<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" validUntil="2026-10-08T21:40:57.346Z" entityID="https://shib01.vassar.edu/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">vassar.edu</shibmd:Scope>
<!--
    Fill in the details for your IdP here 

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">A Name for the IdP at shib01.vassar.edu</mdui:DisplayName>
                <mdui:Description xml:lang="en">Enter a description of your IdP at shib01.vassar.edu</mdui:Description>
                <mdui:Logo height="80" width="80">https://shib01.vassar.edu/Path/To/Logo.png</mdui:Logo>
            </mdui:UIInfo>
-->
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDLzCCAhegAwIBAgIUSjoOeBfWTUg2UOaPJlXTgri/eRYwDQYJKoZIhvcNAQEL
BQAwHDEaMBgGA1UEAwwRc2hpYjAxLnZhc3Nhci5lZHUwHhcNMjAwNjA4MjE0MDQ5
WhcNNDAwNjA4MjE0MDQ5WjAcMRowGAYDVQQDDBFzaGliMDEudmFzc2FyLmVkdTCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI09+p6BbW/pKiPCzeqdrZqA
k5LBgCzAhNuvKf7Ld8uEc2BYeTLqOG5M+OkCIZRc9GgTZRfLS8nq3kzRhvQC0ryQ
6hl9dDGq0zdwz/Uc4p/wz7Dju4R0WCAud7cAD0cBihSnGS3ZuJgapjbmPYAsowmE
2XIJH8SdniMlLlBCnJHStVE8AN5VNQ58NjE2kexajn+CogjvLqSRZWsZxR8CAhpo
/hnPwkKYXlRptnQT3Ob05Y+cZtgFrncl6qLMONV/mT1DmtDGweti8CeIL1NfJK6R
Qvvl07cYRPumfpb4JAu2GAYMWGugklus/JxYdAFtT69VpmRIi1SwpC+lUCi6ulUC
AwEAAaNpMGcwHQYDVR0OBBYEFO2d82XsrTTZ1+mYcByg5CJiOXfQMEYGA1UdEQQ/
MD2CEXNoaWIwMS52YXNzYXIuZWR1hihodHRwczovL3NoaWIwMS52YXNzYXIuZWR1
L2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQBIoG3Sz87gyHkv9ERu
G3puiVzPvd5d7DgV9OS3fyTWlLfaoZACfYb00qTAWGIvbNuE9JToLVW1ZdamIvpP
pxcim/xRSeGbQaOpkVEqhKKbfCdXXbRBm2qYaCeAq0l8h/2PXfK/bqeRV/BjvO5R
OHpwFsRqQ3FM8A2gWo5YaaLRIQ7qS8nWzYTXW7VBNhIJCuse7LmuUIkJhr+C3j4y
WMlAf7W4uxjxoh1Gx8zMC7Hrf7pjT5YI2bp+4RBOxjht9zkhOH3JQP6yqsD7Ql9Q
HRTeQ0eNxcRlhHgd5+lknRGE/680m1MyoHs92hMfZlEcDsJ4KXaW1JbxWig95VKM
pnV7
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDMDCCAhigAwIBAgIVANjbKVsNc26edpKyqoaRJvb/5TFuMA0GCSqGSIb3DQEB
CwUAMBwxGjAYBgNVBAMMEXNoaWIwMS52YXNzYXIuZWR1MB4XDTIwMDYwODIxNDA0
NFoXDTQwMDYwODIxNDA0NFowHDEaMBgGA1UEAwwRc2hpYjAxLnZhc3Nhci5lZHUw
ggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCsTqm7+r3SfOMwss6yUSpI
vziCGz/PoCkvLzh2be+bz3VOB2rXtrAADVEJ0Ig+7e4ODzGh4iCtq1MVX+aNb9L/
