<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" entityID="https://idp.lincoln.ac.nz/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">lincoln.ac.nz</shibmd:Scope>
            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">Lincoln University</mdui:DisplayName>
                <mdui:Description xml:lang="en">IDP for Lincoln University (NZ) Staff, Postgraduates and Undergraduates</mdui:Description>
            </mdui:UIInfo>
<!--
    Fill in the details for your IdP here 

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">A Name for the IdP at idp.lincoln.ac.nz</mdui:DisplayName>
                <mdui:Description xml:lang="en">Enter a description of your IdP at idp.lincoln.ac.nz</mdui:Description>
                <mdui:Logo height="80" width="80">https://idp.lincoln.ac.nz/Path/To/Logo.png</mdui:Logo>
            </mdui:UIInfo>
-->

        </Extensions>

        <!-- original V2 certificiate -->
        <KeyDescriptor use="signing">
          <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
            <ds:X509Data>
              <ds:X509Certificate>
MIIDLzCCAhegAwIBAgIUEjuXYW8HjpQVhLDXc+sr5LY/PRswDQYJKoZIhvcNAQEF
BQAwHDEaMBgGA1UEAxMRaWRwLmxpbmNvbG4uYWMubnowHhcNMTAwMjA5MjIwNjMw
WhcNMzAwMjA5MjIwNjMwWjAcMRowGAYDVQQDExFpZHAubGluY29sbi5hYy5uejCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKY9WULadSfPUvPa0gHUre+9
z9pmpuL7w+2sjX05L6JTrQyp0BAlPAb3c9ynlP14mO3cEivmvAekeMj6Dxre4Cv8
4RUlTknnkuT9JKh5ANO4o1p9rcYKt+QWojGS/ftTx+V5aDATCg273WZCBd9z4/I8
oshY/PcHXIDfract1dHrC14ObC6KXWC63S40IrSzTRdjRZ3sV9KG8Fq57EHdgC9V
8176GPaGR0jRH9luDpZ0HV2TMkXHNoIw3DWGkaZyS9y5Y3/Rybp43rAbqp2KpGBc
JfErUyMBoez04mf3GYnBAlnU9YNxitl+bg/kqHjahOYjI/iVZcsd0o+Mu/UvtO8C
AwEAAaNpMGcwRgYDVR0RBD8wPYIRaWRwLmxpbmNvbG4uYWMubnqGKGh0dHBzOi8v
aWRwLmxpbmNvbG4uYWMubnovaWRwL3NoaWJib2xldGgwHQYDVR0OBBYEFLt90GJo
tAFIg/bFoDXYSpdFJG40MA0GCSqGSIb3DQEBBQUAA4IBAQCcwhcKfMtspExQxrw+
U4qFLziMhRw6p7XFk+PPFUimfKcymirBvoO770f8G92yvAIpKZSOUBHZRcBB6EXG
1Rswb1b09u3LuXhfEpk3IF3b61lasT27qMIHXvoG18g4nD14X0ObVMmyRJ9YT1n/
3vXM8CUwbOF8PBpVtJZ0ClHMX1ak0gldjD2wWRFz2mqLSkYSu7SHt/4/Xqt6JbyO
QhGp4/SqBrh7xkacxFGzoAzoEmHnMS7EROtzSYNZ+/ymsM0I4ctnAXvuUPA8i2yN
5J0HzckvC3cN+K8n9gEQZEDoZapokBbSCAn7ITMeTlzc3rrinDA/FBcDsVqyqkdG
jDrw
              </ds:X509Certificate>
            </ds:X509Data>
          </ds:KeyInfo>
        </KeyDescriptor>

