<?xml version="1.0" encoding="UTF-8"?>
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" entityID="https://hosted-login.tuakiri.ac.nz/hosting/cawthron.org.nz/idp/shibboleth">

    <Extensions>
      <mdrpi:RegistrationInfo registrationAuthority="https://tuakiri.ac.nz/" registrationInstant="2022-03-09T04:31:01Z" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi">
        <mdrpi:RegistrationPolicy xml:lang="en">https://tuakiri.ac.nz/documents/tuakiri-mrps-1.0.pdf</mdrpi:RegistrationPolicy>
      </mdrpi:RegistrationInfo>
      <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
        <saml:Attribute Name="http://macedir.org/entity-category-support" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
          <saml:AttributeValue>http://refeds.org/category/research-and-scholarship</saml:AttributeValue>
        </saml:Attribute>
        <saml:Attribute Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
          <saml:AttributeValue>https://refeds.org/sirtfi</saml:AttributeValue>
        </saml:Attribute>
      </mdattr:EntityAttributes>
    </Extensions>

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">cawthron.org.nz</shibmd:Scope>
            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">Cawthron Institute</mdui:DisplayName>
                <mdui:Logo xml:lang="en" height="62" width="205">https://hosted-login.tuakiri.ac.nz/hosting/cawthron.org.nz/idp/images/logo.png</mdui:Logo>
            </mdui:UIInfo>
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEnTCCAwWgAwIBAgIUXZyoKo0/dJZqpd90exkgaLaWfKowDQYJKoZIhvcNAQELBQAwPTE7MDkG
A1UEAwwyaG9zdGVkLWxvZ2luLnR1YWtpcmkuYWMubnovaG9zdGluZy9jYXd0aHJvbi5vcmcubnow
HhcNMjIwMzI1MDkzMzAwWhcNNDIwMzIwMDkzMzAwWjA9MTswOQYDVQQDDDJob3N0ZWQtbG9naW4u
dHVha2lyaS5hYy5uei9ob3N0aW5nL2Nhd3Rocm9uLm9yZy5uejCCAaIwDQYJKoZIhvcNAQEBBQAD
ggGPADCCAYoCggGBAMPJHp8VsH/7fAdbud6aRmNGihilcdhhVhA3uMVlSmoynO+EJzs6RrRkYPgi
QqYY0TQZA0YSl02JwQ7V9HOSJAMjefx1QooTuiz+NvYFZeK5548YgKkAXoGoqI0v8zh5k+lmSZOp
NG1dQScXt6Xm+qR8vSJ0mJmRQ2K3ELNWOVY5rBbASJbvF6mtDpfSgNRrkUkpp6+3r8RtwQE1f+wU
zllrL10cCeOPJlZAuCo8TFvmdZbkwB/DQIHRZDNqm/eW3I1GCZvVzJdgPUvfT2wf5lH7YUOL++wf
CCQ2CtVIpNdQyww/MXlGMjt7J+AxXRIbQfWHDPs8RJUeHgrBRetuK8pmbw77QZDb5hfu5ALNbL6x
O4MkfZxMnA1X+RgLDMp4HaSsRjKNY/6W4iIlzEhVW7ND23UlaE10TpizGel0ZkTpY0iwQvFDmClp
m/qDd93cqJVhd5/0fZh/A9XvC+3f5OLlaB5DXkB9l2L+hhIFJPeWcQVMD1HHNLwuFdXUEl1qZQID
AQABo4GUMIGRMHAGA1UdEQRpMGeCGmhvc3RlZC1sb2dpbi50dWFraXJpLmFjLm56hklodHRwczov
