<?xml version="1.0" encoding="UTF-8"?>
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" entityID="https://login.stolaf.edu/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">stolaf.edu</shibmd:Scope>
            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">St. Olaf College Shibboleth server</mdui:DisplayName>
                <mdui:Description xml:lang="en">St. Olaf College Shibboleth server</mdui:Description>
                <!-- <mdui:Logo height="144" width="360">https://www.stolaf.edu/files/sto_logo_email_sig.png</mdui:Logo> -->
            </mdui:UIInfo>
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEBTCCAu2gAwIBAgIJAIpCACOSmm5jMA0GCSqGSIb3DQEBBQUAMIGYMQswCQYD
VQQGEwJVUzESMBAGA1UECAwJTWlubmVzb3RhMRMwEQYDVQQHDApOb3J0aGZpZWxk
MRgwFgYDVQQKDA9TdCBPbGFmIENvbGxlZ2UxCzAJBgNVBAsMAklUMRkwFwYDVQQD
DBBsb2dpbi5zdG9sYWYuZWR1MR4wHAYJKoZIhvcNAQkBFg9yb290QHN0b2xhZi5l
ZHUwHhcNMTIwODA4MTUzODM4WhcNMzIwODA4MTUzODM4WjCBmDELMAkGA1UEBhMC
VVMxEjAQBgNVBAgMCU1pbm5lc290YTETMBEGA1UEBwwKTm9ydGhmaWVsZDEYMBYG
A1UECgwPU3QgT2xhZiBDb2xsZWdlMQswCQYDVQQLDAJJVDEZMBcGA1UEAwwQbG9n
aW4uc3RvbGFmLmVkdTEeMBwGCSqGSIb3DQEJARYPcm9vdEBzdG9sYWYuZWR1MIIB
IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAs6mj0mZ9xeLDbuGLO6ugsJWM
5hN5Smi+MejkIv+Q95SVZP7tROG2kwMhMl8mPdV+xf8+vNG6GPLA58kyr5ShgLdf
CAGYnoardWVvp9HVB4kcQA8CgizRmhupCKZqNqQOKg+7qejxHA863dWmPr4a62pS
ddoMuhAOl9yZBpnGHusHy8+Cfbdan8NqUXBX33STQVqA3980oUxLxpo+ywF0prV2
bCy/54dgIScVT66TDuGZAwdmToRE6Yi4FePI4FFRh7ohOajadkmG1Ni/uEbWXYwl
l6ehDhTkm0lo0uZ8D1LtCe6ydKE6UAE1ACAZfrfyEh6LfnzoiFJCrJoOzTHlrQID
AQABo1AwTjAdBgNVHQ4EFgQUt/02+LxZnPfKIg3hVKI774yeF9IwHwYDVR0jBBgw
