<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" entityID="https://idp.nelsongroup.ac.uk/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">nelsongroup.ac.uk</shibmd:Scope>
<!--
    Fill in the details for your IdP here 

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">A Name for the IdP at idp.nelsongroup.ac.uk</mdui:DisplayName>
                <mdui:Description xml:lang="en">Enter a description of your IdP at idp.nelsongroup.ac.uk</mdui:Description>
                <mdui:Logo height="80" width="80">https://idp.nelsongroup.ac.uk/Path/To/Logo.png</mdui:Logo>
            </mdui:UIInfo>
-->
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEPzCCAqegAwIBAgIUB5B1hWBd73gOlpkgdBXABHBcjkgwDQYJKoZIhvcNAQEL
BQAwIDEeMBwGA1UEAwwVaWRwLm5lbHNvbmdyb3VwLmFjLnVrMB4XDTE5MTExOTEx
MTgxN1oXDTM5MTExOTExMTgxN1owIDEeMBwGA1UEAwwVaWRwLm5lbHNvbmdyb3Vw
LmFjLnVrMIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEArLANUWDI1g9D
1/lzMUHlWP/DBqZgOqTQ4Oc7L0EWGXFki4c79yPn5ml8D45CNe/1xTexgkRMhd89
iXezIy7/2yQ8xas/tCLcCRJWoSYShf5DyzBFcjBfET+iVWLmrKVo8pAq2PZ1GO8w
LrbVC3UlfWEx/AOOnLxJXXf76bEsmOKoVLO4/ydsXSN+NGIpMeAAoLhAmGZKQMpV
PHYMt9r5WaOlpIU+1fDkz/tQSGMAkyWdW9BXn9YzlIBAugwxKp03bLzpTAvMS2eA
tPuCY0v9mIpQvzADHt9dc64YcT+vqnqsTJM9/ZHuIgV41RZgN0fwl/jDb6rVPUU4
EOTR6HPq3AOcqkmBHK2+7inKpmq0B/vHAZqRQ7gtg1Hj6IHxGzgmU6P45H1uLU+F
kMkqeJBdi0mbBg2PuJiVALXZ9rNFl0zEEN574sEsp6sWYAN89yp9bng4HqI9YwdU
fV13jMeT15sYSJ3lX6EB1LvhobBrfMlVQKTb+WwDblSiAhCate2FAgMBAAGjcTBv
MB0GA1UdDgQWBBQLx9uEswycdLDGY0vsHqhMchAJSDBOBgNVHREERzBFghVpZHAu
bmVsc29uZ3JvdXAuYWMudWuGLGh0dHBzOi8vaWRwLm5lbHNvbmdyb3VwLmFjLnVr
L2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBgQApCWOWDkSeNjLCQbzZ
ybrhs0zhFmsXTrYyEcrSf1j/YN+PA/ZThGj1zy9IaiX6N7Kfxk0GW+oUqHzF+Vwy
jJIRBb3bxIrmKBswgHZaEYbTcVF7WN2wtPZEu0FMIVavpo8xJxi/eH5cwUbustlI
nrDxazzFxBKMy1gQ/5ibFleBVuZNgtNQrU2eS8nPWkwSj4DAwmAm4VunWg6E8YDX
H0JeqK1kljQBU2OlXb4wNgkodHnrTKP4hAq/oiWQdqtU+/Eq+89ELqOxKX/6k2ve
ee6D5f+v8L00E9KHknlr1BY4uTeZB7dsBgWZo60ZjHslT+/HIUG+XFrBKJKZJQkk
qqGh7fATGlmje8dFsuCzhAO8D+80teXB69YWLpTYyJzeaFDeHZ3s4QK94ACQ+Ndk
TbC1zYDM0P5ioC2qulA8Jkg4KtGmOV0l5n3GfDgxSD1z+BTr72ZRKVeAeQH5lgsy