        <!-- new V3 backchannel certificate - unused
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDLzCCAhegAwIBAgIUG4W2rvV6eSSFGAa2fum8BeYskuMwDQYJKoZIhvcNAQEL
BQAwHDEaMBgGA1UEAwwRaWRwLmxpbmNvbG4uYWMubnowHhcNMTYwNzI3MjM0NDQy
WhcNMzYwNzI3MjM0NDQyWjAcMRowGAYDVQQDDBFpZHAubGluY29sbi5hYy5uejCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALnyd284BkPyST+Cw8FhPYBH
EYtt9uWASVgYqwfdl8dma8QZ9iuX/KojA/4exSaHZ5WkZ60kSuDZaWPt+/T9+J+n
4qc079sexqlIPHE/BBYwPOhC3GPoNJWaIMg6AXojtzxd8Vwvqn8jOZ4xfESWop6M
iFb4CtEorMelkx1Xvmpss6U+FQ1N790eErJdC88QMr/LRS4qHWUo+R99fEp8f0w6
r6KXSKr6jwX4nkMDgytGoDP8mNZsjkm8VtI6dgp1Dltyn4YT8sbj1ZBMPyy5GnFc
zqKqinnPxdiZ6vChYljISIFOuej3jOkx641JeQ0wh+lgBXK7JhAfs4pFBL5bh/cC
AwEAAaNpMGcwHQYDVR0OBBYEFAViHv3ti5lr1jJASj+2AheMhqzkMEYGA1UdEQQ/
MD2CEWlkcC5saW5jb2xuLmFjLm56hihodHRwczovL2lkcC5saW5jb2xuLmFjLm56
L2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQByGGpG5r79B1yknihG
Fj08bsIlWOH9wxL650sArpOlGDQZ77XDO/EjFazGclYTGoVvqs49AHlEJsVA9tss
5mQtwjvZ0+0eDBf4ygKbaDvSSyypaMtvm9mhRvMM7OFz3evJNK8fkKpAzkCIsdl5
ujuGT4R/7UI+edfohPjYxQmflgN+fuMyRnVtM2/PK2+IxZiL6e99BKPbFs6sRQtX
nPb4cBACTUk+sLa7Tk0S4pEl8TqV5qRG9WTsu9EzuJfDY3TpfT4LnmxGMVYfysOY
/o8xRRsKbHbCyjFKXuHus2UycG4JgH8ccIHA4+wcva/UrcOGmJQFqVRgDdSFDHG5
xKKE
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        -->
        <!-- new V3 signing certificate - unused
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDLzCCAhegAwIBAgIUU0XACHLeRIYsXJrsg5KbqRGtsbowDQYJKoZIhvcNAQEL
BQAwHDEaMBgGA1UEAwwRaWRwLmxpbmNvbG4uYWMubnowHhcNMTYwNzI3MjM0NDQw
WhcNMzYwNzI3MjM0NDQwWjAcMRowGAYDVQQDDBFpZHAubGluY29sbi5hYy5uejCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMMqyv26Ne6svFxn249sSb//
j3qktLOBdZ2at83Run5UVcIDxcqZmeaWwdw3EDPmtzzS8G18KQR3Io7Expwdxy7D
sVri3mn+ExxsGp5YPjr6ZIA8R2yd6rNWp2Q5vbJbh2iHhv/AH2JPXWDr18vIRMnj
/2y39kmFznle/IhvxafrTGCEuROEICzPMcVu9JBukagZXs3DOc4UlEe8zNCIHVhy
380PL0ajfGZOO7V9lKjKJ9KNhc1QQHLU0Wca9MjVpuV0GqA3UXLzvEttYzvosn66
NhoWMpqpdfMW6+guQPqdt7GPxofd5Uh9EMzfEKn0wT6PzgkjVB8le9UNRC/pjMEC
AwEAAaNpMGcwHQYDVR0OBBYEFJClIwROGSqBfMlxw4qdlyZEm1UCMEYGA1UdEQQ/
MD2CEWlkcC5saW5jb2xuLmFjLm56hihodHRwczovL2lkcC5saW5jb2xuLmFjLm56
L2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQCjoC6XFPnzPf0NJ6tm
p8kdR7ZsSxbIWS/uAQg2YvU5XhZeh9yK9RIBkiLylUcJDxQQOurZNNpRtQ75GBrF
eBhQ0alSTiM+i40eCfCMJWPZZsHZEesIB5Z2NSG9+oEX4Dh7yt85K+IopMdBIQZP
WB3w41v091qANLGikKaLR+sp4ISWr/Zj/chARUR5ddcscnUsM22MMr7XWVDEMdPs
bJet16pQzASGJ7bBfijYE1A/OwZVEgyWD5fwd0dQzOZyPBCsN+9+nz8+F+Dz2y2B
mj/ZUtevDTsv0zCN5fe1vuSvfE/QXog1A5uDHGzZs5clJ1l940GPEP2wHs7bo2Dp
9QsJ
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        -->
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDLzCCAhegAwIBAgIUDwXUH+y2xM14JO2JOJ8MqHIgYWIwDQYJKoZIhvcNAQEL
BQAwHDEaMBgGA1UEAwwRaWRwLmxpbmNvbG4uYWMubnowHhcNMTYwNzI3MjM0NDQx
WhcNMzYwNzI3MjM0NDQxWjAcMRowGAYDVQQDDBFpZHAubGluY29sbi5hYy5uejCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMmhKpBSQaG76fQpokTXiRrB
sIKw7pZJPgd3Gv0/0benjbRmvpRt5CAiNgdtsnALVbIVQfceDh+kaR6NRwW8O71+
PnnfyirTQnn9akFsZ6IRn7+SF/k45lqPOhotcUoNrYrAOSTE5WniD+g/axz5K4ju
XbW41Aui6Hh5GTmTQ6rcaCzu+jH+0gzqrf7lJHyfLhzxxuX3rFip0Df/nTJpGaKr
VvN2cO+apQh0q3kI5l3jG47WmABN6wTSswyJRLjCInXjYb/k+o1nAGSQDtxKxlhb
09prHroewOLpvWGCoi8RKamn/qGU9KoRkR1rdOj9svrsFaqERvAZSCiaxfoOKZ8C
AwEAAaNpMGcwHQYDVR0OBBYEFJqrQMtLRfBLafROG8wIU/z3Xb6KMEYGA1UdEQQ/
MD2CEWlkcC5saW5jb2xuLmFjLm56hihodHRwczovL2lkcC5saW5jb2xuLmFjLm56
L2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQB71LgQ76tcn1Iprlb7
0bMB3GZVLs3QRR1fF2ss3KvZHzj7mN44BDUiya08m0sQAFGbQlS0Aal1ulNdzfJO
uHPX34qfrDGSjzeTBSoTxAx3bwk+4mfeNyY9p3GTdLZupCinU87y4ODBnzH0ZfvZ
DTjw7zwalIEwEA0F0wbsb7WeKnl4bSlkf67fsxC8hVdXnXXRjQdOF4xEnqZnSQYq
ubD7BErygXjPZXgw5oXYqYFC78txxOWlStmXzM5x/y/qQ9XKLLDCIsr404/mkmJ2
7Vzrzng9unPIMFSwhIvqdNZsaak56uu/xPe2wDYr/1Eq/3kXlcBKAVn2225EwMN4
WW6t
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.lincoln.ac.nz:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.lincoln.ac.nz:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>

