<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.

<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" validUntil="2019-04-25T13:20:54.404Z" entityID="https://aai.pik-potsdam.de/idp/shibboleth">
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" entityID="https://aai.pik-potsdam.de/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">pik-potsdam.de</shibmd:Scope>
<!--
    Fill in the details for your IdP here 

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">A Name for the IdP at aai03.pik-potsdam.de</mdui:DisplayName>
                <mdui:Description xml:lang="en">Enter a description of your IdP at aai03.pik-potsdam.de</mdui:Description>
                <mdui:Logo height="80" width="80">https://aai03.pik-potsdam.de/Path/To/Logo.png</mdui:Logo>
            </mdui:UIInfo>
-->
<!--RG 
details about our IdP here
-->
            <mdui:UIInfo>
	        <mdui:DisplayName xml:lang="en">Potsdam Institute for Climate Impact Research</mdui:DisplayName>
	        <mdui:DisplayName xml:lang="de">Potsdam-Institut für Klimafolgenforschung</mdui:DisplayName>
		<mdui:Description xml:lang="en">Identity Provider of PIK</mdui:Description>
		<mdui:Description xml:lang="de">Identity Provider des PIK</mdui:Description>
		<mdui:Logo height="16" width="16">https://aai.pik-potsdam.de/favicon.ico</mdui:Logo>
		<mdui:Logo height="80" width="80">https://aai.pik-potsdam.de/idp/images/logo.png</mdui:Logo>
	    </mdui:UIInfo>


        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIH7zCCBdegAwIBAgIMKNdfbV6z7LGJ9ZmCMA0GCSqGSIb3DQEBCwUAMIGVMQsw
CQYDVQQGEwJERTFFMEMGA1UECgw8VmVyZWluIHp1ciBGb2VyZGVydW5nIGVpbmVz
IERldXRzY2hlbiBGb3JzY2h1bmdzbmV0emVzIGUuIFYuMRAwDgYDVQQLDAdERk4t
UEtJMS0wKwYDVQQDDCRERk4tVmVyZWluIENvbW11bml0eSBJc3N1aW5nIENBIDIw
MjIwHhcNMjMwNzE5MTMxNTA5WhcNMjYxMDAxMTMxNTA5WjCBjTELMAkGA1UEBhMC
REUxFDASBgNVBAgMC0JyYW5kZW5idXJnMRAwDgYDVQQHDAdQb3RzZGFtMTkwNwYD
VQQKDDBQb3RzZGFtLUluc3RpdHV0IGZ1ZXIgS2xpbWFmb2xnZW5mb3JzY2h1bmcg
ZS4gVi4xGzAZBgNVBAMMEmFhaS5waWstcG90c2RhbS5kZTCCAiIwDQYJKoZIhvcN
AQEBBQADggIPADCCAgoCggIBAJN19nfvBo/HtkIJYzGtErWa/9IVZ8swksoFPTq7
wFkVTPRh7Q58xgTPe+Tm48ktjkdkvxGncdJHMQGjB57AevYC+X0u1j/PEA9gYU3D
+mKm4GDVDSmAFBjFqPaKMPtZHKSZW0g42QB5H83+QAERjRJKu6T8+aT6N6YBURL3
TgpvhqIgUmcvIM+wdIC+WrA3DP4QpP5DEDHZ1iVHhNt/3O9f262e6wyOpNTDgfu7
iFXFai8zh8NUNnOKuxkFoIfZjteuc/2OGACmKH6S40sGKk0wHdRsS0yv0H3RVCBU
O1qtnz3EL6LyMn62fqCsQG/X6F4jffkkZYQlFomBI25uBT2Me0nXYSB68w/3BhW3
ace3ZVSmChGwpNxXnzVCqufpgnUXr6+gLmlX0Iy3ZA6heF0i71Cb0NSXzHYwcYwC
GMR9FbKZ7MaHf3PDBE7/zG2oJQbF8NLVSBHEn2p62zfLNLpdOjE1Yf23HZpqJU5c
lLspega8ojTDPeuyk3N742CejgNBDDrK5Uf46lfwXz5z/3kqsm6MC6u6XPqDqwX9