Y6qJfOuF4rKTHOhWWTYgF4oHku7XZ1NH4Z8PoIUPVcpLL+8=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEQDCCAqigAwIBAgIVANyloSPWYVrWpZawBnLLpzxdf3OQMA0GCSqGSIb3DQEB
CwUAMCAxHjAcBgNVBAMMFWlkcC5uZWxzb25ncm91cC5hYy51azAeFw0xOTExMTkx
MTE4MTVaFw0zOTExMTkxMTE4MTVaMCAxHjAcBgNVBAMMFWlkcC5uZWxzb25ncm91
cC5hYy51azCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBALYUr0Y/+u52
pgmDgr3dSp4la9UIwbF4YUen5HrkZ1q4X54iBgjhfKdvZ1bxg+uigYLhqatvqpHg
V5A5sb1U8nx90uTmZrKt5PpArgMnOZUTN1TvQQF4tEKKx9omiUTM0oju6DWG0xPJ
P5/tkGhAizcsF3JKRgOLOjBNWKwBkiEezujeBBBF5XHhSdkxiAYzTcCc2TV86HKQ
tTbHx152zPs8inFQMdxsniEtscc7BQyClC5RqfR3YXxal7g+BsIDioo5N7+udxS2
Bx3X8VGIB/4pQlDq/xg2d3KIXdxecDDfmchHwOfdno+0Gf9yuxkYQom8/UwW9vOb
p0vf4hgBghdGxG3M9DaTT9mEzNkWSoLfRLQAxJS8Io/to10gC/ZbDhdNtGKsqgvs
2BaJtDd07URJ7uNfibFHsfoYp0O+vVsBvmHBBvwjk5ABYmCSX9N/edcB4hmn7i7F
SOep0yR9xb2iPuVUuZ/XMt15m+sbTqfbeQocwDMyQ65ygmuAcgJNVQIDAQABo3Ew
bzAdBgNVHQ4EFgQUouKNtRoYaBjUjL0B7Sr8QFDjefkwTgYDVR0RBEcwRYIVaWRw
Lm5lbHNvbmdyb3VwLmFjLnVrhixodHRwczovL2lkcC5uZWxzb25ncm91cC5hYy51
ay9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAYEATmOvlZkCkoeex7ZF
WI6SQF22rkTi0TWLPSUjAFH4sbiRDsWv5lBsqIlIS0cD9yf+AkP1EsB4F1UeR3Sp
PG+yH+pGcw/4Y7iu7xReGS5T+qUUwC2vvsYxhbyxJeHHJTb5s37NN9Ch1Y59usmg
72GkZ4P9q1YuRT5vC38S1nJMenF90Mw8sD4BHqpw85DCSLYbNLEnxq2h3aVRNm09
mpsj+inXtwDMHrsIeJq3F8635N/MDQbzgLcLhWY78Iha0dJy+oEn6VKXr3IKNs9N
vX2/+5Aj+xM9CpBev0+BCYttcyOACZ2jWVCvJgIPclEKvttM9PmKidmdupLEh54v
mzcbWe4iSt3k6CkjgxUPTpKr5IVIa+kMl+gPEA3hJxU3ZjbIBJOvYdYBeeTBGk8E
mXUtPX3qpyGRyDImtZ38t2YuiNV6CfKfj9k6Y+EnUiprPz94U1hIx6m21LpZEQVo
1Y05Eq7WiskIR9q3aZyLEC4RVHH4qjsQJRDV6AZRUVeMJWSW
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEQDCCAqigAwIBAgIVAIjbM+Oe6GgNsH+4/xzZrfC1/qaIMA0GCSqGSIb3DQEB
CwUAMCAxHjAcBgNVBAMMFWlkcC5uZWxzb25ncm91cC5hYy51azAeFw0xOTExMTkx
MTE4MTZaFw0zOTExMTkxMTE4MTZaMCAxHjAcBgNVBAMMFWlkcC5uZWxzb25ncm91
cC5hYy51azCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAMHOT6TMVthd
zFfBySbG/N8z1EzcrZJbz9jlWmROskWmr2y3tWIpxdYwemjJTMmMRBCmw4KMdMO4
B7uMkAxsk+v6mxVK0XI1fsQ/yTX32ux7tM9popejVz17B7NCyZi+LelRf72Bp45O
oGBH7xmmL6fjMWkRntwB/7/bbm0+1yfPmMyr5b7EKPBwtHoxbOBBuMr7z2/xzGJs
