<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.     On Demand Metadata Generation available from the metadatagen plugin.
--> 
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" validUntil="2026-03-29T14:22:18.248Z" entityID="https://idp.lib.sfedu.ru/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">sfedu.ru</shibmd:Scope>
<!--
    Fill in the details for your IdP here 

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">A Name for the IdP at idp.lib.sfedu.ru</mdui:DisplayName>
                <mdui:Description xml:lang="en">Enter a description of your IdP at idp.lib.sfedu.ru</mdui:Description>
                <mdui:Logo height="80" width="80">https://idp.lib.sfedu.ru/Path/To/Logo.png</mdui:Logo>
            </mdui:UIInfo>
--> 
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel--> 
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDKzCCAhOgAwIBAgIUR4//rt3cnuQtDHwVN9oKz225LTgwDQYJKoZIhvcNAQEL
BQAwGzEZMBcGA1UEAwwQaWRwLmxpYi5zZmVkdS5ydTAeFw0xNzEyMjAxMjMyMjFa
Fw0zNzEyMjAxMjMyMjFaMBsxGTAXBgNVBAMMEGlkcC5saWIuc2ZlZHUucnUwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCJdJjUAA9l1WspwI819lpXP68t
VvINiHgEapxTKAjQktdpWgsuiC9pSG9KZ4bdf2Y2Sxxy118KposxtX/n1RxSxthg
oQd1thZr8y2XTXm5gmBXnO8A+21mjPORn2oij72nyMYVsECD0E+N45MVwBv1dIUn
3dHQUf1KYp8HEQqRyozM5tmLxwZW+r5s27lugFerl0OBLoVk1Ugor/+ABkSylJ6N
eHJO7BNRlfJP9y9kwF2d3fXaLES9pzGSZfUq3XYVNeuov6G6dATE7f4NMwKKqeuh
Dc0wtsvDIdcH7FOJW7jDVML6aiaNorA05VQRYz/55RyQlXuRmnFjIqdScndhAgMB
AAGjZzBlMB0GA1UdDgQWBBQMv8KmifpzTA55wor+1XK+YmJZGTBEBgNVHREEPTA7
ghBpZHAubGliLnNmZWR1LnJ1hidodHRwczovL2lkcC5saWIuc2ZlZHUucnUvaWRw
L3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBADJH6S2zQeMZ13K33vowN5MC
aniNjrNc1MtzAL+j69MDmvLOxDjdXmIdshVWqzxAdxTKCX/4LXrPiU/1ZvaqDOmd
9kds7TvNgnILrN4lExdqNJHVffVeD2bSc+FQvTdskh4kc5pGu07EcoMZiNghAMqz
ZtngVQ8bR7DZiuQ6F2QmxoxUxxAHaC+u5PWiHussgCN7TBgMna7hF9fdm+pth5k6
ioqryEYkMEdn0b+kNgxFxglZfTMe0ia5ISZ5h0wAA3WN/OTpMhJWG4VJXZ82o1V4
21RRFGDWWqCA8mnIsZtRveGD9Ixc435EcEWCDuJRXBULToF7xaFZpPjTQcxbZcg=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDKzCCAhOgAwIBAgIUetrU2HuPa/aRQnEleWWP61FXZKQwDQYJKoZIhvcNAQEL
BQAwGzEZMBcGA1UEAwwQaWRwLmxpYi5zZmVkdS5ydTAeFw0xNzEyMjAxMjMyMjBa
Fw0zNzEyMjAxMjMyMjBaMBsxGTAXBgNVBAMMEGlkcC5saWIuc2ZlZHUucnUwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQColW92HO5AMwaYFOrjMsMLg3ZS
NDfIoYkt7WMPQvGJqy43b5fSyEi8cjPswUfX21dPMetqB0BP1J6VY+4GGS+4O/8l