w3YCDkJfOURhM/ouBK1D9f0u+q9h2l+1GhcrKLfJiDpILMJg1/YISykoNG4UV7mF
bviIqmaAIlfXWhFJZnt18gKgFVLd4/z/5idTrYzx3+YNQ7Hvlm96NA4XvSf29NeS
XB7JAgMBAAGjggJDMIICPzAJBgNVHRMEAjAAMA4GA1UdDwEB/wQEAwIFoDAdBgNV
HSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFGlYYidQ78OYTRrD
radVfEQYkW88MB8GA1UdIwQYMBaAFMQoXYtDj1K14+2sq9w4cYi4gYwDMB0GA1Ud
EQQWMBSCEmFhaS5waWstcG90c2RhbS5kZTCBmwYDVR0fBIGTMIGQMEagRKBChkBo
dHRwOi8vY2RwMS5wY2EuZGZuLmRlL2Rmbi12ZXJlaW4tY29tbXVuaXR5LWNhL3B1
Yi9jcmwvY2FjcmwuY3JsMEagRKBChkBodHRwOi8vY2RwMi5wY2EuZGZuLmRlL2Rm
bi12ZXJlaW4tY29tbXVuaXR5LWNhL3B1Yi9jcmwvY2FjcmwuY3JsMIHpBggrBgEF
BQcBAQSB3DCB2TAzBggrBgEFBQcwAYYnaHR0cDovL29jc3AucGNhLmRmbi5kZS9P
Q1NQLVNlcnZlci9PQ1NQMFAGCCsGAQUFBzAChkRodHRwOi8vY2RwMS5wY2EuZGZu
LmRlL2Rmbi12ZXJlaW4tY29tbXVuaXR5LWNhL3B1Yi9jYWNlcnQvY2FjZXJ0LmNy
dDBQBggrBgEFBQcwAoZEaHR0cDovL2NkcDIucGNhLmRmbi5kZS9kZm4tdmVyZWlu
LWNvbW11bml0eS1jYS9wdWIvY2FjZXJ0L2NhY2VydC5jcnQwGgYDVR0gBBMwETAP
Bg0rBgEEAYGtIYIsAgEHMA0GCSqGSIb3DQEBCwUAA4ICAQCTSP02dpJ39seFTjJe
tXXwzR4/9a2Q1DvMgZkVVVCkOqqa+pdsFRoygu+3fcUTrjNwyq7PEA40C3i8YP9f
+eFeehJro9l+jk+rkUSs8EC8R/1lonzrz9ALxqH3FKajU4mzj0/+FKi9NFObQ6of
pIe9WQAP+jEaM+AJ6o+6xdshXdhkmaBHF9h76PBCGv0GSAMS5bI9pI4d9wRu8zfY
CZiHZZHmsf/Dx0ERe8I/4IxbLHAx9ll1ku5F8MiXoWIG+Bfs1wh4U/Abq+UTRf+X
//Ja+CpfBVJGolb8ub/4tMO36XWZFRgMhgNDYoe/rjkWfzSlFPm9v/xJQ5cEa/m/
6f04KW1QIXiT2a/wRaA61T7NwnwyHY1Ql3leqA4YelCra76cjoU8ZwTfu7jOU8+M
CLez6IV2lOuhrix+0fBl3Vj5nkfJFAy10mz+m0swogAeiEypD/50rXbfImE/mkQ1
MXAAODlAVY2HmtXDlxJhacN+KTIEWpAAQUgwdgOuPes72dDsOZtGf/oMrZNYrmH3
SUvxg6cKO1QBewDZw1vf7lLauIM7jyguKaqSxZvpZG43KMCFVIFd35iAUazMO6yk
gVZeVAcu4U73IVOivPBRZbYUjnny6gY4ntykLwf7u6u6tM+r5aE6NxA3Epk9S1vD
BVkaR5AUm1Tx3zDHlgrTsgrthg==
			</ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIH7zCCBdegAwIBAgIMKNdfbV6z7LGJ9ZmCMA0GCSqGSIb3DQEBCwUAMIGVMQsw
CQYDVQQGEwJERTFFMEMGA1UECgw8VmVyZWluIHp1ciBGb2VyZGVydW5nIGVpbmVz
IERldXRzY2hlbiBGb3JzY2h1bmdzbmV0emVzIGUuIFYuMRAwDgYDVQQLDAdERk4t
UEtJMS0wKwYDVQQDDCRERk4tVmVyZWluIENvbW11bml0eSBJc3N1aW5nIENBIDIw
MjIwHhcNMjMwNzE5MTMxNTA5WhcNMjYxMDAxMTMxNTA5WjCBjTELMAkGA1UEBhMC
REUxFDASBgNVBAgMC0JyYW5kZW5idXJnMRAwDgYDVQQHDAdQb3RzZGFtMTkwNwYD
VQQKDDBQb3RzZGFtLUluc3RpdHV0IGZ1ZXIgS2xpbWFmb2xnZW5mb3JzY2h1bmcg
ZS4gVi4xGzAZBgNVBAMMEmFhaS5waWstcG90c2RhbS5kZTCCAiIwDQYJKoZIhvcN
AQEBBQADggIPADCCAgoCggIBAJN19nfvBo/HtkIJYzGtErWa/9IVZ8swksoFPTq7
wFkVTPRh7Q58xgTPe+Tm48ktjkdkvxGncdJHMQGjB57AevYC+X0u1j/PEA9gYU3D
+mKm4GDVDSmAFBjFqPaKMPtZHKSZW0g42QB5H83+QAERjRJKu6T8+aT6N6YBURL3
TgpvhqIgUmcvIM+wdIC+WrA3DP4QpP5DEDHZ1iVHhNt/3O9f262e6wyOpNTDgfu7
iFXFai8zh8NUNnOKuxkFoIfZjteuc/2OGACmKH6S40sGKk0wHdRsS0yv0H3RVCBU
O1qtnz3EL6LyMn62fqCsQG/X6F4jffkkZYQlFomBI25uBT2Me0nXYSB68w/3BhW3
