<?xml version="1.0" encoding="UTF-8"?>
<!--
    20180911
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" entityID="https://login.ithaca.edu/idp/shibboleth">

    <IDPSSODescriptor errorURL="https://www.ithaca.edu/information-technology/information-security/shibboleth-error" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">ithaca.edu</shibmd:Scope>
<!--
Fill in the details for your IdP here
-->
<mdui:UIInfo>
    <mdui:DisplayName xml:lang="en">login.ithaca.edu</mdui:DisplayName>
    <mdui:Description xml:lang="en">Ithaca College Single Sign on IdP</mdui:Description>
    <mdui:Logo height="99" width="399">https://login.ithaca.edu/idp/images/sso-logo.png</mdui:Logo>
    <mdui:PrivacyStatementURL  xml:lang="en">https://www.ithaca.edu/it/general/policies/privacy/</mdui:PrivacyStatementURL>
</mdui:UIInfo>

        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDLDCCAhSgAwIBAgIVAJe+1m0GBLZtJWgp14ruuR81BcjaMA0GCSqGSIb3DQEB
CwUAMBsxGTAXBgNVBAMMEGxvZ2luLml0aGFjYS5lZHUwHhcNMTcwMzA2MTg0MDQ3
WhcNMzcwMzA2MTg0MDQ3WjAbMRkwFwYDVQQDDBBsb2dpbi5pdGhhY2EuZWR1MIIB
IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAipGKk2mLV5cB1jL6A34/RGXz
6VE2RG0Krj3Z0pE6Ws8cifI9bpkdgnyRz+XS6iZtG68bqB7Oh+BLgzss5LxqaMBG
Mtk+W8LcAVAwECLaaVe4hHFcbQTEAGDwieVpYtaqNxb0Xja4nUX22m/uzeujN76L
kyOKYiQE4MKds5k5UmlWHAWVZM7Rgv5BUNrtgGt0AmRb6+eL3FUDg5yOuWAnmejC
fXWmzigdo8dJRjRDm9YXv2fn5CrWk3/vv2C/GC1seTKQsgSX4WDLrXrHDUhJdzxB
23MtmIEEzi0W3eTaL0OHyNA8D3/P3rey0oED/XnlBghUxq0emvmZHxQKo4+qSwID
AQABo2cwZTAdBgNVHQ4EFgQUrgFuF5kWryEnj1nyn0tjrW/PtYEwRAYDVR0RBD0w
O4IQbG9naW4uaXRoYWNhLmVkdYYnaHR0cHM6Ly9sb2dpbi5pdGhhY2EuZWR1L2lk
cC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQBrKpftO3wAolXBHOQQhYX3
RJVDOZk0oBonXbB5SSAw4ddTP5fBcvXrvoOE6S+3PmY4X3foFeEfED24rDIj/UiC
yen/ISF4pVnJg76/YHyWYtE/R6dQzOVsTtg5r+daIe4D+8/WtQjH5zrJxAvjLhDm
aMtaHHMMR1J7C3mhsq8YJfSnSK4FdzgCzW8YcSTcMs3u2KMckN/nJyt/kctLJCWT
LsVVXkuRmhnQlM3+BnPKA05V7Lxa3B7N5uo9sGL+bGT6E3GU3hoN4NuDckwbrRWF
jJ5xbNzesN77KBns7ejC3BqkJ6wv6Jb/Oyiu50LcvMu+z8sweaJdUNEnPMpZD+gu
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDKzCCAhOgAwIBAgIUWb2+Rx66dRNqzL7iWRGUHNQ7bTUwDQYJKoZIhvcNAQEL
BQAwGzEZMBcGA1UEAwwQbG9naW4uaXRoYWNhLmVkdTAeFw0xNzAzMDYxODQwNDRa
Fw0zNzAzMDYxODQwNDRaMBsxGTAXBgNVBAMMEGxvZ2luLml0aGFjYS5lZHUwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrF3xHl0jGsQof9AVZQj9AsKbc
9JbGqSMcX8OQ61pstijiaPvxZbtEiwgblcA0OQLZFz28l5+6ck3hk3XRmrR2GL4X
Xls600KoUhAuPkHFs9iVIeuw/NYOTlUA7C57Ow3NzzfBopOTApNS2kcvyerPV+lM
oSXmRXN+QtC9LnbsuBcOtHxOmtEOloTD2aWCsdMFbsrHSH8HFrhcwbfCf2nJ7CbU
DAR9j3SIhNC1HlmpeR2rf6c00FtFfNCRQlypGtrGoNm+UafcTKMHxg86kzBzH25c
YjK47Re2vxomIv1REkXsvub26h18Bnz4JDc/b1v07Bh1RwWiFnYSkV9iEdaDAgMB
AAGjZzBlMB0GA1UdDgQWBBQ944Nh0D8Eo1PrLO+NGTGus7iRiDBEBgNVHREEPTA7
ghBsb2dpbi5pdGhhY2EuZWR1hidodHRwczovL2xvZ2luLml0aGFjYS5lZHUvaWRw
L3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBADaRN6f89xlsVhH1DeRsHKWb
w1pd2jLCJtKpjZG0CYF1li8olHvZYYZJWbEtMkX4Wpsh0iG43rv/rZRqoCMq5B5Q
sLXLNlMF3+xmyzbBfnOy0tDISQedL2WcQz1C1DQi2mZgE9qOmJ+P1notq/SWWHvl
2KD/rpe1o2Yawgb+DT9B2KSEXylKBUAKlOcDS6dvalBV4MWt1k9Pad22vJ2SnSnW
iQtnhZBCMpVVH/HRwCSB+4pmDyLCJTaeyWw9csoAO+UsUcicF42yx8ovixfiCMWl
WxUdtqYOQp3ki7f/uaiG0p+deEMTHjYkqXExrqoU+m1jNB/QyWnfhUUzolCVfR0=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDKzCCAhOgAwIBAgIUesUBAqtWSG7OVhsxVOOCa202LdEwDQYJKoZIhvcNAQEL
BQAwGzEZMBcGA1UEAwwQbG9naW4uaXRoYWNhLmVkdTAeFw0xNzAzMDYxODQwNDVa
Fw0zNzAzMDYxODQwNDVaMBsxGTAXBgNVBAMMEGxvZ2luLml0aGFjYS5lZHUwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCMrRfVSwEjISNZD8V+Va3aunI7
0LZlFBlpJUzQWj3owTBw5mHEqoQvNkhCbXn3c8zV02zREPUzNo7C3DSObxGasdeA
FUSCjmexiTiWHD4REJm4IT2fQw4QQ5fkDbl+Eg7zohrmzWPJyUwXk2Zrz3wTDxHC
8wkPEFmq/JlMf92w/Bv1EKKBEQRZ90seC1R5NIusJLlt2j1Sxrtd1+EgjLJLk7IL
Dz54YVXL4P2rajCMVb9yWm5djKSr1tg9CLcNGeEmmhKFhndl3vRYvA0X7vNEG0qA
aEqkSVM0dGwRMavy/lEV7RqaA2TT1ef+UcKhzlzWv9Fx/+i7NlXiaVD7prJ5AgMB
AAGjZzBlMB0GA1UdDgQWBBSzW3lHCbtRg2J9TuputmX9tt9GVzBEBgNVHREEPTA7
ghBsb2dpbi5pdGhhY2EuZWR1hidodHRwczovL2xvZ2luLml0aGFjYS5lZHUvaWRw
L3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBABp4Ik9eWFatJGTcAA+48ARK
ePZvLNBZ75dnOhGndz6NpG9vnz4saCBH8UvIF2W0UUX31C6Ah25fnQ+ZWo5ryE31
eIXcU35xQkFaLgmngE1ulYx72bfCAQAOtBp+9mWs+jEvzfc0rMKpwwpl2ErxmB3w
p25xyV+zjozs02lRzoYglMVnHDBHoCbJmpxWRcqz2ehO+My5rdbD+h+FwmKY/dU1
e26EAdOyPA+PT7plASUfrVU6cbCDPeaMF9hQioVghrsao6UHFo5ZpsbqpvEYkWRq
g3ri4PTmByv8svdMgyJ/oZhlBcDkHm9JKaoTdVfMLpW2pLQyicW+3U/9IjB6IEY=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://login.ithaca.edu:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>

