<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.
--> 
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" validUntil="2021-07-23T17:26:38.233Z" entityID="https://idp.canarie.ca/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">canarie.ca</shibmd:Scope>
<!--
    Fill in the details for your IdP here 

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">A Name for the IdP at idp.canarie.ca</mdui:DisplayName>
                <mdui:Description xml:lang="en">Enter a description of your IdP at idp.canarie.ca</mdui:Description>
                <mdui:Logo height="80" width="80">https://idp.canarie.ca/Path/To/Logo.png</mdui:Logo>
            </mdui:UIInfo>
--> 
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel--> 
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDJDCCAgygAwIBAgIVAMJCEBupgxa2NDCiFfT6YsFdpxrqMA0GCSqGSIb3DQEB
CwUAMBkxFzAVBgNVBAMMDmlkcC5jYW5hcmllLmNhMB4XDTE1MDUwNTE4MDExNFoX
DTM1MDUwNTE4MDExNFowGTEXMBUGA1UEAwwOaWRwLmNhbmFyaWUuY2EwggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCD2QbPWpM46gvlQguBqbD24l2gTAOQ
c3dRxddiM0b9bEEt0s/SfSIZOdtCaFHm8toxvdOtCk9HJh5yN2X035gI0lQNNkyC
+D08AU7mRi423OlnhSUDZtdN+PWek8NG2tTq4B9YayXp/dOHJ8KleKLe60hGTKZG
bcBAzMW8PeWtkLX3dXXcqOcQ58O/99CU7EkuS6M923ItPVm/2EjDFRgwHyrXz/Bl
9zhsebSgtB8Oo4+j1Nr4U4l74URcQaRr9s2Hnal/kygbcwzxRLaPvQznNx2xUx+y
8ieAyxHgIMq1G0drf2tSyDn2+PS0tPL1G+/G8CalXRYDdOYZne4yocydAgMBAAGj
YzBhMB0GA1UdDgQWBBQ2kz5SVzc9LYFjbQNCiXtDmLedajBABgNVHREEOTA3gg5p
ZHAuY2FuYXJpZS5jYYYlaHR0cHM6Ly9pZHAuY2FuYXJpZS5jYS9pZHAvc2hpYmJv
bGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAaflmJhp6YszFbHQexqf4g4K2eQGN/82d
qTZ1KjmfCqSJyL0fpIzGU+Mjy56tr9bRB/VzlzXngl06lwZhS2jOSdI3h+umkVbb
7Ygads95cHjgzgzS97EXEpNyhfU2hPF9dWIeLdsSdSQEwRuI6wmL8Uv8ux5FDRzk
i1B5WbGi2kcXdOEkQC8cN8GH0D7rrzjLsVtrD13e3D92/fc2sD6oWxLukogbndkv
uRuXcbhHlHW8E5rx0/50Aix+o6Ze7MQmKGrmkOXVSbNFuobaevY+yK7ADwBs6RuU
hUkUKlbLsUOTrepGFYmankA0pRTnuS2sbpmdozJ0w6dH5e6+MT+eNw==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDJDCCAgygAwIBAgIVAJ3fH1HeYIxXxMXYbZ/Bx85j/JgKMA0GCSqGSIb3DQEB
BQUAMBkxFzAVBgNVBAMTDmlkcC5jYW5hcmllLmNhMB4XDTExMDcwNjE0MzUxMloX
DTMxMDcwNjE0MzUxMlowGTEXMBUGA1UEAxMOaWRwLmNhbmFyaWUuY2EwggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCcmyqTo01QVuqHI/ZXAdYP+iX6NjP2
topfFsR4y8TVYFN4vMvb5ZSFWPPjJ8T3O2epI8Hy9q4FWyPn1Pa/CZoFi1EMhu7b
QJpOmLzeX6FOvf1X/5De2JnWv7JWMpUMeVqupe2YeCtoaXfViHOB9pW0go2zr6R8
ajvQKxNX46V/o1ND6YwnlKRNsh4hn46cPtl/DNeKYFz4Uj6OHBRSfMHTZCWVENJB