ace3ZVSmChGwpNxXnzVCqufpgnUXr6+gLmlX0Iy3ZA6heF0i71Cb0NSXzHYwcYwC
GMR9FbKZ7MaHf3PDBE7/zG2oJQbF8NLVSBHEn2p62zfLNLpdOjE1Yf23HZpqJU5c
lLspega8ojTDPeuyk3N742CejgNBDDrK5Uf46lfwXz5z/3kqsm6MC6u6XPqDqwX9
w3YCDkJfOURhM/ouBK1D9f0u+q9h2l+1GhcrKLfJiDpILMJg1/YISykoNG4UV7mF
bviIqmaAIlfXWhFJZnt18gKgFVLd4/z/5idTrYzx3+YNQ7Hvlm96NA4XvSf29NeS
XB7JAgMBAAGjggJDMIICPzAJBgNVHRMEAjAAMA4GA1UdDwEB/wQEAwIFoDAdBgNV
HSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFGlYYidQ78OYTRrD
radVfEQYkW88MB8GA1UdIwQYMBaAFMQoXYtDj1K14+2sq9w4cYi4gYwDMB0GA1Ud
EQQWMBSCEmFhaS5waWstcG90c2RhbS5kZTCBmwYDVR0fBIGTMIGQMEagRKBChkBo
dHRwOi8vY2RwMS5wY2EuZGZuLmRlL2Rmbi12ZXJlaW4tY29tbXVuaXR5LWNhL3B1
Yi9jcmwvY2FjcmwuY3JsMEagRKBChkBodHRwOi8vY2RwMi5wY2EuZGZuLmRlL2Rm
bi12ZXJlaW4tY29tbXVuaXR5LWNhL3B1Yi9jcmwvY2FjcmwuY3JsMIHpBggrBgEF
BQcBAQSB3DCB2TAzBggrBgEFBQcwAYYnaHR0cDovL29jc3AucGNhLmRmbi5kZS9P
Q1NQLVNlcnZlci9PQ1NQMFAGCCsGAQUFBzAChkRodHRwOi8vY2RwMS5wY2EuZGZu
LmRlL2Rmbi12ZXJlaW4tY29tbXVuaXR5LWNhL3B1Yi9jYWNlcnQvY2FjZXJ0LmNy
dDBQBggrBgEFBQcwAoZEaHR0cDovL2NkcDIucGNhLmRmbi5kZS9kZm4tdmVyZWlu
LWNvbW11bml0eS1jYS9wdWIvY2FjZXJ0L2NhY2VydC5jcnQwGgYDVR0gBBMwETAP
Bg0rBgEEAYGtIYIsAgEHMA0GCSqGSIb3DQEBCwUAA4ICAQCTSP02dpJ39seFTjJe
tXXwzR4/9a2Q1DvMgZkVVVCkOqqa+pdsFRoygu+3fcUTrjNwyq7PEA40C3i8YP9f
+eFeehJro9l+jk+rkUSs8EC8R/1lonzrz9ALxqH3FKajU4mzj0/+FKi9NFObQ6of
pIe9WQAP+jEaM+AJ6o+6xdshXdhkmaBHF9h76PBCGv0GSAMS5bI9pI4d9wRu8zfY
CZiHZZHmsf/Dx0ERe8I/4IxbLHAx9ll1ku5F8MiXoWIG+Bfs1wh4U/Abq+UTRf+X
//Ja+CpfBVJGolb8ub/4tMO36XWZFRgMhgNDYoe/rjkWfzSlFPm9v/xJQ5cEa/m/
6f04KW1QIXiT2a/wRaA61T7NwnwyHY1Ql3leqA4YelCra76cjoU8ZwTfu7jOU8+M
CLez6IV2lOuhrix+0fBl3Vj5nkfJFAy10mz+m0swogAeiEypD/50rXbfImE/mkQ1
MXAAODlAVY2HmtXDlxJhacN+KTIEWpAAQUgwdgOuPes72dDsOZtGf/oMrZNYrmH3
SUvxg6cKO1QBewDZw1vf7lLauIM7jyguKaqSxZvpZG43KMCFVIFd35iAUazMO6yk
gVZeVAcu4U73IVOivPBRZbYUjnny6gY4ntykLwf7u6u6tM+r5aE6NxA3Epk9S1vD
BVkaR5AUm1Tx3zDHlgrTsgrthg==
			</ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIH7zCCBdegAwIBAgIMKNdfbV6z7LGJ9ZmCMA0GCSqGSIb3DQEBCwUAMIGVMQsw
CQYDVQQGEwJERTFFMEMGA1UECgw8VmVyZWluIHp1ciBGb2VyZGVydW5nIGVpbmVz
IERldXRzY2hlbiBGb3JzY2h1bmdzbmV0emVzIGUuIFYuMRAwDgYDVQQLDAdERk4t
UEtJMS0wKwYDVQQDDCRERk4tVmVyZWluIENvbW11bml0eSBJc3N1aW5nIENBIDIw
MjIwHhcNMjMwNzE5MTMxNTA5WhcNMjYxMDAxMTMxNTA5WjCBjTELMAkGA1UEBhMC
REUxFDASBgNVBAgMC0JyYW5kZW5idXJnMRAwDgYDVQQHDAdQb3RzZGFtMTkwNwYD
VQQKDDBQb3RzZGFtLUluc3RpdHV0IGZ1ZXIgS2xpbWFmb2xnZW5mb3JzY2h1bmcg
ZS4gVi4xGzAZBgNVBAMMEmFhaS5waWstcG90c2RhbS5kZTCCAiIwDQYJKoZIhvcN
AQEBBQADggIPADCCAgoCggIBAJN19nfvBo/HtkIJYzGtErWa/9IVZ8swksoFPTq7
wFkVTPRh7Q58xgTPe+Tm48ktjkdkvxGncdJHMQGjB57AevYC+X0u1j/PEA9gYU3D
+mKm4GDVDSmAFBjFqPaKMPtZHKSZW0g42QB5H83+QAERjRJKu6T8+aT6N6YBURL3
