<?xml version='1.0' encoding='UTF-8'?>
<ns0:EntityDescriptor xmlns:ns0="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ns1="http://www.w3.org/2000/09/xmldsig#" xmlns:ns2="urn:oasis:names:tc:SAML:metadata:attribute" xmlns:ns3="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:ns5="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:ns6="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" xmlns:ns7="urn:oasis:names:tc:SAML:metadata:ui" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" entityID="https://proxy.myaccessid.org/metadata/backend.xml" ID="id-aGKH1aVZmRhYcW3M3">
  <ns1:Signature Id="id-bf3ca84a-c46a-5068-9c9e-e853b5ec95d3">
    <ns1:SignedInfo>
      <ns1:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
      <ns1:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
      <ns1:Reference URI="#id-aGKH1aVZmRhYcW3M3">
        <ns1:Transforms>
          <ns1:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
          <ns1:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
        </ns1:Transforms>
        <ns1:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
        <ns1:DigestValue>8Oq8nIr1rP+UIsIlIvIHC44pAkk=</ns1:DigestValue>
      </ns1:Reference>
    </ns1:SignedInfo>
    <ns1:SignatureValue>lGy/rtzXccZygDCXxG61/7Q2JnsveFr82KBO6udZoMTq9A55+mYsOvOdp+qKMGCT
Z1fVZCCQmc7nF1LwIlOEISEvbubaqjh93l0gGhP67ebAo1lmfS09ZH8RGSwuFEo2
KVX0pMQzi2ByYVKi4WZaKye4QqulvBfxAsec5izWzZVFxrmpaxW1+PQoGFP+bXWy
f9o8ffO2thUky+t/2QjJv0dUdXFX3ujFoPt61oSb1TSq1Cc83eDaUydgRwOMUOTE
bNACH2lOuXtZDgteiIn4tREsD5+OV9XYdQeUS8ADbOpunoEWiJ9bxq6I3Sk82Z6/
gDgzf8BzWbxH6AFMa9bjFQ==</ns1:SignatureValue>
    <ns1:KeyInfo>
      <ns1:X509Data>
        <ns1:X509Certificate>MIIDPzCCAiegAwIBAgIUC9UQEJAjU0r+ghPcK0Zw7nxn5WQwDQYJKoZIhvcNAQELBQAwLzEtMCsGA1UEAwwkbXlhY2Nlc3NpZCBwcm9kIHByb3h5IHNhbWwyX2Zyb250ZW5kMB4XDTIxMDYwNjEyNTUzNFoXDTM4MDExNzEyNTUzNFowLzEtMCsGA1UEAwwkbXlhY2Nlc3NpZCBwcm9kIHByb3h5IHNhbWwyX2Zyb250ZW5kMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0bhBQHx6EfAWUxETZLiUkZ5Sv/2uoabB9fdKMwo9iypy3ydKDaHiKTmQm5ksndn++mwZSlCdKva/So7lq68i6srYzTIZUtTI0/Aa5AobUhBhvdRQ+hiDcT2dsTr3VZ4yKUYJ1HzhT6LJ4QY+9uvtSWPmX+5UvdZ3ew1bHe2sWDZcMXbSZX+QoOuNVjfdOQEMQTzsI0nr++sZ6yrJ9kpmohUbRodRpSkukD43cQB60W7ijT4sGl2/Z7v+hGK3g7Gf1oGqCjXIilLxRnGnAaeooLMQqRSJmrEunXz3jQ7i3oj3DG9+g1noXOq1peqPm6ryjzYrOuzn8WhkZ/X2/EhleQIDAQABo1MwUTAdBgNVHQ4EFgQUbNfHO76cMDQI4NOP7VJTg8GQqFkwHwYDVR0jBBgwFoAUbNfHO76cMDQI4NOP7VJTg8GQqFkwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEANILofqfS2uqk2S1SKoo60C/JZEM6tpRX5ieLqlgoa1Bhzsn5QhW9he4CCq+N7VaRZgayJ/nwtzXwNgPSDZi4d/oiAWazmPfpQkrEPCaiibigyfh3iTXZZvDBUfpm6TQdL1vWFCThhlJ04Gh/QtRVwh9b9CJGglF2x5wu8silKo+k231mxaI2s1uRUvHYu/8K5ehzcBYjfXiw5wRCqN0BjjW/LwAhA8B91qV5x62GFn/QBTYWqXjpu6WRD3h1TRMIuz2qWJtegBeks78isc3+Yoq8/wBMf6gzzhCZG6FVp5Axa2xH4DqztP//3pfY0cN+TduTmutxrVAjQkSOc82NRQ==</ns1:X509Certificate>
      </ns1:X509Data>
    </ns1:KeyInfo>
  </ns1:Signature>
  <ns0:Extensions>
    <ns2:EntityAttributes>
      <ns3:Attribute Name="urn:oasis:names:tc:SAML:profiles:subject-id:req" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
        <ns3:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xsi:type="xs:string">any</ns3:AttributeValue>
      </ns3:Attribute>
      <ns3:Attribute Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
        <ns3:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xsi:type="xs:string">http://www.geant.net/uri/dataprotection-code-of-conduct/v1</ns3:AttributeValue>
        <ns3:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xsi:type="xs:string">http://refeds.org/category/research-and-scholarship</ns3:AttributeValue>
      </ns3:Attribute>
    </ns2:EntityAttributes>
    <ns5:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