GhKf2p/o4F+UhOtk+7R09ptCzdm7aGpQb4Y8WWTp1xs2uof9i6ykmjnyjc0BqK00
thhgE0vnl1WdDvJQXbWBNR5b4gCnQv8JGlqlnnWp3EXQoVtJl/dZ8RLa6zoRPQAt
eDadUXKiXaIbZL/EtLpdlrKwtPt9V8y6l2C0e30KwkS9rRTveKvq2YY1Vk3Ctaef
bl/dcFwJrEozdYNW4XkLZp8+KFy7UtDoPm7SX4laSMMcCCUljsBOtvlc4+YX5vpn
AgMBAAGjaTBnMB0GA1UdDgQWBBTi4LBqMHCD35CHZrNkTT4L7ryspDBGBgNVHREE
PzA9ghFzaGliMDEudmFzc2FyLmVkdYYoaHR0cHM6Ly9zaGliMDEudmFzc2FyLmVk
dS9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAe/gUocGzn4179QnS
dZlhUGMKHWuDCqi8TEb+3pipUthda4FBGwL4TlYHy1YvlmGfr6vKf/mQxuMr5j18
NwZ6jiHSnDXQmexlRxnfkl1hugJASy0wZDFm+l20PFxVGZ/b5RL/YJqb0Lb9ncrh
KVSBJOE8TqZY35ElLddVHfPz+8meLrqGDmfNw/kpNQ9ZHmRlMhGB8GmdzE+id3Cr
ecN6+PQdEz8V4SSGoieIQ/7EVuCU3x795z53V8ceJ71yli2mRonOF0m0JHjj5eyG
d1ax+C1ognJyhcyMNTR+BQr2AEmORLNgIuHUJjTKOG2E6MljRFjv6AjN3U5yS5An
f6x6dQ==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDMDCCAhigAwIBAgIVAOHDmyWcM2sCo4twP24bRQPXiFpYMA0GCSqGSIb3DQEB
CwUAMBwxGjAYBgNVBAMMEXNoaWIwMS52YXNzYXIuZWR1MB4XDTIwMDYwODIxNDA0
NFoXDTQwMDYwODIxNDA0NFowHDEaMBgGA1UEAwwRc2hpYjAxLnZhc3Nhci5lZHUw
ggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrAPhSrHYiAIbLiJMUBTJQ
0if4N8FH0EsSnn5+hh/DUlS0Rg576aP7FRr+fVKl0ZlUM6k4E/uyR7pTKXeI1ZCL
YEwKcPSOrj9fYNjhJiB+EZrN/wyG/SmfHfca8ko4Q2bwVZMM1mKri0UoiUqLuOxB
eSYv2TQZgj2E6IpclapC7ZF8OnIDp9upvfN2pm3lTwlH/I+D9u2lfILoYnaf1sQi
UEd64qlTDvryBLeBJmTbbcbGC9jNqCt0wGx/rgcowJWDYt7ZW52TiVrOtuQmZtZA
aOOkrfvH2rPvFY7wx7xVLFjqW31/XmZF7F1iuhYnD1Uf3N0p7Dx9MiB84p6jgzI9
AgMBAAGjaTBnMB0GA1UdDgQWBBS/nl0X5Q5gZtmNAvDWHCXsuBLWUDBGBgNVHREE
PzA9ghFzaGliMDEudmFzc2FyLmVkdYYoaHR0cHM6Ly9zaGliMDEudmFzc2FyLmVk
dS9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAUsEyY9BDD8vFWmU/
fo2ZOItjSA2t5fVg/+kSkLEExbj7uY+/UWmxKpWFu8ZYwqpywTjJa0ocMJJ6TdBT
vG2kh7hqYyd9YUsN7flmuAkJ7DIx/AlVE/UgwEvxQyiJPQIpMRDZrp25S+vdCWHH
m5kzQncZjugxV11WFJ2YRa67guM0S46erLFmWhQOptgHH8suyqbBYsz6F1dP5yPI
c+3gVEA8/HJTJW1fBzzo/6WT/dsjDBpeL9c48vleVirFdOG4xTY3IwVBmzt7Zdje
GOqZwqyWTqMwmyXC5W2rE01sMZMRzDHpIij7jsnPHXn8b+dROYfTbogZsKyXCh91
hSzH6A==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://shib01.vassar.edu:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://shib01.vassar.edu:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>