TgpvhqIgUmcvIM+wdIC+WrA3DP4QpP5DEDHZ1iVHhNt/3O9f262e6wyOpNTDgfu7
iFXFai8zh8NUNnOKuxkFoIfZjteuc/2OGACmKH6S40sGKk0wHdRsS0yv0H3RVCBU
O1qtnz3EL6LyMn62fqCsQG/X6F4jffkkZYQlFomBI25uBT2Me0nXYSB68w/3BhW3
ace3ZVSmChGwpNxXnzVCqufpgnUXr6+gLmlX0Iy3ZA6heF0i71Cb0NSXzHYwcYwC
GMR9FbKZ7MaHf3PDBE7/zG2oJQbF8NLVSBHEn2p62zfLNLpdOjE1Yf23HZpqJU5c
lLspega8ojTDPeuyk3N742CejgNBDDrK5Uf46lfwXz5z/3kqsm6MC6u6XPqDqwX9
w3YCDkJfOURhM/ouBK1D9f0u+q9h2l+1GhcrKLfJiDpILMJg1/YISykoNG4UV7mF
bviIqmaAIlfXWhFJZnt18gKgFVLd4/z/5idTrYzx3+YNQ7Hvlm96NA4XvSf29NeS
XB7JAgMBAAGjggJDMIICPzAJBgNVHRMEAjAAMA4GA1UdDwEB/wQEAwIFoDAdBgNV
HSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFGlYYidQ78OYTRrD
radVfEQYkW88MB8GA1UdIwQYMBaAFMQoXYtDj1K14+2sq9w4cYi4gYwDMB0GA1Ud
EQQWMBSCEmFhaS5waWstcG90c2RhbS5kZTCBmwYDVR0fBIGTMIGQMEagRKBChkBo
dHRwOi8vY2RwMS5wY2EuZGZuLmRlL2Rmbi12ZXJlaW4tY29tbXVuaXR5LWNhL3B1
Yi9jcmwvY2FjcmwuY3JsMEagRKBChkBodHRwOi8vY2RwMi5wY2EuZGZuLmRlL2Rm
bi12ZXJlaW4tY29tbXVuaXR5LWNhL3B1Yi9jcmwvY2FjcmwuY3JsMIHpBggrBgEF
BQcBAQSB3DCB2TAzBggrBgEFBQcwAYYnaHR0cDovL29jc3AucGNhLmRmbi5kZS9P
Q1NQLVNlcnZlci9PQ1NQMFAGCCsGAQUFBzAChkRodHRwOi8vY2RwMS5wY2EuZGZu
LmRlL2Rmbi12ZXJlaW4tY29tbXVuaXR5LWNhL3B1Yi9jYWNlcnQvY2FjZXJ0LmNy
dDBQBggrBgEFBQcwAoZEaHR0cDovL2NkcDIucGNhLmRmbi5kZS9kZm4tdmVyZWlu
LWNvbW11bml0eS1jYS9wdWIvY2FjZXJ0L2NhY2VydC5jcnQwGgYDVR0gBBMwETAP
Bg0rBgEEAYGtIYIsAgEHMA0GCSqGSIb3DQEBCwUAA4ICAQCTSP02dpJ39seFTjJe
tXXwzR4/9a2Q1DvMgZkVVVCkOqqa+pdsFRoygu+3fcUTrjNwyq7PEA40C3i8YP9f
+eFeehJro9l+jk+rkUSs8EC8R/1lonzrz9ALxqH3FKajU4mzj0/+FKi9NFObQ6of
pIe9WQAP+jEaM+AJ6o+6xdshXdhkmaBHF9h76PBCGv0GSAMS5bI9pI4d9wRu8zfY
CZiHZZHmsf/Dx0ERe8I/4IxbLHAx9ll1ku5F8MiXoWIG+Bfs1wh4U/Abq+UTRf+X
//Ja+CpfBVJGolb8ub/4tMO36XWZFRgMhgNDYoe/rjkWfzSlFPm9v/xJQ5cEa/m/
6f04KW1QIXiT2a/wRaA61T7NwnwyHY1Ql3leqA4YelCra76cjoU8ZwTfu7jOU8+M
CLez6IV2lOuhrix+0fBl3Vj5nkfJFAy10mz+m0swogAeiEypD/50rXbfImE/mkQ1
MXAAODlAVY2HmtXDlxJhacN+KTIEWpAAQUgwdgOuPes72dDsOZtGf/oMrZNYrmH3
SUvxg6cKO1QBewDZw1vf7lLauIM7jyguKaqSxZvpZG43KMCFVIFd35iAUazMO6yk
gVZeVAcu4U73IVOivPBRZbYUjnny6gY4ntykLwf7u6u6tM+r5aE6NxA3Epk9S1vD
BVkaR5AUm1Tx3zDHlgrTsgrthg==
			</ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://aai.pik-potsdam.de:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://aai.pik-potsdam.de:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>

        <!--
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://aai.pik-potsdam.de/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://aai.pik-potsdam.de/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://aai.pik-potsdam.de/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://aai.pik-potsdam.de:8443/idp/profile/SAML2/SOAP/SLO"/>
        -->
<!--RG -->