8Wv2OjLg0jzGOhsn29S4Z7+hIrhPv1xvf/T4UR01gjDYuDaoAzfTJvBBreusJYv/
Tkmv1snwYNcRbb2bxhGhJ4zve+oMWB+LQTLsPQi/DWa6I7LCbq8ZZfk2l3NWkZWe
ICSDuinOVz8+vlFNRhxNBGt+CvNou6ENEiOez7QTX5tPnpidLKFj1SEw9yxmQYNK
ukAHVPJ21R5ooKrzPjbaFc3uX2fjXYYGrKafIt02NU7R3CWFsF7TwsN/8GAPAgMB
AAGjZzBlMB0GA1UdDgQWBBR+I4w4xPBW/siagxR9SaRNJ1o79DBEBgNVHREEPTA7
ghBpZHAubGliLnNmZWR1LnJ1hidodHRwczovL2lkcC5saWIuc2ZlZHUucnUvaWRw
L3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBAD4FRzBLldv+ho4SPR2ERTxi
dA5IH2Kg5HKGRJk6B4vyS2PPrBwMJqviaVHwlDZfkdBoZ0/I4fXmBNBqP2ZSAswJ
CyCNaSvnXnCqdte+kCXslQrNfMV3nrG7/rhvEO0Uy1szdsvpOiyeiH55biytopBQ
Q1tzYF5bA4xBxYVfHLOrXXu+UqSsdY0qJgiCeLNDRcsQUvHYt7tPp4yuuz64M9/B
fipu7IlrArkdsKxXYExkTElOW1ELPKOxxDiR8/J4/2aAXODNfeZUDzh/i81aIjC1
leNEykjbxFDwWiUOQxDGMNZoYKynyTysg6T6shhcZ2dY/y5M0Z27hTbGz1ucU2Y=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDLDCCAhSgAwIBAgIVAP3q7n6LMAjPKNsdcG8EHgcTMdWxMA0GCSqGSIb3DQEB
CwUAMBsxGTAXBgNVBAMMEGlkcC5saWIuc2ZlZHUucnUwHhcNMTcxMjIwMTIzMjIw
WhcNMzcxMjIwMTIzMjIwWjAbMRkwFwYDVQQDDBBpZHAubGliLnNmZWR1LnJ1MIIB
IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkpebPWXTQME+cEXmR9I/ysW1
RTqKkm25mVC/leXHKN1octIEpJq9RdhHYztIHXkchUZRQquLxk1Iy6uuHcsmgX21
3btLGbXMAyCzDoiTTTq3QkINiu8FsfFE+FJXTwc565k/E7V7yTvqPfDU1USfJUH3
RPrcivg6P9PT+j1LfHqPCWu+n0oOzEaq5zKWSXLJyDqXbuFgjw1Z2YC69wF/JK1Q
ofyK3tkkW+hWg40S03XPZg0FQcM8gxvdjXBM96zOseS95uUYG1c8skDGVIAl/H6C
m4ETieJlk7ym6aJMyf7rwlCciufn7k6TSu3QrIDjWcig8bxTKRONwSujcVO35wID
AQABo2cwZTAdBgNVHQ4EFgQUNrnzMc99DmhvVMLv7h+gMInNA7IwRAYDVR0RBD0w
O4IQaWRwLmxpYi5zZmVkdS5ydYYnaHR0cHM6Ly9pZHAubGliLnNmZWR1LnJ1L2lk
cC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQBbgg4lECeUVQXaEd9CHP52
EcLlggTzcO5EmjYQ8CB+QD4szTksuh8NCoyXZdMtIflInOrB2I0F6YxatyYACHPL
35GteIzAdmiC3VPapaylEB1wjF9Z81AsQhtb0NhSMVLe9HGg+24qSNIvP2XeQKBA
RktAfoAVQrwesOYo8UNIerkWAG+r5CcNkN6vsZqHiB3Sp2gzAfxB/bABIxrz/+7v
bAuELR2FF5XXDrwPrdYetr0JNvlK4qRwr2dNKPU+24VNVqvo2HXy0SsFHVz+8hLX
jjCPNjL46ru8C293Kl6AZ0Tzp9sscwsn7DkXG+3HfsQXKGTWNYqlAMBAkOVVDBmh
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.lib.sfedu.ru:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>
        <!--<ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.lib.sfedu.ru:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
--> 
<!--
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.lib.sfedu.ru/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.lib.sfedu.ru:8443/idp/profile/SAML2/SOAP/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.lib.sfedu.ru/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.lib.sfedu.ru/idp/profile/SAML2/POST-SimpleSign/SLO"/>