+LbQYo4DGLtELGWYDSS7lEnt6mGS5pO8FBoSdQxE9B2czRzCbTxm8wbc+NoqjkCK
i2JrNuYi0RD19/pOBzjQXvxQXbnuGB0haDcPfEJbTGgiQ4Onwk9PVTCfPgfC/ji4
ysyBBLUGkXsTTJjl7qytObgx53sgK2IbJOmeYnUSVs/PG+M+nghZlZ7eDMr/Mj2e
7pmqY2eHXLClYLcgqECyVzWpKQw1TOcseZlLAQyyt2C0+/iGtyogdWqK2S3Ewl2v
ZcvX2hc3MXKeyiCK+hFSOzfpALnI7sqa1T7Ay86+6XIJ3qsKJQptsQIDAQABo3Ew
bzAdBgNVHQ4EFgQU8Fnk8vLHzDnG4gPPZWwBWVVC/+AwTgYDVR0RBEcwRYIVaWRw
Lm5lbHNvbmdyb3VwLmFjLnVrhixodHRwczovL2lkcC5uZWxzb25ncm91cC5hYy51
ay9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAYEAkuxyuWCDsJkkcbTn
VgAsqRYoOBXr1pI3wkiHe3aOpDnlBqh26kRZ+ZuVBeCQYVI3nqG/DT3t7FnHGWtp
b9trf2mHwa+N4Wckrazp49WrQjNQeJY0XO5n7N4SDBwlrLDKSKSzUWUgxBhKW+dS
iF6fPwEMeQzFQ+PyLTB6CJ55ZxZUOdiX9xxbjTTK+kw4B7he+ZQTN66Wsppdgq3m
I4JQH0QM93OOUsAtLJlMg5e/b1JiR+gJUSqke6JuJwaQmmzleZu7nqrNfgU20I8t
uKEbwGw+dx5UzO6A3L17/1wUOIOWmzeAc2zUGZaZIbYjgsQIEGox6ndRSlm7X6q6
jabgOICPOa50iJDMi1zYcnV8zkjWuJm1zWHQe7JHjfaeuCTUHTDvxwgWECSYiONf
lwAofadtSYZ3hA4PJhEIpC5obacMSjmrtFDKyAh4QY2awrz5tt6m+/t+P20jGb7+
96TwChvp2L6e7jIO+YvekwoNo+N/WOqc8TDIhiGMU63Ip/H6
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.nelsongroup.ac.uk:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.nelsongroup.ac.uk:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>

        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.nelsongroup.ac.uk/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.nelsongroup.ac.uk/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.nelsongroup.ac.uk/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.nelsongroup.ac.uk:8443/idp/profile/SAML2/SOAP/SLO"/>

        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.nelsongroup.ac.uk/idp/profile/Shibboleth/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://idp.nelsongroup.ac.uk/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://idp.nelsongroup.ac.uk/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://idp.nelsongroup.ac.uk/idp/profile/SAML2/Redirect/SSO"/>

    </IDPSSODescriptor>


    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">nelsongroup.ac.uk</shibmd:Scope>