FoAUt/02+LxZnPfKIg3hVKI774yeF9IwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0B
AQUFAAOCAQEAAq57xrup7Jtuy0u2GCcTyqF44T6wPPXwMTmy8R1104gT8AQh7VHh
UqBU4OUHx3ZUaXNkGOVFQUftc9BSBxKBuyK+6m1yLQyY1zV/WI9UG7wjtUBcu2Vn
PEKSb+LrqVee+0fm1kMLa7BBH2eDOF3L+7A88JhWnLmpXZIPv/iLoqqibZuw+nDU
cYnf3BffmuLLX119fYL+023+7YDfXolEbyd0nYVeWV2e33xt6RJtmWuO1VbQsPQZ
Gq8AofetoybsRS9b+CrRWiYzUvjZ0zkjDe9PMzvsXcS7xGD8/90X9damUttErlld
Yj2frn/AgpSfFIR4btP5vc0jd8Qy85QoDg==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDLDCCAhSgAwIBAgIVAPoBmMVipOKbAYFHAVDrD7ZNEOJTMA0GCSqGSIb3DQEB
CwUAMBsxGTAXBgNVBAMMEGxvZ2luLnN0b2xhZi5lZHUwHhcNMTYwMzMxMjA1NTAw
WhcNMzYwMzMxMjA1NTAwWjAbMRkwFwYDVQQDDBBsb2dpbi5zdG9sYWYuZWR1MIIB
IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAj/9aBS0ts6Noz5TcIYJgyCjD
v124biKuSlqxQ3Hp8gzf2RFPtb1+z8pfsD9/ECAbkPaHh4EXBlXmxWPvGjwk2l2w
g1C2TqAJhEJTmUOueXj3c8zdqtGhZBH9twQw09WAwQmEgSRvxiElf/xS/wRKPyOl
YcBYI72rcb56vxIE2s+IA5l6gKn/4wp1yH5+g4Q1g/W02yT0C6gDAk5N49MwQcw6
afrHsIEbqz1nhnZRZrNj1QRH2i7SSI06JSfUVBZhjT8c3uBabMQBocH+/m/S4V3l
i0B1MluF1oqiGlJSF/IqYQMsl1OSS+QQqzJ6o0k9aQm/zjAhQtrUYofjQ6ySvwID
AQABo2cwZTAdBgNVHQ4EFgQUW9h3NdSlk44Z9bTTjWj4VcVi7iowRAYDVR0RBD0w
O4IQbG9naW4uc3RvbGFmLmVkdYYnaHR0cHM6Ly9sb2dpbi5zdG9sYWYuZWR1L2lk
cC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQB+NZ5QToNUZ7kQ9gxmou/Q
VNOHULLyPO59cGQ5xYxcySTbtxK0zc6GQORexhaDyZuD7mdXX6voaaoBcWul+DEx
EfyRe/Bq3VDsanpXslevV2Bx13tHutjtpg3CBJ/mdqNPDL6xaxzy5ay2dYbIukmb
IQ3OsZ/d5/qPTu5s7fzc8HSkYuTzLySzMbiS3A75QHIgl/LJqdSg2VbrS/FwQc/I
05PDauDLwOHyklA+nokoVbxcEP1N283eGfETwrEyJOrEY5FrZ5oo3GkJmR8EB4v8
1+ykReyggFxfFJgOqeLEIoWkz8YHgdWwfbRlR55FiHJnnnQC8jo5NAmU01C7CmuH
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>

