxFOron13TF69
fuOjmWpbYZwDGqld

                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" 
                          Location="https://shibidp.amherst.edu:8443/idp/profile/SAML1/SOAP/AttributeQuery" />
        
        <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"
                          Location="https://shibidp.amherst.edu:8443/idp/profile/SAML2/SOAP/AttributeQuery" />
        
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
        
    </AttributeAuthorityDescriptor>

       <Organization>
                <OrganizationName xml:lang="en">Amherst College</OrganizationName>
                <OrganizationDisplayName xml:lang="en">Amherst College</OrganizationDisplayName>
                <OrganizationURL xml:lang="en">https://www.amherst.edu/</OrganizationURL>
        </Organization>
        <ContactPerson contactType="technical">
                <GivenName>Amherst</GivenName>
                <SurName>College</SurName>
                <EmailAddress>idm-l@amherst.edu</EmailAddress>
        </ContactPerson>

        <ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security">
          <GivenName>Brian</GivenName>
          <SurName>Holley</SurName>
          <EmailAddress>bholley@amherst.edu</EmailAddress>
        </ContactPerson>
</EntityDescriptor>    