        <!-- uncommented by Vlad Mencl 2016-08-10 -->
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.lincoln.ac.nz/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.lincoln.ac.nz/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.lincoln.ac.nz/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.lincoln.ac.nz:8443/idp/profile/SAML2/SOAP/SLO"/>

        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>

        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.lincoln.ac.nz/idp/profile/Shibboleth/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.lincoln.ac.nz/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.lincoln.ac.nz/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.lincoln.ac.nz/idp/profile/SAML2/Redirect/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.lincoln.ac.nz/idp/profile/SAML2/SOAP/ECP" />
    </IDPSSODescriptor>


    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">lincoln.ac.nz</shibmd:Scope>
        </Extensions>

        <!-- original V2 certificiate -->
        <KeyDescriptor use="signing">
          <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
            <ds:X509Data>
              <ds:X509Certificate>
MIIDLzCCAhegAwIBAgIUEjuXYW8HjpQVhLDXc+sr5LY/PRswDQYJKoZIhvcNAQEF
BQAwHDEaMBgGA1UEAxMRaWRwLmxpbmNvbG4uYWMubnowHhcNMTAwMjA5MjIwNjMw
WhcNMzAwMjA5MjIwNjMwWjAcMRowGAYDVQQDExFpZHAubGluY29sbi5hYy5uejCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKY9WULadSfPUvPa0gHUre+9
z9pmpuL7w+2sjX05L6JTrQyp0BAlPAb3c9ynlP14mO3cEivmvAekeMj6Dxre4Cv8
4RUlTknnkuT9JKh5ANO4o1p9rcYKt+QWojGS/ftTx+V5aDATCg273WZCBd9z4/I8
oshY/PcHXIDfract1dHrC14ObC6KXWC63S40IrSzTRdjRZ3sV9KG8Fq57EHdgC9V
8176GPaGR0jRH9luDpZ0HV2TMkXHNoIw3DWGkaZyS9y5Y3/Rybp43rAbqp2KpGBc
JfErUyMBoez04mf3GYnBAlnU9YNxitl+bg/kqHjahOYjI/iVZcsd0o+Mu/UvtO8C
AwEAAaNpMGcwRgYDVR0RBD8wPYIRaWRwLmxpbmNvbG4uYWMubnqGKGh0dHBzOi8v
aWRwLmxpbmNvbG4uYWMubnovaWRwL3NoaWJib2xldGgwHQYDVR0OBBYEFLt90GJo
tAFIg/bFoDXYSpdFJG40MA0GCSqGSIb3DQEBBQUAA4IBAQCcwhcKfMtspExQxrw+
U4qFLziMhRw6p7XFk+PPFUimfKcymirBvoO770f8G92yvAIpKZSOUBHZRcBB6EXG
1Rswb1b09u3LuXhfEpk3IF3b61lasT27qMIHXvoG18g4nD14X0ObVMmyRJ9YT1n/
3vXM8CUwbOF8PBpVtJZ0ClHMX1ak0gldjD2wWRFz2mqLSkYSu7SHt/4/Xqt6JbyO
QhGp4/SqBrh7xkacxFGzoAzoEmHnMS7EROtzSYNZ+/ymsM0I4ctnAXvuUPA8i2yN
5J0HzckvC3cN+K8n9gEQZEDoZapokBbSCAn7ITMeTlzc3rrinDA/FBcDsVqyqkdG
jDrw
              </ds:X509Certificate>
            </ds:X509Data>
          </ds:KeyInfo>
        </KeyDescriptor>