--> 

        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://idp.lib.sfedu.ru/idp/profile/SAML2/Redirect/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://idp.lib.sfedu.ru/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://idp.lib.sfedu.ru/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <!--<SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.lib.sfedu.ru/idp/profile/Shibboleth/SSO"/>
--> 
    </IDPSSODescriptor>


<!--    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">sfedu.ru</shibmd:Scope>
        </Extensions>

        --> <!-- First signing certificate is BackChannel, the Second is FrontChannel-->  <!--
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDKzCCAhOgAwIBAgIUR4//rt3cnuQtDHwVN9oKz225LTgwDQYJKoZIhvcNAQEL
BQAwGzEZMBcGA1UEAwwQaWRwLmxpYi5zZmVkdS5ydTAeFw0xNzEyMjAxMjMyMjFa
Fw0zNzEyMjAxMjMyMjFaMBsxGTAXBgNVBAMMEGlkcC5saWIuc2ZlZHUucnUwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCJdJjUAA9l1WspwI819lpXP68t
VvINiHgEapxTKAjQktdpWgsuiC9pSG9KZ4bdf2Y2Sxxy118KposxtX/n1RxSxthg
oQd1thZr8y2XTXm5gmBXnO8A+21mjPORn2oij72nyMYVsECD0E+N45MVwBv1dIUn
3dHQUf1KYp8HEQqRyozM5tmLxwZW+r5s27lugFerl0OBLoVk1Ugor/+ABkSylJ6N
eHJO7BNRlfJP9y9kwF2d3fXaLES9pzGSZfUq3XYVNeuov6G6dATE7f4NMwKKqeuh
Dc0wtsvDIdcH7FOJW7jDVML6aiaNorA05VQRYz/55RyQlXuRmnFjIqdScndhAgMB
AAGjZzBlMB0GA1UdDgQWBBQMv8KmifpzTA55wor+1XK+YmJZGTBEBgNVHREEPTA7
ghBpZHAubGliLnNmZWR1LnJ1hidodHRwczovL2lkcC5saWIuc2ZlZHUucnUvaWRw
L3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBADJH6S2zQeMZ13K33vowN5MC
aniNjrNc1MtzAL+j69MDmvLOxDjdXmIdshVWqzxAdxTKCX/4LXrPiU/1ZvaqDOmd
9kds7TvNgnILrN4lExdqNJHVffVeD2bSc+FQvTdskh4kc5pGu07EcoMZiNghAMqz
ZtngVQ8bR7DZiuQ6F2QmxoxUxxAHaC+u5PWiHussgCN7TBgMna7hF9fdm+pth5k6
ioqryEYkMEdn0b+kNgxFxglZfTMe0ia5ISZ5h0wAA3WN/OTpMhJWG4VJXZ82o1V4
21RRFGDWWqCA8mnIsZtRveGD9Ixc435EcEWCDuJRXBULToF7xaFZpPjTQcxbZcg=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDKzCCAhOgAwIBAgIUetrU2HuPa/aRQnEleWWP61FXZKQwDQYJKoZIhvcNAQEL
BQAwGzEZMBcGA1UEAwwQaWRwLmxpYi5zZmVkdS5ydTAeFw0xNzEyMjAxMjMyMjBa
Fw0zNzEyMjAxMjMyMjBaMBsxGTAXBgNVBAMMEGlkcC5saWIuc2ZlZHUucnUwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQColW92HO5AMwaYFOrjMsMLg3ZS
NDfIoYkt7WMPQvGJqy43b5fSyEi8cjPswUfX21dPMetqB0BP1J6VY+4GGS+4O/8l
8Wv2OjLg0jzGOhsn29S4Z7+hIrhPv1xvf/T4UR01gjDYuDaoAzfTJvBBreusJYv/