L2hvc3RlZC1sb2dpbi50dWFraXJpLmFjLm56L2hvc3RpbmcvY2F3dGhyb24ub3JnLm56L2lkcC9z
aGliYm9sZXRoMB0GA1UdDgQWBBQapTGp52Ie8B4WF+OI0zIOeaj5hzANBgkqhkiG9w0BAQsFAAOC
AYEAeX3KyhfXuD/GXTyJsw7k470qXp4CvznmQ8zBMdrPNhz5VsBf/F2gYSOrG0gTSNjXkxJSTohV
S+NhjGH+R4kpvi1l27VrEgpl1QGWmOjtdozq1Qyclma5PALCb6VLFfjJBmo5TARquIHvvvBqDM+w
znxfyPTb5MWUX7JSoxtG4oExfZFVhnTQx3yV8z7kgFBbYct5NEnFj3mbmnnn3gCXDI+IWaebWNOo
0BeHvZQP/UbyMhhg+G61fBO+aaHURkbW8zJgUoDy7Y3OjCCU1HpESDOETzz/lOqTNirjfF01EZMO
gj4q2lD4e7gb9Q921i0npEhKofkvS2W0t5j4sqJKALJpiF4TmZY6zu+JvK0Q9KaZC1VE+BvvlC/W
kF1syq5lIa3Wc0/I74kU+eLzkcQHvxKl5MAN8VaNTvv83A+db4aGANlZtr4b976XpcAx14zQfQv9
yG9MsirOl9tN6I2rBmV+qX/K76gx/aaJ9F5tIu5mJKVm2osER5nJNnh4EwF6
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEnTCCAwWgAwIBAgIUbUVH5ZLsodhFBCDkqegeUr4FbIwwDQYJKoZIhvcNAQELBQAwPTE7MDkG
A1UEAwwyaG9zdGVkLWxvZ2luLnR1YWtpcmkuYWMubnovaG9zdGluZy9jYXd0aHJvbi5vcmcubnow
HhcNMjIwMzI1MDkzMzAyWhcNNDIwMzIwMDkzMzAyWjA9MTswOQYDVQQDDDJob3N0ZWQtbG9naW4u
dHVha2lyaS5hYy5uei9ob3N0aW5nL2Nhd3Rocm9uLm9yZy5uejCCAaIwDQYJKoZIhvcNAQEBBQAD
ggGPADCCAYoCggGBAMauN+/ggrd5SQIVAdRajCuwaXrwHBEjXPfEfxG4JQqZ0P+C2HDrJLJ6ePTm
WyUcYcIVn6g0mdK4iHQKingC1woB/xpiHwP1Vl/6RWndkmERPWA2Kg0LTMIMQluluDT5sttnpNtC
lEn89RLLUaHBKXk6VJ1bVfpvvAt6i+Rl91z3qo7LCA/pROt7XQC+M9gLCi9vnwXCrgSc2s8n88iT
Fz5DTywRpQ8gs9aAGBDfNUyEhav8aKZ/n7gMmKtlm7k4cChzZkKNkbNiu3ZXbfW1AJrf+BQHdshy
07slcztmeXFwUKe6f3QlT1GwU8VznXyuCI+p3leOxWSdnPxj5hR3+bDme3OhKu/TwVqW1CTmJUOX
mPfWD6motN1Kmso+6O7T/B+WacWx2l2sEwWA/tuJkvoPX0fH9fU6mzZPqVqxqkA66lK3q7ptx3/X
9bzHkqW/YtbvwVCdigQYxxLVEQH61KXDvkKrKqyzV9yrtcCt5MCRuDR9XQt6lKwQHa2CjSmyawID
AQABo4GUMIGRMHAGA1UdEQRpMGeCGmhvc3RlZC1sb2dpbi50dWFraXJpLmFjLm56hklodHRwczov
L2hvc3RlZC1sb2dpbi50dWFraXJpLmFjLm56L2hvc3RpbmcvY2F3dGhyb24ub3JnLm56L2lkcC9z
aGliYm9sZXRoMB0GA1UdDgQWBBTuANRR68lBysKOEbBJeL3SAKAq7zANBgkqhkiG9w0BAQsFAAOC
AYEABufi/YBIMKzVHFOhnG3WyqzAOY883BCV6eKL22PO0aH+ib52et0LmxV0auYNYxHq8Ck83M86
8B6z7vinJcSmA9Xy/BOLk2/CfZq4NENjBwO/fRKSQaXyF+NfR+HUJl1PDUbhTn9H1BEKYZ5P67CZ
9xP+8dITu00Yt+xDMkkb4/gtnAX+QGRP97R49ygMgIORK0vXsMOdVg3z/fw+JF88bOqKyq6izCru
O3h882iR87qPJSJFdH8ybOSLs8L7DmzVcTwL7+Q/7vdoMUOpD8pqwAIRw4xCN3sr3Q0Dtqw/7/Mz
fcG8vWc6bH1wiwPLqVLJ1vC5Xlgn9wkcaUnnkVuUq3lohuVDHbfGX48XFCtETsfsMSBATMHLjwVF
jdFaJ9e0oO6daEqQ16/5GkcnjbD3ixVQjASR1mYWV1EIyBCouiBKvBLMdNWkUixg6DIoibPzI+15
NeeSjlh64Pnw6yEE9gOK+Xfk353V9n2FO8XZvT2T5FMHxNIHwTDr5EArPe9Q
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>