        <!-- new V3 backchannel certificate - unused
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDLzCCAhegAwIBAgIUG4W2rvV6eSSFGAa2fum8BeYskuMwDQYJKoZIhvcNAQEL
BQAwHDEaMBgGA1UEAwwRaWRwLmxpbmNvbG4uYWMubnowHhcNMTYwNzI3MjM0NDQy
WhcNMzYwNzI3MjM0NDQyWjAcMRowGAYDVQQDDBFpZHAubGluY29sbi5hYy5uejCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALnyd284BkPyST+Cw8FhPYBH
EYtt9uWASVgYqwfdl8dma8QZ9iuX/KojA/4exSaHZ5WkZ60kSuDZaWPt+/T9+J+n
4qc079sexqlIPHE/BBYwPOhC3GPoNJWaIMg6AXojtzxd8Vwvqn8jOZ4xfESWop6M
iFb4CtEorMelkx1Xvmpss6U+FQ1N790eErJdC88QMr/LRS4qHWUo+R99fEp8f0w6
r6KXSKr6jwX4nkMDgytGoDP8mNZsjkm8VtI6dgp1Dltyn4YT8sbj1ZBMPyy5GnFc
zqKqinnPxdiZ6vChYljISIFOuej3jOkx641JeQ0wh+lgBXK7JhAfs4pFBL5bh/cC
AwEAAaNpMGcwHQYDVR0OBBYEFAViHv3ti5lr1jJASj+2AheMhqzkMEYGA1UdEQQ/
MD2CEWlkcC5saW5jb2xuLmFjLm56hihodHRwczovL2lkcC5saW5jb2xuLmFjLm56
L2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQByGGpG5r79B1yknihG
Fj08bsIlWOH9wxL650sArpOlGDQZ77XDO/EjFazGclYTGoVvqs49AHlEJsVA9tss
5mQtwjvZ0+0eDBf4ygKbaDvSSyypaMtvm9mhRvMM7OFz3evJNK8fkKpAzkCIsdl5
ujuGT4R/7UI+edfohPjYxQmflgN+fuMyRnVtM2/PK2+IxZiL6e99BKPbFs6sRQtX
nPb4cBACTUk+sLa7Tk0S4pEl8TqV5qRG9WTsu9EzuJfDY3TpfT4LnmxGMVYfysOY
/o8xRRsKbHbCyjFKXuHus2UycG4JgH8ccIHA4+wcva/UrcOGmJQFqVRgDdSFDHG5
xKKE
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        -->
        <!-- new V3 signing certificate - unused
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDLzCCAhegAwIBAgIUU0XACHLeRIYsXJrsg5KbqRGtsbowDQYJKoZIhvcNAQEL
BQAwHDEaMBgGA1UEAwwRaWRwLmxpbmNvbG4uYWMubnowHhcNMTYwNzI3MjM0NDQw
WhcNMzYwNzI3MjM0NDQwWjAcMRowGAYDVQQDDBFpZHAubGluY29sbi5hYy5uejCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMMqyv26Ne6svFxn249sSb//
j3qktLOBdZ2at83Run5UVcIDxcqZmeaWwdw3EDPmtzzS8G18KQR3Io7Expwdxy7D
sVri3mn+ExxsGp5YPjr6ZIA8R2yd6rNWp2Q5vbJbh2iHhv/AH2JPXWDr18vIRMnj
/2y39kmFznle/IhvxafrTGCEuROEICzPMcVu9JBukagZXs3DOc4UlEe8zNCIHVhy
380PL0ajfGZOO7V9lKjKJ9KNhc1QQHLU0Wca9MjVpuV0GqA3UXLzvEttYzvosn66
NhoWMpqpdfMW6+guQPqdt7GPxofd5Uh9EMzfEKn0wT6PzgkjVB8le9UNRC/pjMEC
AwEAAaNpMGcwHQYDVR0OBBYEFJClIwROGSqBfMlxw4qdlyZEm1UCMEYGA1UdEQQ/
MD2CEWlkcC5saW5jb2xuLmFjLm56hihodHRwczovL2lkcC5saW5jb2xuLmFjLm56