        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>

        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://login.stolaf.edu/idp/profile/Shibboleth/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://login.stolaf.edu/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://login.stolaf.edu/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://login.stolaf.edu/idp/profile/SAML2/Redirect/SSO"/>

    </IDPSSODescriptor>

    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">stolaf.edu</shibmd:Scope>
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEBTCCAu2gAwIBAgIJAIpCACOSmm5jMA0GCSqGSIb3DQEBBQUAMIGYMQswCQYD
VQQGEwJVUzESMBAGA1UECAwJTWlubmVzb3RhMRMwEQYDVQQHDApOb3J0aGZpZWxk
MRgwFgYDVQQKDA9TdCBPbGFmIENvbGxlZ2UxCzAJBgNVBAsMAklUMRkwFwYDVQQD
DBBsb2dpbi5zdG9sYWYuZWR1MR4wHAYJKoZIhvcNAQkBFg9yb290QHN0b2xhZi5l
ZHUwHhcNMTIwODA4MTUzODM4WhcNMzIwODA4MTUzODM4WjCBmDELMAkGA1UEBhMC
VVMxEjAQBgNVBAgMCU1pbm5lc290YTETMBEGA1UEBwwKTm9ydGhmaWVsZDEYMBYG
A1UECgwPU3QgT2xhZiBDb2xsZWdlMQswCQYDVQQLDAJJVDEZMBcGA1UEAwwQbG9n
aW4uc3RvbGFmLmVkdTEeMBwGCSqGSIb3DQEJARYPcm9vdEBzdG9sYWYuZWR1MIIB
IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAs6mj0mZ9xeLDbuGLO6ugsJWM
5hN5Smi+MejkIv+Q95SVZP7tROG2kwMhMl8mPdV+xf8+vNG6GPLA58kyr5ShgLdf
CAGYnoardWVvp9HVB4kcQA8CgizRmhupCKZqNqQOKg+7qejxHA863dWmPr4a62pS
ddoMuhAOl9yZBpnGHusHy8+Cfbdan8NqUXBX33STQVqA3980oUxLxpo+ywF0prV2
bCy/54dgIScVT66TDuGZAwdmToRE6Yi4FePI4FFRh7ohOajadkmG1Ni/uEbWXYwl
l6ehDhTkm0lo0uZ8D1LtCe6ydKE6UAE1ACAZfrfyEh6LfnzoiFJCrJoOzTHlrQID
AQABo1AwTjAdBgNVHQ4EFgQUt/02+LxZnPfKIg3hVKI774yeF9IwHwYDVR0jBBgw
FoAUt/02+LxZnPfKIg3hVKI774yeF9IwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0B
AQUFAAOCAQEAAq57xrup7Jtuy0u2GCcTyqF44T6wPPXwMTmy8R1104gT8AQh7VHh
UqBU4OUHx3ZUaXNkGOVFQUftc9BSBxKBuyK+6m1yLQyY1zV/WI9UG7wjtUBcu2Vn
PEKSb+LrqVee+0fm1kMLa7BBH2eDOF3L+7A88JhWnLmpXZIPv/iLoqqibZuw+nDU
cYnf3BffmuLLX119fYL+023+7YDfXolEbyd0nYVeWV2e33xt6RJtmWuO1VbQsPQZ
Gq8AofetoybsRS9b+CrRWiYzUvjZ0zkjDe9PMzvsXcS7xGD8/90X9damUttErlld
Yj2frn/AgpSfFIR4btP5vc0jd8Qy85QoDg==
			</ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDLDCCAhSgAwIBAgIVAPoBmMVipOKbAYFHAVDrD7ZNEOJTMA0GCSqGSIb3DQEB
CwUAMBsxGTAXBgNVBAMMEGxvZ2luLnN0b2xhZi5lZHUwHhcNMTYwMzMxMjA1NTAw
WhcNMzYwMzMxMjA1NTAwWjAbMRkwFwYDVQQDDBBsb2dpbi5zdG9sYWYuZWR1MIIB
IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAj/9aBS0ts6Noz5TcIYJgyCjD
v124biKuSlqxQ3Hp8gzf2RFPtb1+z8pfsD9/ECAbkPaHh4EXBlXmxWPvGjwk2l2w
g1C2TqAJhEJTmUOueXj3c8zdqtGhZBH9twQw09WAwQmEgSRvxiElf/xS/wRKPyOl
YcBYI72rcb56vxIE2s+IA5l6gKn/4wp1yH5+g4Q1g/W02yT0C6gDAk5N49MwQcw6
afrHsIEbqz1nhnZRZrNj1QRH2i7SSI06JSfUVBZhjT8c3uBabMQBocH+/m/S4V3l
i0B1MluF1oqiGlJSF/IqYQMsl1OSS+QQqzJ6o0k9aQm/zjAhQtrUYofjQ6ySvwID
AQABo2cwZTAdBgNVHQ4EFgQUW9h3NdSlk44Z9bTTjWj4VcVi7iowRAYDVR0RBD0w
O4IQbG9naW4uc3RvbGFmLmVkdYYnaHR0cHM6Ly9sb2dpbi5zdG9sYWYuZWR1L2lk
cC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQB+NZ5QToNUZ7kQ9gxmou/Q
VNOHULLyPO59cGQ5xYxcySTbtxK0zc6GQORexhaDyZuD7mdXX6voaaoBcWul+DEx
EfyRe/Bq3VDsanpXslevV2Bx13tHutjtpg3CBJ/mdqNPDL6xaxzy5ay2dYbIukmb
IQ3OsZ/d5/qPTu5s7fzc8HSkYuTzLySzMbiS3A75QHIgl/LJqdSg2VbrS/FwQc/I
05PDauDLwOHyklA+nokoVbxcEP1N283eGfETwrEyJOrEY5FrZ5oo3GkJmR8EB4v8
1+ykReyggFxfFJgOqeLEIoWkz8YHgdWwfbRlR55FiHJnnnQC8jo5NAmU01C7CmuH
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

    </AttributeAuthorityDescriptor>

    <!-- New SP block for Google SAML Proxy -->
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
 