        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://login.ithaca.edu/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://login.ithaca.edu/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://login.ithaca.edu/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://login.ithaca.edu:8443/idp/profile/SAML2/SOAP/SLO"/>

        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>

	<!--
        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://login.ithaca.edu/idp/profile/Shibboleth/SSO"/>
        -->
	<SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://login.ithaca.edu/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://login.ithaca.edu/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://login.ithaca.edu/idp/profile/SAML2/Redirect/SSO"/>

    </IDPSSODescriptor>

  <Organization>
    <OrganizationName xml:lang="en">Ithaca College</OrganizationName>
    <OrganizationDisplayName xml:lang="en">Ithaca College</OrganizationDisplayName>
    <OrganizationURL xml:lang="en">http://www.ithaca.edu/</OrganizationURL>
  </Organization>
  <ContactPerson contactType="technical"
     xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata">
    <GivenName>Technical Support Team</GivenName>
    <EmailAddress>mailto:shibbolethadmin@ithaca.edu</EmailAddress>
  </ContactPerson>
  <ContactPerson contactType="administrative"
     xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata">
    <GivenName>Administrative Support</GivenName>
    <EmailAddress>mailto:shibbolethadmin@ithaca.edu</EmailAddress>
  </ContactPerson>
  <ContactPerson contactType="support"
     xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata">
    <GivenName>Service Desk</GivenName>
    <EmailAddress>mailto:shibbolethadmin@ithaca.edu</EmailAddress>
  </ContactPerson>
  <ContactPerson contactType="other"
     xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
     xmlns:remd="http://refeds.org/metadata"
     remd:contactType="http://refeds.org/metadata/contactType/security">
    <GivenName>IT Security Office</GivenName>
    <EmailAddress>mailto:infosec@ithaca.edu</EmailAddress>
  </ContactPerson>

</EntityDescriptor>