        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://hosted-login.tuakiri.ac.nz/hosting/cawthron.org.nz/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://hosted-login.tuakiri.ac.nz/hosting/cawthron.org.nz/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://hosted-login.tuakiri.ac.nz/hosting/cawthron.org.nz/idp/profile/SAML2/Redirect/SLO"/>

        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>

        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://hosted-login.tuakiri.ac.nz/hosting/cawthron.org.nz/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://hosted-login.tuakiri.ac.nz/hosting/cawthron.org.nz/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://hosted-login.tuakiri.ac.nz/hosting/cawthron.org.nz/idp/profile/SAML2/Redirect/SSO"/>

        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.27856.1.2.5" FriendlyName="auEduPersonSharedToken" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:2.5.4.3" FriendlyName="cn" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:2.16.840.1.113730.3.1.241" FriendlyName="displayName" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.1" FriendlyName="eduPersonAffiliation" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.11" FriendlyName="eduPersonAssurance" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.7" FriendlyName="eduPersonEntitlement" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.5" FriendlyName="eduPersonPrimaryAffiliation" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" FriendlyName="eduPersonPrincipalName" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" FriendlyName="eduPersonScopedAffiliation" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:2.5.4.42" FriendlyName="givenName" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:0.9.2342.19200300.100.1.3" FriendlyName="mail" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:2.5.4.10" FriendlyName="o" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.25178.1.2.9" FriendlyName="schacHomeOrganization" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.25178.1.2.10" FriendlyName="schacHomeOrganizationType" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:2.5.4.4" FriendlyName="sn" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oasis:names:tc:SAML:attribute:pairwise-id" FriendlyName="samlPairwiseID" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oasis:names:tc:SAML:attribute:subject-id" FriendlyName="samlSubjectID" />
    </IDPSSODescriptor>


    <Organization>
        <OrganizationName xml:lang="en">cawthron.org.nz</OrganizationName>
        <OrganizationDisplayName xml:lang="en">Cawthron Institute</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">https://www.cawthron.org.nz/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="technical">
      <Company>REANNZ</Company>
      <GivenName>Tuakiri</GivenName>
      <SurName>Support</SurName>
      <EmailAddress>mailto:tuakiri@reannz.co.nz</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
      <Company>REANNZ</Company>
      <GivenName>Tuakiri</GivenName>
      <SurName>Support</SurName>
      <EmailAddress>mailto:tuakiri@reannz.co.nz</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security" xmlns:remd="http://refeds.org/metadata" >
      <Company>REANNZ</Company>
      <GivenName>Tuakiri</GivenName>
      <SurName>Security</SurName>
      <EmailAddress>mailto:security@reannz.co.nz</EmailAddress>
    </ContactPerson>

</EntityDescriptor>