    <ns5:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
    <ns5:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
    <ns5:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/>
    <ns5:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/>
    <ns5:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/>
    <ns5:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/>
    <ns5:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
    <ns5:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
    <ns5:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
  </ns0:Extensions>
  <ns0:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" AuthnRequestsSigned="false" WantAssertionsSigned="false">
    <ns0:Extensions>
      <ns6:DiscoveryResponse Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://proxy.myaccessid.org/saml2sp/disco" index="1"/>
      <ns7:UIInfo>
        <ns7:DisplayName xml:lang="en">MyAccessID</ns7:DisplayName>
        <ns7:Description xml:lang="en">MyAccessID is a GÉANT service providing a common Identity Layer for Infrastructure Service Domains (ISDs) in Europe. It supports the EuroHPC Federation Platform, the European Open Science Cloud (EOSC) and Research Infrastructures.</ns7:Description>
        <ns7:Logo height="66" width="200">https://proxy.myaccessid.org/logos/myaccessid-logo-200x66.png</ns7:Logo>
        <ns7:Logo height="16" width="16">https://proxy.myaccessid.org/logos/myaccessid-logo-16x16.png</ns7:Logo>
        <ns7:InformationURL xml:lang="en">https://wiki.geant.org/display/MyAccessID</ns7:InformationURL>
        <ns7:PrivacyStatementURL xml:lang="en">https://wiki.geant.org/display/MyAccessID/Privacy+Notice</ns7:PrivacyStatementURL>
      </ns7:UIInfo>
    </ns0:Extensions>
    <ns0:KeyDescriptor use="signing">
      <ns1:KeyInfo>
        <ns1:X509Data>
          <ns1:X509Certificate>MIIDPTCCAiWgAwIBAgIUId2Y+GYd2i+t22imQEkliI6rKhcwDQYJKoZIhvcNAQELBQAwLjEsMCoGA1UEAwwjbXlhY2Nlc3NpZCBwcm9kIHByb3h5IHNhbWwyX2JhY2tlbmQwHhcNMjEwNjA2MTI1NTM0WhcNMzgwMTE3MTI1NTM0WjAuMSwwKgYDVQQDDCNteWFjY2Vzc2lkIHByb2QgcHJveHkgc2FtbDJfYmFja2VuZDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKFiyyDndbxTuy1AJPOFlq3ZIGrVkE5soKWVPVZuQTorW4/MDynbyNU1gR2ZlCa0jXdzf3Fc1xae+bej9c5cxKgUZXCSRnNPY0AiWkhN4XJ1mC+lkf4TS4uytoFaW20vYj+xQRhtY+KDpRTx7Cw3JvfFOcNi8vbu5ftkeluomg1dRu5Jmfd3nHp/xgaX6MWWoQpICvL3q2gtCo8ucx0HflXiwnq0hTS3heiS3XIIgkukETETq1hH0D3UweAQdzM27xCQnRJECsSD+d8qV56Ec08cZ57FnBYF4X29obhXYX2SidMdi4yhq7ZfXKNVhV3pkgh2V0e3MeoXVzALyu5hbrcCAwEAAaNTMFEwHQYDVR0OBBYEFKVd27g5az0MJKhskU1tANDqK8SHMB8GA1UdIwQYMBaAFKVd27g5az0MJKhskU1tANDqK8SHMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAAV9/LPR/2waHcfI659LAOIjxxKu/eHDeuQyE7+YqyHKhup7GO0HLxwV02RI9c8Qor1LK8IMKzCGhwWR6sAH3g042cKdBTyr2jOWuavgmL0leT0BG4yiVVZpwjn/hpCnWDMMvru7R+l6aH/1UuYRvRAa4zVcoxBO9vJKjNsBNEnmI7gEfc2Blmpg1TVSakrnlMyDLR/S2cQ/KMKuR3b+tz+zSApqZp5rQ8Ze5pjKhDwODHpEn8umD26WtjiJil0NcyH6nkntp85s7GiSCobB0G6KsMwgE3PQkUPQp4QwfwsO6YMu5H4edloVdAaLTZT38HMiUijYYNKIerZDi4ES7po=</ns1:X509Certificate>
        </ns1:X509Data>
      </ns1:KeyInfo>
    </ns0:KeyDescriptor>
    <ns0:KeyDescriptor use="encryption">
      <ns1:KeyInfo>
        <ns1:X509Data>
          <ns1:X509Certificate>MIIDPTCCAiWgAwIBAgIUId2Y+GYd2i+t22imQEkliI6rKhcwDQYJKoZIhvcNAQELBQAwLjEsMCoGA1UEAwwjbXlhY2Nlc3NpZCBwcm9kIHByb3h5IHNhbWwyX2JhY2tlbmQwHhcNMjEwNjA2MTI1NTM0WhcNMzgwMTE3MTI1NTM0WjAuMSwwKgYDVQQDDCNteWFjY2Vzc2lkIHByb2QgcHJveHkgc2FtbDJfYmFja2VuZDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKFiyyDndbxTuy1AJPOFlq3ZIGrVkE5soKWVPVZuQTorW4/MDynbyNU1gR2ZlCa0jXdzf3Fc1xae+bej9c5cxKgUZXCSRnNPY0AiWkhN4XJ1mC+lkf4TS4uytoFaW20vYj+xQRhtY+KDpRTx7Cw3JvfFOcNi8vbu5ftkeluomg1dRu5Jmfd3nHp/xgaX6MWWoQpICvL3q2gtCo8ucx0HflXiwnq0hTS3heiS3XIIgkukETETq1hH0D3UweAQdzM27xCQnRJECsSD+d8qV56Ec08cZ57FnBYF4X29obhXYX2SidMdi4yhq7ZfXKNVhV3pkgh2V0e3MeoXVzALyu5hbrcCAwEAAaNTMFEwHQYDVR0OBBYEFKVd27g5az0MJKhskU1tANDqK8SHMB8GA1UdIwQYMBaAFKVd27g5az0MJKhskU1tANDqK8SHMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAAV9/LPR/2waHcfI659LAOIjxxKu/eHDeuQyE7+YqyHKhup7GO0HLxwV02RI9c8Qor1LK8IMKzCGhwWR6sAH3g042cKdBTyr2jOWuavgmL0leT0BG4yiVVZpwjn/hpCnWDMMvru7R+l6aH/1UuYRvRAa4zVcoxBO9vJKjNsBNEnmI7gEfc2Blmpg1TVSakrnlMyDLR/S2cQ/KMKuR3b+tz+zSApqZp5rQ8Ze5pjKhDwODHpEn8umD26WtjiJil0NcyH6nkntp85s7GiSCobB0G6KsMwgE3PQkUPQp4QwfwsO6YMu5H4edloVdAaLTZT38HMiUijYYNKIerZDi4ES7po=</ns1:X509Certificate>