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://aai.pik-potsdam.de/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://aai.pik-potsdam.de/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://aai.pik-potsdam.de/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://aai.pik-potsdam.de:8443/idp/profile/SAML2/SOAP/SLO"/>


        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://aai.pik-potsdam.de/idp/profile/Shibboleth/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://aai.pik-potsdam.de/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://aai.pik-potsdam.de/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://aai.pik-potsdam.de/idp/profile/SAML2/Redirect/SSO"/>

<!--RG -->
       <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://aai.pik-potsdam.de/idp/profile/SAML2/SOAP/ECP"/>
       <!-- die fehlenden NameID-Formate hinzufügen -->
       <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
       <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
       <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>

    </IDPSSODescriptor>

    <!--RG
    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
-->
    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol">
        <Extensions>
            <shibmd:Scope regexp="false">pik-potsdam.de</shibmd:Scope>
        </Extensions>

	<!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIH7zCCBdegAwIBAgIMKNdfbV6z7LGJ9ZmCMA0GCSqGSIb3DQEBCwUAMIGVMQsw
CQYDVQQGEwJERTFFMEMGA1UECgw8VmVyZWluIHp1ciBGb2VyZGVydW5nIGVpbmVz
IERldXRzY2hlbiBGb3JzY2h1bmdzbmV0emVzIGUuIFYuMRAwDgYDVQQLDAdERk4t
UEtJMS0wKwYDVQQDDCRERk4tVmVyZWluIENvbW11bml0eSBJc3N1aW5nIENBIDIw
MjIwHhcNMjMwNzE5MTMxNTA5WhcNMjYxMDAxMTMxNTA5WjCBjTELMAkGA1UEBhMC
REUxFDASBgNVBAgMC0JyYW5kZW5idXJnMRAwDgYDVQQHDAdQb3RzZGFtMTkwNwYD
VQQKDDBQb3RzZGFtLUluc3RpdHV0IGZ1ZXIgS2xpbWFmb2xnZW5mb3JzY2h1bmcg
ZS4gVi4xGzAZBgNVBAMMEmFhaS5waWstcG90c2RhbS5kZTCCAiIwDQYJKoZIhvcN
AQEBBQADggIPADCCAgoCggIBAJN19nfvBo/HtkIJYzGtErWa/9IVZ8swksoFPTq7
wFkVTPRh7Q58xgTPe+Tm48ktjkdkvxGncdJHMQGjB57AevYC+X0u1j/PEA9gYU3D
+mKm4GDVDSmAFBjFqPaKMPtZHKSZW0g42QB5H83+QAERjRJKu6T8+aT6N6YBURL3
TgpvhqIgUmcvIM+wdIC+WrA3DP4QpP5DEDHZ1iVHhNt/3O9f262e6wyOpNTDgfu7
iFXFai8zh8NUNnOKuxkFoIfZjteuc/2OGACmKH6S40sGKk0wHdRsS0yv0H3RVCBU
O1qtnz3EL6LyMn62fqCsQG/X6F4jffkkZYQlFomBI25uBT2Me0nXYSB68w/3BhW3
ace3ZVSmChGwpNxXnzVCqufpgnUXr6+gLmlX0Iy3ZA6heF0i71Cb0NSXzHYwcYwC
GMR9FbKZ7MaHf3PDBE7/zG2oJQbF8NLVSBHEn2p62zfLNLpdOjE1Yf23HZpqJU5c
lLspega8ojTDPeuyk3N742CejgNBDDrK5Uf46lfwXz5z/3kqsm6MC6u6XPqDqwX9
w3YCDkJfOURhM/ouBK1D9f0u+q9h2l+1GhcrKLfJiDpILMJg1/YISykoNG4UV7mF
bviIqmaAIlfXWhFJZnt18gKgFVLd4/z/5idTrYzx3+YNQ7Hvlm96NA4XvSf29NeS