        <!--
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://shib01.vassar.edu/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://shib01.vassar.edu:8443/idp/profile/SAML2/SOAP/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://shib01.vassar.edu/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://shib01.vassar.edu/idp/profile/SAML2/POST/SLO"/>
        -->

        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://shib01.vassar.edu/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://shib01.vassar.edu/idp/profile/SAML2/Redirect/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://shib01.vassar.edu/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://shib01.vassar.edu/idp/profile/Shibboleth/SSO"/>

    </IDPSSODescriptor>


    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">vassar.edu</shibmd:Scope>
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDLzCCAhegAwIBAgIUSjoOeBfWTUg2UOaPJlXTgri/eRYwDQYJKoZIhvcNAQEL
BQAwHDEaMBgGA1UEAwwRc2hpYjAxLnZhc3Nhci5lZHUwHhcNMjAwNjA4MjE0MDQ5
WhcNNDAwNjA4MjE0MDQ5WjAcMRowGAYDVQQDDBFzaGliMDEudmFzc2FyLmVkdTCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAI09+p6BbW/pKiPCzeqdrZqA
k5LBgCzAhNuvKf7Ld8uEc2BYeTLqOG5M+OkCIZRc9GgTZRfLS8nq3kzRhvQC0ryQ
6hl9dDGq0zdwz/Uc4p/wz7Dju4R0WCAud7cAD0cBihSnGS3ZuJgapjbmPYAsowmE
2XIJH8SdniMlLlBCnJHStVE8AN5VNQ58NjE2kexajn+CogjvLqSRZWsZxR8CAhpo
/hnPwkKYXlRptnQT3Ob05Y+cZtgFrncl6qLMONV/mT1DmtDGweti8CeIL1NfJK6R
Qvvl07cYRPumfpb4JAu2GAYMWGugklus/JxYdAFtT69VpmRIi1SwpC+lUCi6ulUC
AwEAAaNpMGcwHQYDVR0OBBYEFO2d82XsrTTZ1+mYcByg5CJiOXfQMEYGA1UdEQQ/
MD2CEXNoaWIwMS52YXNzYXIuZWR1hihodHRwczovL3NoaWIwMS52YXNzYXIuZWR1
L2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQBIoG3Sz87gyHkv9ERu
G3puiVzPvd5d7DgV9OS3fyTWlLfaoZACfYb00qTAWGIvbNuE9JToLVW1ZdamIvpP
pxcim/xRSeGbQaOpkVEqhKKbfCdXXbRBm2qYaCeAq0l8h/2PXfK/bqeRV/BjvO5R
OHpwFsRqQ3FM8A2gWo5YaaLRIQ7qS8nWzYTXW7VBNhIJCuse7LmuUIkJhr+C3j4y
WMlAf7W4uxjxoh1Gx8zMC7Hrf7pjT5YI2bp+4RBOxjht9zkhOH3JQP6yqsD7Ql9Q
HRTeQ0eNxcRlhHgd5+lknRGE/680m1MyoHs92hMfZlEcDsJ4KXaW1JbxWig95VKM
pnV7
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDMDCCAhigAwIBAgIVANjbKVsNc26edpKyqoaRJvb/5TFuMA0GCSqGSIb3DQEB
CwUAMBwxGjAYBgNVBAMMEXNoaWIwMS52YXNzYXIuZWR1MB4XDTIwMDYwODIxNDA0
NFoXDTQwMDYwODIxNDA0NFowHDEaMBgGA1UEAwwRc2hpYjAxLnZhc3Nhci5lZHUw
ggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCsTqm7+r3SfOMwss6yUSpI
vziCGz/PoCkvLzh2be+bz3VOB2rXtrAADVEJ0Ig+7e4ODzGh4iCtq1MVX+aNb9L/