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
MIIEBTCCAu2gAwIBAgIJAIpCACOSmm5jMA0GCSqGSIb3DQEBBQUAMIGYMQswCQYD
VQQGEwJVUzESMBAGA1UECAwJTWlubmVzb3RhMRMwEQYDVQQHDApOb3J0aGZpZWxk
MRgwFgYDVQQKDA9TdCBPbGFmIENvbGxlZ2UxCzAJBgNVBAsMAklUMRkwFwYDVQQD
DBBsb2dpbi5zdG9sYWYuZWR1MR4wHAYJKoZIhvcNAQkBFg9yb290QHN0b2xhZi5l
ZHUwHhcNMTIwODA4MTUzODM4WhcNMzIwODA4MTUzODM4WjCBmDELMAkGA1UEBhMC
VVMxEjAQBgNVBAgMCU1pbm5lc290YTETMBEGA1UEBwwKTm9ydGhmaWVsZDEYMBYG
A1UECgwPU3QgT2xhZiBDb2xsZWdlMQswCQYDVQQLDAJJVDEZMBcGA1UEAwwQbG9n
aW4uc3RvbGFmLmVkdTEeMBwGCSqGSIb3DQEJARYPcm9vdEBzdG9sYWYuZWR1MIIB
IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAs6mj0mZ9xeLDbuGLO6ugsJWM
5hN5Smi+MejkIv+Q95SVZP7tROG2kwMhMl8mPdV+xf8+vNG6GPLA58kyr5ShgLdf
CAGYnoardWVvp9HVB4kcQA8CgizRmhupCKZqNqQOKg+7qejxHA863dWmPr4a62pS
ddoMuhAOl9yZBpnGHusHy8+Cfbdan8NqUXBX33STQVqA3980oUxLxpo+ywF0prV2
bCy/54dgIScVT66TDuGZAwdmToRE6Yi4FePI4FFRh7ohOajadkmG1Ni/uEbWXYwl
l6ehDhTkm0lo0uZ8D1LtCe6ydKE6UAE1ACAZfrfyEh6LfnzoiFJCrJoOzTHlrQID
AQABo1AwTjAdBgNVHQ4EFgQUt/02+LxZnPfKIg3hVKI774yeF9IwHwYDVR0jBBgw
FoAUt/02+LxZnPfKIg3hVKI774yeF9IwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0B
AQUFAAOCAQEAAq57xrup7Jtuy0u2GCcTyqF44T6wPPXwMTmy8R1104gT8AQh7VHh
UqBU4OUHx3ZUaXNkGOVFQUftc9BSBxKBuyK+6m1yLQyY1zV/WI9UG7wjtUBcu2Vn
PEKSb+LrqVee+0fm1kMLa7BBH2eDOF3L+7A88JhWnLmpXZIPv/iLoqqibZuw+nDU
cYnf3BffmuLLX119fYL+023+7YDfXolEbyd0nYVeWV2e33xt6RJtmWuO1VbQsPQZ
Gq8AofetoybsRS9b+CrRWiYzUvjZ0zkjDe9PMzvsXcS7xGD8/90X9damUttErlld
Yj2frn/AgpSfFIR4btP5vc0jd8Qy85QoDg==
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
MIIDLDCCAhSgAwIBAgIVAPoBmMVipOKbAYFHAVDrD7ZNEOJTMA0GCSqGSIb3DQEB
CwUAMBsxGTAXBgNVBAMMEGxvZ2luLnN0b2xhZi5lZHUwHhcNMTYwMzMxMjA1NTAw
WhcNMzYwMzMxMjA1NTAwWjAbMRkwFwYDVQQDDBBsb2dpbi5zdG9sYWYuZWR1MIIB
IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAj/9aBS0ts6Noz5TcIYJgyCjD
v124biKuSlqxQ3Hp8gzf2RFPtb1+z8pfsD9/ECAbkPaHh4EXBlXmxWPvGjwk2l2w
g1C2TqAJhEJTmUOueXj3c8zdqtGhZBH9twQw09WAwQmEgSRvxiElf/xS/wRKPyOl
YcBYI72rcb56vxIE2s+IA5l6gKn/4wp1yH5+g4Q1g/W02yT0C6gDAk5N49MwQcw6
afrHsIEbqz1nhnZRZrNj1QRH2i7SSI06JSfUVBZhjT8c3uBabMQBocH+/m/S4V3l
i0B1MluF1oqiGlJSF/IqYQMsl1OSS+QQqzJ6o0k9aQm/zjAhQtrUYofjQ6ySvwID
AQABo2cwZTAdBgNVHQ4EFgQUW9h3NdSlk44Z9bTTjWj4VcVi7iowRAYDVR0RBD0w
O4IQbG9naW4uc3RvbGFmLmVkdYYnaHR0cHM6Ly9sb2dpbi5zdG9sYWYuZWR1L2lk
cC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQB+NZ5QToNUZ7kQ9gxmou/Q
VNOHULLyPO59cGQ5xYxcySTbtxK0zc6GQORexhaDyZuD7mdXX6voaaoBcWul+DEx
EfyRe/Bq3VDsanpXslevV2Bx13tHutjtpg3CBJ/mdqNPDL6xaxzy5ay2dYbIukmb
IQ3OsZ/d5/qPTu5s7fzc8HSkYuTzLySzMbiS3A75QHIgl/LJqdSg2VbrS/FwQc/I
05PDauDLwOHyklA+nokoVbxcEP1N283eGfETwrEyJOrEY5FrZ5oo3GkJmR8EB4v8
1+ykReyggFxfFJgOqeLEIoWkz8YHgdWwfbRlR55FiHJnnnQC8jo5NAmU01C7CmuH
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
 
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.example.com/idp/profile/Authn/SAML2/POST/SSO" index="0"/>
    </SPSSODescriptor>

</EntityDescriptor>