XB7JAgMBAAGjggJDMIICPzAJBgNVHRMEAjAAMA4GA1UdDwEB/wQEAwIFoDAdBgNV
HSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFGlYYidQ78OYTRrD
radVfEQYkW88MB8GA1UdIwQYMBaAFMQoXYtDj1K14+2sq9w4cYi4gYwDMB0GA1Ud
EQQWMBSCEmFhaS5waWstcG90c2RhbS5kZTCBmwYDVR0fBIGTMIGQMEagRKBChkBo
dHRwOi8vY2RwMS5wY2EuZGZuLmRlL2Rmbi12ZXJlaW4tY29tbXVuaXR5LWNhL3B1
Yi9jcmwvY2FjcmwuY3JsMEagRKBChkBodHRwOi8vY2RwMi5wY2EuZGZuLmRlL2Rm
bi12ZXJlaW4tY29tbXVuaXR5LWNhL3B1Yi9jcmwvY2FjcmwuY3JsMIHpBggrBgEF
BQcBAQSB3DCB2TAzBggrBgEFBQcwAYYnaHR0cDovL29jc3AucGNhLmRmbi5kZS9P
Q1NQLVNlcnZlci9PQ1NQMFAGCCsGAQUFBzAChkRodHRwOi8vY2RwMS5wY2EuZGZu
LmRlL2Rmbi12ZXJlaW4tY29tbXVuaXR5LWNhL3B1Yi9jYWNlcnQvY2FjZXJ0LmNy
dDBQBggrBgEFBQcwAoZEaHR0cDovL2NkcDIucGNhLmRmbi5kZS9kZm4tdmVyZWlu
LWNvbW11bml0eS1jYS9wdWIvY2FjZXJ0L2NhY2VydC5jcnQwGgYDVR0gBBMwETAP
Bg0rBgEEAYGtIYIsAgEHMA0GCSqGSIb3DQEBCwUAA4ICAQCTSP02dpJ39seFTjJe
tXXwzR4/9a2Q1DvMgZkVVVCkOqqa+pdsFRoygu+3fcUTrjNwyq7PEA40C3i8YP9f
+eFeehJro9l+jk+rkUSs8EC8R/1lonzrz9ALxqH3FKajU4mzj0/+FKi9NFObQ6of
pIe9WQAP+jEaM+AJ6o+6xdshXdhkmaBHF9h76PBCGv0GSAMS5bI9pI4d9wRu8zfY
CZiHZZHmsf/Dx0ERe8I/4IxbLHAx9ll1ku5F8MiXoWIG+Bfs1wh4U/Abq+UTRf+X
//Ja+CpfBVJGolb8ub/4tMO36XWZFRgMhgNDYoe/rjkWfzSlFPm9v/xJQ5cEa/m/
6f04KW1QIXiT2a/wRaA61T7NwnwyHY1Ql3leqA4YelCra76cjoU8ZwTfu7jOU8+M
CLez6IV2lOuhrix+0fBl3Vj5nkfJFAy10mz+m0swogAeiEypD/50rXbfImE/mkQ1
MXAAODlAVY2HmtXDlxJhacN+KTIEWpAAQUgwdgOuPes72dDsOZtGf/oMrZNYrmH3
SUvxg6cKO1QBewDZw1vf7lLauIM7jyguKaqSxZvpZG43KMCFVIFd35iAUazMO6yk
gVZeVAcu4U73IVOivPBRZbYUjnny6gY4ntykLwf7u6u6tM+r5aE6NxA3Epk9S1vD
BVkaR5AUm1Tx3zDHlgrTsgrthg==
			</ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIH7zCCBdegAwIBAgIMKNdfbV6z7LGJ9ZmCMA0GCSqGSIb3DQEBCwUAMIGVMQsw
CQYDVQQGEwJERTFFMEMGA1UECgw8VmVyZWluIHp1ciBGb2VyZGVydW5nIGVpbmVz
IERldXRzY2hlbiBGb3JzY2h1bmdzbmV0emVzIGUuIFYuMRAwDgYDVQQLDAdERk4t
UEtJMS0wKwYDVQQDDCRERk4tVmVyZWluIENvbW11bml0eSBJc3N1aW5nIENBIDIw
MjIwHhcNMjMwNzE5MTMxNTA5WhcNMjYxMDAxMTMxNTA5WjCBjTELMAkGA1UEBhMC
REUxFDASBgNVBAgMC0JyYW5kZW5idXJnMRAwDgYDVQQHDAdQb3RzZGFtMTkwNwYD
VQQKDDBQb3RzZGFtLUluc3RpdHV0IGZ1ZXIgS2xpbWFmb2xnZW5mb3JzY2h1bmcg
ZS4gVi4xGzAZBgNVBAMMEmFhaS5waWstcG90c2RhbS5kZTCCAiIwDQYJKoZIhvcN
AQEBBQADggIPADCCAgoCggIBAJN19nfvBo/HtkIJYzGtErWa/9IVZ8swksoFPTq7
wFkVTPRh7Q58xgTPe+Tm48ktjkdkvxGncdJHMQGjB57AevYC+X0u1j/PEA9gYU3D
+mKm4GDVDSmAFBjFqPaKMPtZHKSZW0g42QB5H83+QAERjRJKu6T8+aT6N6YBURL3
TgpvhqIgUmcvIM+wdIC+WrA3DP4QpP5DEDHZ1iVHhNt/3O9f262e6wyOpNTDgfu7
iFXFai8zh8NUNnOKuxkFoIfZjteuc/2OGACmKH6S40sGKk0wHdRsS0yv0H3RVCBU
O1qtnz3EL6LyMn62fqCsQG/X6F4jffkkZYQlFomBI25uBT2Me0nXYSB68w/3BhW3
ace3ZVSmChGwpNxXnzVCqufpgnUXr6+gLmlX0Iy3ZA6heF0i71Cb0NSXzHYwcYwC
GMR9FbKZ7MaHf3PDBE7/zG2oJQbF8NLVSBHEn2p62zfLNLpdOjE1Yf23HZpqJU5c