L2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQCjoC6XFPnzPf0NJ6tm
p8kdR7ZsSxbIWS/uAQg2YvU5XhZeh9yK9RIBkiLylUcJDxQQOurZNNpRtQ75GBrF
eBhQ0alSTiM+i40eCfCMJWPZZsHZEesIB5Z2NSG9+oEX4Dh7yt85K+IopMdBIQZP
WB3w41v091qANLGikKaLR+sp4ISWr/Zj/chARUR5ddcscnUsM22MMr7XWVDEMdPs
bJet16pQzASGJ7bBfijYE1A/OwZVEgyWD5fwd0dQzOZyPBCsN+9+nz8+F+Dz2y2B
mj/ZUtevDTsv0zCN5fe1vuSvfE/QXog1A5uDHGzZs5clJ1l940GPEP2wHs7bo2Dp
9QsJ
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        -->
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDLzCCAhegAwIBAgIUDwXUH+y2xM14JO2JOJ8MqHIgYWIwDQYJKoZIhvcNAQEL
BQAwHDEaMBgGA1UEAwwRaWRwLmxpbmNvbG4uYWMubnowHhcNMTYwNzI3MjM0NDQx
WhcNMzYwNzI3MjM0NDQxWjAcMRowGAYDVQQDDBFpZHAubGluY29sbi5hYy5uejCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMmhKpBSQaG76fQpokTXiRrB
sIKw7pZJPgd3Gv0/0benjbRmvpRt5CAiNgdtsnALVbIVQfceDh+kaR6NRwW8O71+
PnnfyirTQnn9akFsZ6IRn7+SF/k45lqPOhotcUoNrYrAOSTE5WniD+g/axz5K4ju
XbW41Aui6Hh5GTmTQ6rcaCzu+jH+0gzqrf7lJHyfLhzxxuX3rFip0Df/nTJpGaKr
VvN2cO+apQh0q3kI5l3jG47WmABN6wTSswyJRLjCInXjYb/k+o1nAGSQDtxKxlhb
09prHroewOLpvWGCoi8RKamn/qGU9KoRkR1rdOj9svrsFaqERvAZSCiaxfoOKZ8C
AwEAAaNpMGcwHQYDVR0OBBYEFJqrQMtLRfBLafROG8wIU/z3Xb6KMEYGA1UdEQQ/
MD2CEWlkcC5saW5jb2xuLmFjLm56hihodHRwczovL2lkcC5saW5jb2xuLmFjLm56
L2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQB71LgQ76tcn1Iprlb7
0bMB3GZVLs3QRR1fF2ss3KvZHzj7mN44BDUiya08m0sQAFGbQlS0Aal1ulNdzfJO
uHPX34qfrDGSjzeTBSoTxAx3bwk+4mfeNyY9p3GTdLZupCinU87y4ODBnzH0ZfvZ
DTjw7zwalIEwEA0F0wbsb7WeKnl4bSlkf67fsxC8hVdXnXXRjQdOF4xEnqZnSQYq
ubD7BErygXjPZXgw5oXYqYFC78txxOWlStmXzM5x/y/qQ9XKLLDCIsr404/mkmJ2
7Vzrzng9unPIMFSwhIvqdNZsaak56uu/xPe2wDYr/1Eq/3kXlcBKAVn2225EwMN4
WW6t
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.lincoln.ac.nz:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
        <!-- uncommented by Vlad Mencl 2016-08-10 -->
        <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.lincoln.ac.nz:8443/idp/profile/SAML2/SOAP/AttributeQuery"/>
        <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->

    </AttributeAuthorityDescriptor>

</EntityDescriptor>