ife66AS7X5hC6o7o2Sd5VHr0TgY+ZeKrl3/33war+RIGXr6cRW9iA9yEeW0Oi13Q
3hkjPT7MNkvNJjWpERR7aBogQ3z5Id8Ygl+WASbyfoiXNCHPa3USAaynAgMBAAGj
YzBhMEAGA1UdEQQ5MDeCDmlkcC5jYW5hcmllLmNhhiVodHRwczovL2lkcC5jYW5h
cmllLmNhL2lkcC9zaGliYm9sZXRoMB0GA1UdDgQWBBRDEuTlL5Y/HfiEJ/wzCfCz
otFdxjANBgkqhkiG9w0BAQUFAAOCAQEAD6WiCAdkGjA7Bza59pnn+/z5/Jhwn7Mf
+WS0WAPz686nIxYjblMBjIVITedkAFvwnEBn0Rs+XNXrc90uRFCNFf4VfSP9NLEf
7cTPNxHiGt6TqOju2Rg6OBmNwRqAtFNqKG7VeKgoiZ4FcRVU2AdQ8fYnxxtwO4xJ
8Md//Yp0lGQzj2FpSU7dnbVRGWAEE3g1Ghjrwe9Aj6e6lunZNaIdTZ6Yvnsa5qly
DngkPipfHlmi56QMo9Iqa3nEKaCv2ykKzTIIUdgDI/M8sHXgitp5tFrAK8f96iBu
zwZrSXVMnjQppB7E2l48gea/BPyFP4FBlxeN8E6aIXH09uN+HbcohQ==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDJDCCAgygAwIBAgIVAJ3fH1HeYIxXxMXYbZ/Bx85j/JgKMA0GCSqGSIb3DQEB
BQUAMBkxFzAVBgNVBAMTDmlkcC5jYW5hcmllLmNhMB4XDTExMDcwNjE0MzUxMloX
DTMxMDcwNjE0MzUxMlowGTEXMBUGA1UEAxMOaWRwLmNhbmFyaWUuY2EwggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCcmyqTo01QVuqHI/ZXAdYP+iX6NjP2
topfFsR4y8TVYFN4vMvb5ZSFWPPjJ8T3O2epI8Hy9q4FWyPn1Pa/CZoFi1EMhu7b
QJpOmLzeX6FOvf1X/5De2JnWv7JWMpUMeVqupe2YeCtoaXfViHOB9pW0go2zr6R8
ajvQKxNX46V/o1ND6YwnlKRNsh4hn46cPtl/DNeKYFz4Uj6OHBRSfMHTZCWVENJB
ife66AS7X5hC6o7o2Sd5VHr0TgY+ZeKrl3/33war+RIGXr6cRW9iA9yEeW0Oi13Q
3hkjPT7MNkvNJjWpERR7aBogQ3z5Id8Ygl+WASbyfoiXNCHPa3USAaynAgMBAAGj
YzBhMEAGA1UdEQQ5MDeCDmlkcC5jYW5hcmllLmNhhiVodHRwczovL2lkcC5jYW5h
cmllLmNhL2lkcC9zaGliYm9sZXRoMB0GA1UdDgQWBBRDEuTlL5Y/HfiEJ/wzCfCz
otFdxjANBgkqhkiG9w0BAQUFAAOCAQEAD6WiCAdkGjA7Bza59pnn+/z5/Jhwn7Mf
+WS0WAPz686nIxYjblMBjIVITedkAFvwnEBn0Rs+XNXrc90uRFCNFf4VfSP9NLEf
7cTPNxHiGt6TqOju2Rg6OBmNwRqAtFNqKG7VeKgoiZ4FcRVU2AdQ8fYnxxtwO4xJ
8Md//Yp0lGQzj2FpSU7dnbVRGWAEE3g1Ghjrwe9Aj6e6lunZNaIdTZ6Yvnsa5qly
DngkPipfHlmi56QMo9Iqa3nEKaCv2ykKzTIIUdgDI/M8sHXgitp5tFrAK8f96iBu
zwZrSXVMnjQppB7E2l48gea/BPyFP4FBlxeN8E6aIXH09uN+HbcohQ==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.canarie.ca:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>
        <!--<ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.canarie.ca:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
--> 
<!--
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.canarie.ca/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.canarie.ca/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.canarie.ca:8443/idp/profile/SAML2/SOAP/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.canarie.ca/idp/profile/SAML2/POST-SimpleSign/SLO"/>
--> 