lLspega8ojTDPeuyk3N742CejgNBDDrK5Uf46lfwXz5z/3kqsm6MC6u6XPqDqwX9
w3YCDkJfOURhM/ouBK1D9f0u+q9h2l+1GhcrKLfJiDpILMJg1/YISykoNG4UV7mF
bviIqmaAIlfXWhFJZnt18gKgFVLd4/z/5idTrYzx3+YNQ7Hvlm96NA4XvSf29NeS
XB7JAgMBAAGjggJDMIICPzAJBgNVHRMEAjAAMA4GA1UdDwEB/wQEAwIFoDAdBgNV
HSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFGlYYidQ78OYTRrD
radVfEQYkW88MB8GA1UdIwQYMBaAFMQoXYtDj1K14+2sq9w4cYi4gYwDMB0GA1Ud
EQQWMBSCEmFhaS5waWstcG90c2RhbS5kZTCBmwYDVR0fBIGTMIGQMEagRKBChkBo
dHRwOi8vY2RwMS5wY2EuZGZuLmRlL2Rmbi12ZXJlaW4tY29tbXVuaXR5LWNhL3B1
Yi9jcmwvY2FjcmwuY3JsMEagRKBChkBodHRwOi8vY2RwMi5wY2EuZGZuLmRlL2Rm
bi12ZXJlaW4tY29tbXVuaXR5LWNhL3B1Yi9jcmwvY2FjcmwuY3JsMIHpBggrBgEF
BQcBAQSB3DCB2TAzBggrBgEFBQcwAYYnaHR0cDovL29jc3AucGNhLmRmbi5kZS9P
Q1NQLVNlcnZlci9PQ1NQMFAGCCsGAQUFBzAChkRodHRwOi8vY2RwMS5wY2EuZGZu
LmRlL2Rmbi12ZXJlaW4tY29tbXVuaXR5LWNhL3B1Yi9jYWNlcnQvY2FjZXJ0LmNy
dDBQBggrBgEFBQcwAoZEaHR0cDovL2NkcDIucGNhLmRmbi5kZS9kZm4tdmVyZWlu
LWNvbW11bml0eS1jYS9wdWIvY2FjZXJ0L2NhY2VydC5jcnQwGgYDVR0gBBMwETAP
Bg0rBgEEAYGtIYIsAgEHMA0GCSqGSIb3DQEBCwUAA4ICAQCTSP02dpJ39seFTjJe
tXXwzR4/9a2Q1DvMgZkVVVCkOqqa+pdsFRoygu+3fcUTrjNwyq7PEA40C3i8YP9f
+eFeehJro9l+jk+rkUSs8EC8R/1lonzrz9ALxqH3FKajU4mzj0/+FKi9NFObQ6of
pIe9WQAP+jEaM+AJ6o+6xdshXdhkmaBHF9h76PBCGv0GSAMS5bI9pI4d9wRu8zfY
CZiHZZHmsf/Dx0ERe8I/4IxbLHAx9ll1ku5F8MiXoWIG+Bfs1wh4U/Abq+UTRf+X
//Ja+CpfBVJGolb8ub/4tMO36XWZFRgMhgNDYoe/rjkWfzSlFPm9v/xJQ5cEa/m/
6f04KW1QIXiT2a/wRaA61T7NwnwyHY1Ql3leqA4YelCra76cjoU8ZwTfu7jOU8+M
CLez6IV2lOuhrix+0fBl3Vj5nkfJFAy10mz+m0swogAeiEypD/50rXbfImE/mkQ1
MXAAODlAVY2HmtXDlxJhacN+KTIEWpAAQUgwdgOuPes72dDsOZtGf/oMrZNYrmH3
SUvxg6cKO1QBewDZw1vf7lLauIM7jyguKaqSxZvpZG43KMCFVIFd35iAUazMO6yk
gVZeVAcu4U73IVOivPBRZbYUjnny6gY4ntykLwf7u6u6tM+r5aE6NxA3Epk9S1vD
BVkaR5AUm1Tx3zDHlgrTsgrthg==
			</ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIH7zCCBdegAwIBAgIMKNdfbV6z7LGJ9ZmCMA0GCSqGSIb3DQEBCwUAMIGVMQsw
CQYDVQQGEwJERTFFMEMGA1UECgw8VmVyZWluIHp1ciBGb2VyZGVydW5nIGVpbmVz
IERldXRzY2hlbiBGb3JzY2h1bmdzbmV0emVzIGUuIFYuMRAwDgYDVQQLDAdERk4t
UEtJMS0wKwYDVQQDDCRERk4tVmVyZWluIENvbW11bml0eSBJc3N1aW5nIENBIDIw
MjIwHhcNMjMwNzE5MTMxNTA5WhcNMjYxMDAxMTMxNTA5WjCBjTELMAkGA1UEBhMC
REUxFDASBgNVBAgMC0JyYW5kZW5idXJnMRAwDgYDVQQHDAdQb3RzZGFtMTkwNwYD
VQQKDDBQb3RzZGFtLUluc3RpdHV0IGZ1ZXIgS2xpbWFmb2xnZW5mb3JzY2h1bmcg
ZS4gVi4xGzAZBgNVBAMMEmFhaS5waWstcG90c2RhbS5kZTCCAiIwDQYJKoZIhvcN
AQEBBQADggIPADCCAgoCggIBAJN19nfvBo/HtkIJYzGtErWa/9IVZ8swksoFPTq7
wFkVTPRh7Q58xgTPe+Tm48ktjkdkvxGncdJHMQGjB57AevYC+X0u1j/PEA9gYU3D
+mKm4GDVDSmAFBjFqPaKMPtZHKSZW0g42QB5H83+QAERjRJKu6T8+aT6N6YBURL3
TgpvhqIgUmcvIM+wdIC+WrA3DP4QpP5DEDHZ1iVHhNt/3O9f262e6wyOpNTDgfu7
iFXFai8zh8NUNnOKuxkFoIfZjteuc/2OGACmKH6S40sGKk0wHdRsS0yv0H3RVCBU