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEPzCCAqegAwIBAgIUB5B1hWBd73gOlpkgdBXABHBcjkgwDQYJKoZIhvcNAQEL
BQAwIDEeMBwGA1UEAwwVaWRwLm5lbHNvbmdyb3VwLmFjLnVrMB4XDTE5MTExOTEx
MTgxN1oXDTM5MTExOTExMTgxN1owIDEeMBwGA1UEAwwVaWRwLm5lbHNvbmdyb3Vw
LmFjLnVrMIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEArLANUWDI1g9D
1/lzMUHlWP/DBqZgOqTQ4Oc7L0EWGXFki4c79yPn5ml8D45CNe/1xTexgkRMhd89
iXezIy7/2yQ8xas/tCLcCRJWoSYShf5DyzBFcjBfET+iVWLmrKVo8pAq2PZ1GO8w
LrbVC3UlfWEx/AOOnLxJXXf76bEsmOKoVLO4/ydsXSN+NGIpMeAAoLhAmGZKQMpV
PHYMt9r5WaOlpIU+1fDkz/tQSGMAkyWdW9BXn9YzlIBAugwxKp03bLzpTAvMS2eA
tPuCY0v9mIpQvzADHt9dc64YcT+vqnqsTJM9/ZHuIgV41RZgN0fwl/jDb6rVPUU4
EOTR6HPq3AOcqkmBHK2+7inKpmq0B/vHAZqRQ7gtg1Hj6IHxGzgmU6P45H1uLU+F
kMkqeJBdi0mbBg2PuJiVALXZ9rNFl0zEEN574sEsp6sWYAN89yp9bng4HqI9YwdU
fV13jMeT15sYSJ3lX6EB1LvhobBrfMlVQKTb+WwDblSiAhCate2FAgMBAAGjcTBv
MB0GA1UdDgQWBBQLx9uEswycdLDGY0vsHqhMchAJSDBOBgNVHREERzBFghVpZHAu
bmVsc29uZ3JvdXAuYWMudWuGLGh0dHBzOi8vaWRwLm5lbHNvbmdyb3VwLmFjLnVr
L2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBgQApCWOWDkSeNjLCQbzZ
ybrhs0zhFmsXTrYyEcrSf1j/YN+PA/ZThGj1zy9IaiX6N7Kfxk0GW+oUqHzF+Vwy
jJIRBb3bxIrmKBswgHZaEYbTcVF7WN2wtPZEu0FMIVavpo8xJxi/eH5cwUbustlI
nrDxazzFxBKMy1gQ/5ibFleBVuZNgtNQrU2eS8nPWkwSj4DAwmAm4VunWg6E8YDX
H0JeqK1kljQBU2OlXb4wNgkodHnrTKP4hAq/oiWQdqtU+/Eq+89ELqOxKX/6k2ve
ee6D5f+v8L00E9KHknlr1BY4uTeZB7dsBgWZo60ZjHslT+/HIUG+XFrBKJKZJQkk
qqGh7fATGlmje8dFsuCzhAO8D+80teXB69YWLpTYyJzeaFDeHZ3s4QK94ACQ+Ndk
TbC1zYDM0P5ioC2qulA8Jkg4KtGmOV0l5n3GfDgxSD1z+BTr72ZRKVeAeQH5lgsy
Y6qJfOuF4rKTHOhWWTYgF4oHku7XZ1NH4Z8PoIUPVcpLL+8=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEQDCCAqigAwIBAgIVANyloSPWYVrWpZawBnLLpzxdf3OQMA0GCSqGSIb3DQEB
CwUAMCAxHjAcBgNVBAMMFWlkcC5uZWxzb25ncm91cC5hYy51azAeFw0xOTExMTkx
MTE4MTVaFw0zOTExMTkxMTE4MTVaMCAxHjAcBgNVBAMMFWlkcC5uZWxzb25ncm91
cC5hYy51azCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBALYUr0Y/+u52
pgmDgr3dSp4la9UIwbF4YUen5HrkZ1q4X54iBgjhfKdvZ1bxg+uigYLhqatvqpHg
V5A5sb1U8nx90uTmZrKt5PpArgMnOZUTN1TvQQF4tEKKx9omiUTM0oju6DWG0xPJ
P5/tkGhAizcsF3JKRgOLOjBNWKwBkiEezujeBBBF5XHhSdkxiAYzTcCc2TV86HKQ
tTbHx152zPs8inFQMdxsniEtscc7BQyClC5RqfR3YXxal7g+BsIDioo5N7+udxS2