        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://idp.canarie.ca/idp/profile/SAML2/Redirect/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://idp.canarie.ca/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <!--<SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.canarie.ca/idp/profile/Shibboleth/SSO"/>
-->         <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://idp.canarie.ca/idp/profile/SAML2/POST/SSO"/>

    </IDPSSODescriptor>


<!--    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">canarie.ca</shibmd:Scope>
        </Extensions>

        --> <!-- First signing certificate is BackChannel, the Second is FrontChannel-->  <!--
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDJDCCAgygAwIBAgIVAMJCEBupgxa2NDCiFfT6YsFdpxrqMA0GCSqGSIb3DQEB
CwUAMBkxFzAVBgNVBAMMDmlkcC5jYW5hcmllLmNhMB4XDTE1MDUwNTE4MDExNFoX
DTM1MDUwNTE4MDExNFowGTEXMBUGA1UEAwwOaWRwLmNhbmFyaWUuY2EwggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCD2QbPWpM46gvlQguBqbD24l2gTAOQ
c3dRxddiM0b9bEEt0s/SfSIZOdtCaFHm8toxvdOtCk9HJh5yN2X035gI0lQNNkyC
+D08AU7mRi423OlnhSUDZtdN+PWek8NG2tTq4B9YayXp/dOHJ8KleKLe60hGTKZG
bcBAzMW8PeWtkLX3dXXcqOcQ58O/99CU7EkuS6M923ItPVm/2EjDFRgwHyrXz/Bl
9zhsebSgtB8Oo4+j1Nr4U4l74URcQaRr9s2Hnal/kygbcwzxRLaPvQznNx2xUx+y
8ieAyxHgIMq1G0drf2tSyDn2+PS0tPL1G+/G8CalXRYDdOYZne4yocydAgMBAAGj
YzBhMB0GA1UdDgQWBBQ2kz5SVzc9LYFjbQNCiXtDmLedajBABgNVHREEOTA3gg5p
ZHAuY2FuYXJpZS5jYYYlaHR0cHM6Ly9pZHAuY2FuYXJpZS5jYS9pZHAvc2hpYmJv
bGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAaflmJhp6YszFbHQexqf4g4K2eQGN/82d
qTZ1KjmfCqSJyL0fpIzGU+Mjy56tr9bRB/VzlzXngl06lwZhS2jOSdI3h+umkVbb
7Ygads95cHjgzgzS97EXEpNyhfU2hPF9dWIeLdsSdSQEwRuI6wmL8Uv8ux5FDRzk
i1B5WbGi2kcXdOEkQC8cN8GH0D7rrzjLsVtrD13e3D92/fc2sD6oWxLukogbndkv
uRuXcbhHlHW8E5rx0/50Aix+o6Ze7MQmKGrmkOXVSbNFuobaevY+yK7ADwBs6RuU
hUkUKlbLsUOTrepGFYmankA0pRTnuS2sbpmdozJ0w6dH5e6+MT+eNw==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDJDCCAgygAwIBAgIVAJ3fH1HeYIxXxMXYbZ/Bx85j/JgKMA0GCSqGSIb3DQEB
BQUAMBkxFzAVBgNVBAMTDmlkcC5jYW5hcmllLmNhMB4XDTExMDcwNjE0MzUxMloX
DTMxMDcwNjE0MzUxMlowGTEXMBUGA1UEAxMOaWRwLmNhbmFyaWUuY2EwggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCcmyqTo01QVuqHI/ZXAdYP+iX6NjP2
topfFsR4y8TVYFN4vMvb5ZSFWPPjJ8T3O2epI8Hy9q4FWyPn1Pa/CZoFi1EMhu7b
QJpOmLzeX6FOvf1X/5De2JnWv7JWMpUMeVqupe2YeCtoaXfViHOB9pW0go2zr6R8