O1qtnz3EL6LyMn62fqCsQG/X6F4jffkkZYQlFomBI25uBT2Me0nXYSB68w/3BhW3
ace3ZVSmChGwpNxXnzVCqufpgnUXr6+gLmlX0Iy3ZA6heF0i71Cb0NSXzHYwcYwC
GMR9FbKZ7MaHf3PDBE7/zG2oJQbF8NLVSBHEn2p62zfLNLpdOjE1Yf23HZpqJU5c
lLspega8ojTDPeuyk3N742CejgNBDDrK5Uf46lfwXz5z/3kqsm6MC6u6XPqDqwX9
w3YCDkJfOURhM/ouBK1D9f0u+q9h2l+1GhcrKLfJiDpILMJg1/YISykoNG4UV7mF
bviIqmaAIlfXWhFJZnt18gKgFVLd4/z/5idTrYzx3+YNQ7Hvlm96NA4XvSf29NeS
XB7JAgMBAAGjggJDMIICPzAJBgNVHRMEAjAAMA4GA1UdDwEB/wQEAwIFoDAdBgNV
HSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFGlYYidQ78OYTRrD
radVfEQYkW88MB8GA1UdIwQYMBaAFMQoXYtDj1K14+2sq9w4cYi4gYwDMB0GA1Ud
EQQWMBSCEmFhaS5waWstcG90c2RhbS5kZTCBmwYDVR0fBIGTMIGQMEagRKBChkBo
dHRwOi8vY2RwMS5wY2EuZGZuLmRlL2Rmbi12ZXJlaW4tY29tbXVuaXR5LWNhL3B1
Yi9jcmwvY2FjcmwuY3JsMEagRKBChkBodHRwOi8vY2RwMi5wY2EuZGZuLmRlL2Rm
bi12ZXJlaW4tY29tbXVuaXR5LWNhL3B1Yi9jcmwvY2FjcmwuY3JsMIHpBggrBgEF
BQcBAQSB3DCB2TAzBggrBgEFBQcwAYYnaHR0cDovL29jc3AucGNhLmRmbi5kZS9P
Q1NQLVNlcnZlci9PQ1NQMFAGCCsGAQUFBzAChkRodHRwOi8vY2RwMS5wY2EuZGZu
LmRlL2Rmbi12ZXJlaW4tY29tbXVuaXR5LWNhL3B1Yi9jYWNlcnQvY2FjZXJ0LmNy
dDBQBggrBgEFBQcwAoZEaHR0cDovL2NkcDIucGNhLmRmbi5kZS9kZm4tdmVyZWlu
LWNvbW11bml0eS1jYS9wdWIvY2FjZXJ0L2NhY2VydC5jcnQwGgYDVR0gBBMwETAP
Bg0rBgEEAYGtIYIsAgEHMA0GCSqGSIb3DQEBCwUAA4ICAQCTSP02dpJ39seFTjJe
tXXwzR4/9a2Q1DvMgZkVVVCkOqqa+pdsFRoygu+3fcUTrjNwyq7PEA40C3i8YP9f
+eFeehJro9l+jk+rkUSs8EC8R/1lonzrz9ALxqH3FKajU4mzj0/+FKi9NFObQ6of
pIe9WQAP+jEaM+AJ6o+6xdshXdhkmaBHF9h76PBCGv0GSAMS5bI9pI4d9wRu8zfY
CZiHZZHmsf/Dx0ERe8I/4IxbLHAx9ll1ku5F8MiXoWIG+Bfs1wh4U/Abq+UTRf+X
//Ja+CpfBVJGolb8ub/4tMO36XWZFRgMhgNDYoe/rjkWfzSlFPm9v/xJQ5cEa/m/
6f04KW1QIXiT2a/wRaA61T7NwnwyHY1Ql3leqA4YelCra76cjoU8ZwTfu7jOU8+M
CLez6IV2lOuhrix+0fBl3Vj5nkfJFAy10mz+m0swogAeiEypD/50rXbfImE/mkQ1
MXAAODlAVY2HmtXDlxJhacN+KTIEWpAAQUgwdgOuPes72dDsOZtGf/oMrZNYrmH3
SUvxg6cKO1QBewDZw1vf7lLauIM7jyguKaqSxZvpZG43KMCFVIFd35iAUazMO6yk
gVZeVAcu4U73IVOivPBRZbYUjnny6gY4ntykLwf7u6u6tM+r5aE6NxA3Epk9S1vD
BVkaR5AUm1Tx3zDHlgrTsgrthg==
			</ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://aai.pik-potsdam.de:8443/idp/profile/SAML1/SOAP/AttributeQuery"/> 
<!--RG SAML2-Attribute-Service aktivieren -->
	<!-- <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://aai.pik-potsdam.de:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> -->
	<AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://aai.pik-potsdam.de:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> 
        <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->

        <!-- die fehlenden NameID-Formate hinzufügen -->
        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>


    </AttributeAuthorityDescriptor>




</EntityDescriptor>