Bx3X8VGIB/4pQlDq/xg2d3KIXdxecDDfmchHwOfdno+0Gf9yuxkYQom8/UwW9vOb
p0vf4hgBghdGxG3M9DaTT9mEzNkWSoLfRLQAxJS8Io/to10gC/ZbDhdNtGKsqgvs
2BaJtDd07URJ7uNfibFHsfoYp0O+vVsBvmHBBvwjk5ABYmCSX9N/edcB4hmn7i7F
SOep0yR9xb2iPuVUuZ/XMt15m+sbTqfbeQocwDMyQ65ygmuAcgJNVQIDAQABo3Ew
bzAdBgNVHQ4EFgQUouKNtRoYaBjUjL0B7Sr8QFDjefkwTgYDVR0RBEcwRYIVaWRw
Lm5lbHNvbmdyb3VwLmFjLnVrhixodHRwczovL2lkcC5uZWxzb25ncm91cC5hYy51
ay9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAYEATmOvlZkCkoeex7ZF
WI6SQF22rkTi0TWLPSUjAFH4sbiRDsWv5lBsqIlIS0cD9yf+AkP1EsB4F1UeR3Sp
PG+yH+pGcw/4Y7iu7xReGS5T+qUUwC2vvsYxhbyxJeHHJTb5s37NN9Ch1Y59usmg
72GkZ4P9q1YuRT5vC38S1nJMenF90Mw8sD4BHqpw85DCSLYbNLEnxq2h3aVRNm09
mpsj+inXtwDMHrsIeJq3F8635N/MDQbzgLcLhWY78Iha0dJy+oEn6VKXr3IKNs9N
vX2/+5Aj+xM9CpBev0+BCYttcyOACZ2jWVCvJgIPclEKvttM9PmKidmdupLEh54v
mzcbWe4iSt3k6CkjgxUPTpKr5IVIa+kMl+gPEA3hJxU3ZjbIBJOvYdYBeeTBGk8E
mXUtPX3qpyGRyDImtZ38t2YuiNV6CfKfj9k6Y+EnUiprPz94U1hIx6m21LpZEQVo
1Y05Eq7WiskIR9q3aZyLEC4RVHH4qjsQJRDV6AZRUVeMJWSW
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEQDCCAqigAwIBAgIVAIjbM+Oe6GgNsH+4/xzZrfC1/qaIMA0GCSqGSIb3DQEB
CwUAMCAxHjAcBgNVBAMMFWlkcC5uZWxzb25ncm91cC5hYy51azAeFw0xOTExMTkx
MTE4MTZaFw0zOTExMTkxMTE4MTZaMCAxHjAcBgNVBAMMFWlkcC5uZWxzb25ncm91
cC5hYy51azCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAMHOT6TMVthd
zFfBySbG/N8z1EzcrZJbz9jlWmROskWmr2y3tWIpxdYwemjJTMmMRBCmw4KMdMO4
B7uMkAxsk+v6mxVK0XI1fsQ/yTX32ux7tM9popejVz17B7NCyZi+LelRf72Bp45O
oGBH7xmmL6fjMWkRntwB/7/bbm0+1yfPmMyr5b7EKPBwtHoxbOBBuMr7z2/xzGJs
+LbQYo4DGLtELGWYDSS7lEnt6mGS5pO8FBoSdQxE9B2czRzCbTxm8wbc+NoqjkCK
i2JrNuYi0RD19/pOBzjQXvxQXbnuGB0haDcPfEJbTGgiQ4Onwk9PVTCfPgfC/ji4
ysyBBLUGkXsTTJjl7qytObgx53sgK2IbJOmeYnUSVs/PG+M+nghZlZ7eDMr/Mj2e
7pmqY2eHXLClYLcgqECyVzWpKQw1TOcseZlLAQyyt2C0+/iGtyogdWqK2S3Ewl2v
ZcvX2hc3MXKeyiCK+hFSOzfpALnI7sqa1T7Ay86+6XIJ3qsKJQptsQIDAQABo3Ew
bzAdBgNVHQ4EFgQU8Fnk8vLHzDnG4gPPZWwBWVVC/+AwTgYDVR0RBEcwRYIVaWRw
Lm5lbHNvbmdyb3VwLmFjLnVrhixodHRwczovL2lkcC5uZWxzb25ncm91cC5hYy51
ay9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAYEAkuxyuWCDsJkkcbTn
VgAsqRYoOBXr1pI3wkiHe3aOpDnlBqh26kRZ+ZuVBeCQYVI3nqG/DT3t7FnHGWtp