GhKf2p/o4F+UhOtk+7R09ptCzdm7aGpQb4Y8WWTp1xs2uof9i6ykmjnyjc0BqK00
thhgE0vnl1WdDvJQXbWBNR5b4gCnQv8JGlqlnnWp3EXQoVtJl/dZ8RLa6zoRPQAt
eDadUXKiXaIbZL/EtLpdlrKwtPt9V8y6l2C0e30KwkS9rRTveKvq2YY1Vk3Ctaef
bl/dcFwJrEozdYNW4XkLZp8+KFy7UtDoPm7SX4laSMMcCCUljsBOtvlc4+YX5vpn
AgMBAAGjaTBnMB0GA1UdDgQWBBTi4LBqMHCD35CHZrNkTT4L7ryspDBGBgNVHREE
PzA9ghFzaGliMDEudmFzc2FyLmVkdYYoaHR0cHM6Ly9zaGliMDEudmFzc2FyLmVk
dS9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAe/gUocGzn4179QnS
dZlhUGMKHWuDCqi8TEb+3pipUthda4FBGwL4TlYHy1YvlmGfr6vKf/mQxuMr5j18
NwZ6jiHSnDXQmexlRxnfkl1hugJASy0wZDFm+l20PFxVGZ/b5RL/YJqb0Lb9ncrh
KVSBJOE8TqZY35ElLddVHfPz+8meLrqGDmfNw/kpNQ9ZHmRlMhGB8GmdzE+id3Cr
ecN6+PQdEz8V4SSGoieIQ/7EVuCU3x795z53V8ceJ71yli2mRonOF0m0JHjj5eyG
d1ax+C1ognJyhcyMNTR+BQr2AEmORLNgIuHUJjTKOG2E6MljRFjv6AjN3U5yS5An
f6x6dQ==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDMDCCAhigAwIBAgIVAOHDmyWcM2sCo4twP24bRQPXiFpYMA0GCSqGSIb3DQEB
CwUAMBwxGjAYBgNVBAMMEXNoaWIwMS52YXNzYXIuZWR1MB4XDTIwMDYwODIxNDA0
NFoXDTQwMDYwODIxNDA0NFowHDEaMBgGA1UEAwwRc2hpYjAxLnZhc3Nhci5lZHUw
ggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrAPhSrHYiAIbLiJMUBTJQ
0if4N8FH0EsSnn5+hh/DUlS0Rg576aP7FRr+fVKl0ZlUM6k4E/uyR7pTKXeI1ZCL
YEwKcPSOrj9fYNjhJiB+EZrN/wyG/SmfHfca8ko4Q2bwVZMM1mKri0UoiUqLuOxB
eSYv2TQZgj2E6IpclapC7ZF8OnIDp9upvfN2pm3lTwlH/I+D9u2lfILoYnaf1sQi
UEd64qlTDvryBLeBJmTbbcbGC9jNqCt0wGx/rgcowJWDYt7ZW52TiVrOtuQmZtZA
aOOkrfvH2rPvFY7wx7xVLFjqW31/XmZF7F1iuhYnD1Uf3N0p7Dx9MiB84p6jgzI9
AgMBAAGjaTBnMB0GA1UdDgQWBBS/nl0X5Q5gZtmNAvDWHCXsuBLWUDBGBgNVHREE
PzA9ghFzaGliMDEudmFzc2FyLmVkdYYoaHR0cHM6Ly9zaGliMDEudmFzc2FyLmVk
dS9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAUsEyY9BDD8vFWmU/
fo2ZOItjSA2t5fVg/+kSkLEExbj7uY+/UWmxKpWFu8ZYwqpywTjJa0ocMJJ6TdBT
vG2kh7hqYyd9YUsN7flmuAkJ7DIx/AlVE/UgwEvxQyiJPQIpMRDZrp25S+vdCWHH
m5kzQncZjugxV11WFJ2YRa67guM0S46erLFmWhQOptgHH8suyqbBYsz6F1dP5yPI
c+3gVEA8/HJTJW1fBzzo/6WT/dsjDBpeL9c48vleVirFdOG4xTY3IwVBmzt7Zdje
GOqZwqyWTqMwmyXC5W2rE01sMZMRzDHpIij7jsnPHXn8b+dROYfTbogZsKyXCh91
hSzH6A==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://shib01.vassar.edu:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
        <!-- <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://shib01.vassar.edu:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> -->
        <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->

    </AttributeAuthorityDescriptor>

</EntityDescriptor>