        </ns1:X509Data>
      </ns1:KeyInfo>
    </ns0:KeyDescriptor>
    <ns0:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</ns0:NameIDFormat>
    <ns0:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</ns0:NameIDFormat>
    <ns0:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://proxy.myaccessid.org/saml2sp/acs/post" index="1"/>
    <ns0:AttributeConsumingService index="1">
      <ns0:ServiceName xml:lang="en">MyAccessID</ns0:ServiceName>
      <ns0:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.13" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonUniqueId" isRequired="true"/>
      <ns0:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonTargetedID" isRequired="true"/>
      <ns0:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonPrincipalName" isRequired="true"/>
      <ns0:RequestedAttribute Name="urn:oid:2.5.4.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="cn" isRequired="true"/>
      <ns0:RequestedAttribute Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="displayName" isRequired="true"/>
      <ns0:RequestedAttribute Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="sn" isRequired="true"/>
      <ns0:RequestedAttribute Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="givenName" isRequired="true"/>
      <ns0:RequestedAttribute Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="mail" isRequired="true"/>
      <ns0:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonScopedAffiliation" isRequired="true"/>
      <ns0:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonAssurance" isRequired="true"/>
      <ns0:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.25178.1.2.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="schacHomeOrganization" isRequired="true"/>
      <ns0:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.7" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonEntitlement" isRequired="false"/>
      <ns0:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.25178.4.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="voPersonID" isRequired="false"/>
      <ns0:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.25178.4.1.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="voPersonExternalAffiliation" isRequired="false"/>
    </ns0:AttributeConsumingService>
  </ns0:SPSSODescriptor>
  <ns0:Organization>
    <ns0:OrganizationName xml:lang="en">GEANT</ns0:OrganizationName>
    <ns0:OrganizationDisplayName xml:lang="en">GEANT</ns0:OrganizationDisplayName>
    <ns0:OrganizationURL xml:lang="en">https://www.geant.org</ns0:OrganizationURL>
  </ns0:Organization>
  <ns0:ContactPerson contactType="technical">
    <ns0:GivenName>MyAccessID support</ns0:GivenName>
    <ns0:EmailAddress>mailto:support@myaccessid.org</ns0:EmailAddress>
  </ns0:ContactPerson>
  <ns0:ContactPerson contactType="administrative">
    <ns0:GivenName>MyAccessID support</ns0:GivenName>
    <ns0:EmailAddress>mailto:support@myaccessid.org</ns0:EmailAddress>
  </ns0:ContactPerson>
  <ns0:ContactPerson contactType="support">
    <ns0:GivenName>MyAccessID support</ns0:GivenName>
    <ns0:EmailAddress>mailto:support@myaccessid.org</ns0:EmailAddress>
  </ns0:ContactPerson>
</ns0:EntityDescriptor>