b9trf2mHwa+N4Wckrazp49WrQjNQeJY0XO5n7N4SDBwlrLDKSKSzUWUgxBhKW+dS
iF6fPwEMeQzFQ+PyLTB6CJ55ZxZUOdiX9xxbjTTK+kw4B7he+ZQTN66Wsppdgq3m
I4JQH0QM93OOUsAtLJlMg5e/b1JiR+gJUSqke6JuJwaQmmzleZu7nqrNfgU20I8t
uKEbwGw+dx5UzO6A3L17/1wUOIOWmzeAc2zUGZaZIbYjgsQIEGox6ndRSlm7X6q6
jabgOICPOa50iJDMi1zYcnV8zkjWuJm1zWHQe7JHjfaeuCTUHTDvxwgWECSYiONf
lwAofadtSYZ3hA4PJhEIpC5obacMSjmrtFDKyAh4QY2awrz5tt6m+/t+P20jGb7+
96TwChvp2L6e7jIO+YvekwoNo+N/WOqc8TDIhiGMU63Ip/H6
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.nelsongroup.ac.uk:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
        <!-- <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.nelsongroup.ac.uk:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> -->
        <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->

    </AttributeAuthorityDescriptor>

    <!-- SP metadata for SAML proxy -->
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
  
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
MIIEPzCCAqegAwIBAgIUB5B1hWBd73gOlpkgdBXABHBcjkgwDQYJKoZIhvcNAQEL
BQAwIDEeMBwGA1UEAwwVaWRwLm5lbHNvbmdyb3VwLmFjLnVrMB4XDTE5MTExOTEx
MTgxN1oXDTM5MTExOTExMTgxN1owIDEeMBwGA1UEAwwVaWRwLm5lbHNvbmdyb3Vw
LmFjLnVrMIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEArLANUWDI1g9D
1/lzMUHlWP/DBqZgOqTQ4Oc7L0EWGXFki4c79yPn5ml8D45CNe/1xTexgkRMhd89
iXezIy7/2yQ8xas/tCLcCRJWoSYShf5DyzBFcjBfET+iVWLmrKVo8pAq2PZ1GO8w
LrbVC3UlfWEx/AOOnLxJXXf76bEsmOKoVLO4/ydsXSN+NGIpMeAAoLhAmGZKQMpV
PHYMt9r5WaOlpIU+1fDkz/tQSGMAkyWdW9BXn9YzlIBAugwxKp03bLzpTAvMS2eA
tPuCY0v9mIpQvzADHt9dc64YcT+vqnqsTJM9/ZHuIgV41RZgN0fwl/jDb6rVPUU4
EOTR6HPq3AOcqkmBHK2+7inKpmq0B/vHAZqRQ7gtg1Hj6IHxGzgmU6P45H1uLU+F
kMkqeJBdi0mbBg2PuJiVALXZ9rNFl0zEEN574sEsp6sWYAN89yp9bng4HqI9YwdU
fV13jMeT15sYSJ3lX6EB1LvhobBrfMlVQKTb+WwDblSiAhCate2FAgMBAAGjcTBv
MB0GA1UdDgQWBBQLx9uEswycdLDGY0vsHqhMchAJSDBOBgNVHREERzBFghVpZHAu
bmVsc29uZ3JvdXAuYWMudWuGLGh0dHBzOi8vaWRwLm5lbHNvbmdyb3VwLmFjLnVr
L2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBgQApCWOWDkSeNjLCQbzZ
ybrhs0zhFmsXTrYyEcrSf1j/YN+PA/ZThGj1zy9IaiX6N7Kfxk0GW+oUqHzF+Vwy
jJIRBb3bxIrmKBswgHZaEYbTcVF7WN2wtPZEu0FMIVavpo8xJxi/eH5cwUbustlI