ajvQKxNX46V/o1ND6YwnlKRNsh4hn46cPtl/DNeKYFz4Uj6OHBRSfMHTZCWVENJB
ife66AS7X5hC6o7o2Sd5VHr0TgY+ZeKrl3/33war+RIGXr6cRW9iA9yEeW0Oi13Q
3hkjPT7MNkvNJjWpERR7aBogQ3z5Id8Ygl+WASbyfoiXNCHPa3USAaynAgMBAAGj
YzBhMEAGA1UdEQQ5MDeCDmlkcC5jYW5hcmllLmNhhiVodHRwczovL2lkcC5jYW5h
cmllLmNhL2lkcC9zaGliYm9sZXRoMB0GA1UdDgQWBBRDEuTlL5Y/HfiEJ/wzCfCz
otFdxjANBgkqhkiG9w0BAQUFAAOCAQEAD6WiCAdkGjA7Bza59pnn+/z5/Jhwn7Mf
+WS0WAPz686nIxYjblMBjIVITedkAFvwnEBn0Rs+XNXrc90uRFCNFf4VfSP9NLEf
7cTPNxHiGt6TqOju2Rg6OBmNwRqAtFNqKG7VeKgoiZ4FcRVU2AdQ8fYnxxtwO4xJ
8Md//Yp0lGQzj2FpSU7dnbVRGWAEE3g1Ghjrwe9Aj6e6lunZNaIdTZ6Yvnsa5qly
DngkPipfHlmi56QMo9Iqa3nEKaCv2ykKzTIIUdgDI/M8sHXgitp5tFrAK8f96iBu
zwZrSXVMnjQppB7E2l48gea/BPyFP4FBlxeN8E6aIXH09uN+HbcohQ==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDJDCCAgygAwIBAgIVAJ3fH1HeYIxXxMXYbZ/Bx85j/JgKMA0GCSqGSIb3DQEB
BQUAMBkxFzAVBgNVBAMTDmlkcC5jYW5hcmllLmNhMB4XDTExMDcwNjE0MzUxMloX
DTMxMDcwNjE0MzUxMlowGTEXMBUGA1UEAxMOaWRwLmNhbmFyaWUuY2EwggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCcmyqTo01QVuqHI/ZXAdYP+iX6NjP2
topfFsR4y8TVYFN4vMvb5ZSFWPPjJ8T3O2epI8Hy9q4FWyPn1Pa/CZoFi1EMhu7b
QJpOmLzeX6FOvf1X/5De2JnWv7JWMpUMeVqupe2YeCtoaXfViHOB9pW0go2zr6R8
ajvQKxNX46V/o1ND6YwnlKRNsh4hn46cPtl/DNeKYFz4Uj6OHBRSfMHTZCWVENJB
ife66AS7X5hC6o7o2Sd5VHr0TgY+ZeKrl3/33war+RIGXr6cRW9iA9yEeW0Oi13Q
3hkjPT7MNkvNJjWpERR7aBogQ3z5Id8Ygl+WASbyfoiXNCHPa3USAaynAgMBAAGj
YzBhMEAGA1UdEQQ5MDeCDmlkcC5jYW5hcmllLmNhhiVodHRwczovL2lkcC5jYW5h
cmllLmNhL2lkcC9zaGliYm9sZXRoMB0GA1UdDgQWBBRDEuTlL5Y/HfiEJ/wzCfCz
otFdxjANBgkqhkiG9w0BAQUFAAOCAQEAD6WiCAdkGjA7Bza59pnn+/z5/Jhwn7Mf
+WS0WAPz686nIxYjblMBjIVITedkAFvwnEBn0Rs+XNXrc90uRFCNFf4VfSP9NLEf
7cTPNxHiGt6TqOju2Rg6OBmNwRqAtFNqKG7VeKgoiZ4FcRVU2AdQ8fYnxxtwO4xJ
8Md//Yp0lGQzj2FpSU7dnbVRGWAEE3g1Ghjrwe9Aj6e6lunZNaIdTZ6Yvnsa5qly
DngkPipfHlmi56QMo9Iqa3nEKaCv2ykKzTIIUdgDI/M8sHXgitp5tFrAK8f96iBu
zwZrSXVMnjQppB7E2l48gea/BPyFP4FBlxeN8E6aIXH09uN+HbcohQ==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        --> <!--<AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.canarie.ca:8443/idp/profile/SAML2/SOAP/AttributeQuery"/>-->  <!--
        --> <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above-->  <!--
        --> <!--<AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.canarie.ca:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>-->  <!--

    </AttributeAuthorityDescriptor>--> 

</EntityDescriptor>