Tkmv1snwYNcRbb2bxhGhJ4zve+oMWB+LQTLsPQi/DWa6I7LCbq8ZZfk2l3NWkZWe
ICSDuinOVz8+vlFNRhxNBGt+CvNou6ENEiOez7QTX5tPnpidLKFj1SEw9yxmQYNK
ukAHVPJ21R5ooKrzPjbaFc3uX2fjXYYGrKafIt02NU7R3CWFsF7TwsN/8GAPAgMB
AAGjZzBlMB0GA1UdDgQWBBR+I4w4xPBW/siagxR9SaRNJ1o79DBEBgNVHREEPTA7
ghBpZHAubGliLnNmZWR1LnJ1hidodHRwczovL2lkcC5saWIuc2ZlZHUucnUvaWRw
L3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBAD4FRzBLldv+ho4SPR2ERTxi
dA5IH2Kg5HKGRJk6B4vyS2PPrBwMJqviaVHwlDZfkdBoZ0/I4fXmBNBqP2ZSAswJ
CyCNaSvnXnCqdte+kCXslQrNfMV3nrG7/rhvEO0Uy1szdsvpOiyeiH55biytopBQ
Q1tzYF5bA4xBxYVfHLOrXXu+UqSsdY0qJgiCeLNDRcsQUvHYt7tPp4yuuz64M9/B
fipu7IlrArkdsKxXYExkTElOW1ELPKOxxDiR8/J4/2aAXODNfeZUDzh/i81aIjC1
leNEykjbxFDwWiUOQxDGMNZoYKynyTysg6T6shhcZ2dY/y5M0Z27hTbGz1ucU2Y=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDLDCCAhSgAwIBAgIVAP3q7n6LMAjPKNsdcG8EHgcTMdWxMA0GCSqGSIb3DQEB
CwUAMBsxGTAXBgNVBAMMEGlkcC5saWIuc2ZlZHUucnUwHhcNMTcxMjIwMTIzMjIw
WhcNMzcxMjIwMTIzMjIwWjAbMRkwFwYDVQQDDBBpZHAubGliLnNmZWR1LnJ1MIIB
IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkpebPWXTQME+cEXmR9I/ysW1
RTqKkm25mVC/leXHKN1octIEpJq9RdhHYztIHXkchUZRQquLxk1Iy6uuHcsmgX21
3btLGbXMAyCzDoiTTTq3QkINiu8FsfFE+FJXTwc565k/E7V7yTvqPfDU1USfJUH3
RPrcivg6P9PT+j1LfHqPCWu+n0oOzEaq5zKWSXLJyDqXbuFgjw1Z2YC69wF/JK1Q
ofyK3tkkW+hWg40S03XPZg0FQcM8gxvdjXBM96zOseS95uUYG1c8skDGVIAl/H6C
m4ETieJlk7ym6aJMyf7rwlCciufn7k6TSu3QrIDjWcig8bxTKRONwSujcVO35wID
AQABo2cwZTAdBgNVHQ4EFgQUNrnzMc99DmhvVMLv7h+gMInNA7IwRAYDVR0RBD0w
O4IQaWRwLmxpYi5zZmVkdS5ydYYnaHR0cHM6Ly9pZHAubGliLnNmZWR1LnJ1L2lk
cC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQBbgg4lECeUVQXaEd9CHP52
EcLlggTzcO5EmjYQ8CB+QD4szTksuh8NCoyXZdMtIflInOrB2I0F6YxatyYACHPL
35GteIzAdmiC3VPapaylEB1wjF9Z81AsQhtb0NhSMVLe9HGg+24qSNIvP2XeQKBA
RktAfoAVQrwesOYo8UNIerkWAG+r5CcNkN6vsZqHiB3Sp2gzAfxB/bABIxrz/+7v
bAuELR2FF5XXDrwPrdYetr0JNvlK4qRwr2dNKPU+24VNVqvo2HXy0SsFHVz+8hLX
jjCPNjL46ru8C293Kl6AZ0Tzp9sscwsn7DkXG+3HfsQXKGTWNYqlAMBAkOVVDBmh
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        --> <!--<AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.lib.sfedu.ru:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>-->  <!--
        --> <!--<AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.lib.sfedu.ru:8443/idp/profile/SAML2/SOAP/AttributeQuery"/>-->  <!--
        --> <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above-->  <!--

    </AttributeAuthorityDescriptor>--> 

</EntityDescriptor>