nrDxazzFxBKMy1gQ/5ibFleBVuZNgtNQrU2eS8nPWkwSj4DAwmAm4VunWg6E8YDX
H0JeqK1kljQBU2OlXb4wNgkodHnrTKP4hAq/oiWQdqtU+/Eq+89ELqOxKX/6k2ve
ee6D5f+v8L00E9KHknlr1BY4uTeZB7dsBgWZo60ZjHslT+/HIUG+XFrBKJKZJQkk
qqGh7fATGlmje8dFsuCzhAO8D+80teXB69YWLpTYyJzeaFDeHZ3s4QK94ACQ+Ndk
TbC1zYDM0P5ioC2qulA8Jkg4KtGmOV0l5n3GfDgxSD1z+BTr72ZRKVeAeQH5lgsy
Y6qJfOuF4rKTHOhWWTYgF4oHku7XZ1NH4Z8PoIUPVcpLL+8=
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
MIIEQDCCAqigAwIBAgIVAIjbM+Oe6GgNsH+4/xzZrfC1/qaIMA0GCSqGSIb3DQEB
CwUAMCAxHjAcBgNVBAMMFWlkcC5uZWxzb25ncm91cC5hYy51azAeFw0xOTExMTkx
MTE4MTZaFw0zOTExMTkxMTE4MTZaMCAxHjAcBgNVBAMMFWlkcC5uZWxzb25ncm91
cC5hYy51azCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAMHOT6TMVthd
zFfBySbG/N8z1EzcrZJbz9jlWmROskWmr2y3tWIpxdYwemjJTMmMRBCmw4KMdMO4
B7uMkAxsk+v6mxVK0XI1fsQ/yTX32ux7tM9popejVz17B7NCyZi+LelRf72Bp45O
oGBH7xmmL6fjMWkRntwB/7/bbm0+1yfPmMyr5b7EKPBwtHoxbOBBuMr7z2/xzGJs
+LbQYo4DGLtELGWYDSS7lEnt6mGS5pO8FBoSdQxE9B2czRzCbTxm8wbc+NoqjkCK
i2JrNuYi0RD19/pOBzjQXvxQXbnuGB0haDcPfEJbTGgiQ4Onwk9PVTCfPgfC/ji4
ysyBBLUGkXsTTJjl7qytObgx53sgK2IbJOmeYnUSVs/PG+M+nghZlZ7eDMr/Mj2e
7pmqY2eHXLClYLcgqECyVzWpKQw1TOcseZlLAQyyt2C0+/iGtyogdWqK2S3Ewl2v
ZcvX2hc3MXKeyiCK+hFSOzfpALnI7sqa1T7Ay86+6XIJ3qsKJQptsQIDAQABo3Ew
bzAdBgNVHQ4EFgQU8Fnk8vLHzDnG4gPPZWwBWVVC/+AwTgYDVR0RBEcwRYIVaWRw
Lm5lbHNvbmdyb3VwLmFjLnVrhixodHRwczovL2lkcC5uZWxzb25ncm91cC5hYy51
ay9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAYEAkuxyuWCDsJkkcbTn
VgAsqRYoOBXr1pI3wkiHe3aOpDnlBqh26kRZ+ZuVBeCQYVI3nqG/DT3t7FnHGWtp
b9trf2mHwa+N4Wckrazp49WrQjNQeJY0XO5n7N4SDBwlrLDKSKSzUWUgxBhKW+dS
iF6fPwEMeQzFQ+PyLTB6CJ55ZxZUOdiX9xxbjTTK+kw4B7he+ZQTN66Wsppdgq3m
I4JQH0QM93OOUsAtLJlMg5e/b1JiR+gJUSqke6JuJwaQmmzleZu7nqrNfgU20I8t
uKEbwGw+dx5UzO6A3L17/1wUOIOWmzeAc2zUGZaZIbYjgsQIEGox6ndRSlm7X6q6
jabgOICPOa50iJDMi1zYcnV8zkjWuJm1zWHQe7JHjfaeuCTUHTDvxwgWECSYiONf
lwAofadtSYZ3hA4PJhEIpC5obacMSjmrtFDKyAh4QY2awrz5tt6m+/t+P20jGb7+
96TwChvp2L6e7jIO+YvekwoNo+N/WOqc8TDIhiGMU63Ip/H6
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
  
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.example.ac.uk/idp/profile/Authn/SAML2/POST/SSO" index="0"/>


</EntityDescriptor>
