<?xml version="1.0" encoding="UTF-8"?>
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" entityID="https://hosted-login.tuakiri.ac.nz/hosting/malaghan.org.nz/idp/shibboleth">

    <Extensions>
      <mdrpi:RegistrationInfo registrationAuthority="https://tuakiri.ac.nz/" registrationInstant="2022-03-14T00:36:39Z" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi">
        <mdrpi:RegistrationPolicy xml:lang="en">https://tuakiri.ac.nz/documents/tuakiri-mrps-1.0.pdf</mdrpi:RegistrationPolicy>
      </mdrpi:RegistrationInfo>
      <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
        <saml:Attribute Name="http://macedir.org/entity-category-support" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
          <saml:AttributeValue>http://refeds.org/category/research-and-scholarship</saml:AttributeValue>
        </saml:Attribute>
        <saml:Attribute Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
          <saml:AttributeValue>https://refeds.org/sirtfi</saml:AttributeValue>
        </saml:Attribute>
      </mdattr:EntityAttributes>
    </Extensions>

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">malaghan.org.nz</shibmd:Scope>
            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">Malaghan Institute of Medical Research</mdui:DisplayName>
                <mdui:Logo xml:lang="en" height="215" width="207">https://hosted-login.tuakiri.ac.nz/hosting/malaghan.org.nz/idp/images/logo.jpg</mdui:Logo>
            </mdui:UIInfo>
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEnTCCAwWgAwIBAgIUFKWfEDIttOieX3QCMBYSmmP51sEwDQYJKoZIhvcNAQELBQAwPTE7MDkG
A1UEAwwyaG9zdGVkLWxvZ2luLnR1YWtpcmkuYWMubnovaG9zdGluZy9tYWxhZ2hhbi5vcmcubnow
HhcNMjIwMzE0MDMyMjMxWhcNNDIwMzA5MDMyMjMxWjA9MTswOQYDVQQDDDJob3N0ZWQtbG9naW4u
dHVha2lyaS5hYy5uei9ob3N0aW5nL21hbGFnaGFuLm9yZy5uejCCAaIwDQYJKoZIhvcNAQEBBQAD
ggGPADCCAYoCggGBANKgrlP6kobdMYygehpLJW0ToxzuODL3CU45Hkho47RKPhO/+Z9UAeVwHPiV
pja0AVhuD6Hd82iD9IxGN/euD2mdC9HzBrS0Dvax2Bcf7CgKcGrsiMvBtn6L5CGgH14xYwlECdG0
HY8ubShcrYCtnvqGTltOilOGvKzPx/ZsKv2m/9FLnL1n1+ynL8r/rzJO7GF7aZEJBtgsmeGXTOvn
svi2p2zOaOVvxdym5AFHEV0NrvMbmt3zehDJCWJMkDRpsw7PYsTCwVqIOyUTiefsLKJZ6Gco1/lK
98RdnsRLioql9pGMllup1H3t/2AKRTKkOv1N5ZiZuQvIPF4krbnycYmvXDyQ8TQSLDp7PLheKSIe
wUjJZXaJHhsMKjs96PKWmtDXpX1Tt83r4sRjvpOcTtMx0i7sl87a5FR762QUl3KJYrh4ApdUJq7W
rgzj2Z2AdVgLkIZQnG/gOBdRwt038CfgYeypbhg3BmqIh/LxSpwt3uB/ySxJtVoubBL3VjQ+SQID
AQABo4GUMIGRMHAGA1UdEQRpMGeCGmhvc3RlZC1sb2dpbi50dWFraXJpLmFjLm56hklodHRwczov
L2hvc3RlZC1sb2dpbi50dWFraXJpLmFjLm56L2hvc3RpbmcvbWFsYWdoYW4ub3JnLm56L2lkcC9z
aGliYm9sZXRoMB0GA1UdDgQWBBR8HiFh/IqzGafaX5cJ+feulI2MUzANBgkqhkiG9w0BAQsFAAOC
AYEAmwrv8DZ7wc8TtawUPMR8J11byhA7eLkZZfUe+2jtxmDrZfDjcMREmfSakMHP3gg8ZVX3FB4v
N7NGtZCKx899IKSHdthnv2ADGoAE/I5X6GOzbm77cthzHPzDooWKwzGY4IfxyTYoTN6/kpqsr2tn
mBV1TL0VyDeV3+jEiLEEtm7pBLRRPLZ1EREeU1VUdY4iyMGymt/xCV2a1UUqeIQFQNhoSAHCd5kf
mfp/Qn4a/xMG9c2xw1NOMvmf3+JOCGGkLt0fCjaH6NqEGG5+L/pJwMBUXeDYFCSH/EIt09qvoObO
K5otEU4ExcSWVstWwH+borBT/apUlaCV3VPHNaaCsFwdB0Gwo7TRaFtQo3MQuW3p5pES4cGzYYBM
j01ZBNk7FCln+RZg+087oUw3khn75096WEHUeVYQv9dwCwEb6RlbuHVLAYaqGJITrGEIKP7vGoHr
LcxhpwpxmHCilVN+6ZAYSeT92Shv+akTTzH6zIdjYdbVdVxrsve5ZXPkAjGA
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEnTCCAwWgAwIBAgIUB4gIxPWJKwg5rgihBbLt/GC1ZjMwDQYJKoZIhvcNAQELBQAwPTE7MDkG
A1UEAwwyaG9zdGVkLWxvZ2luLnR1YWtpcmkuYWMubnovaG9zdGluZy9tYWxhZ2hhbi5vcmcubnow
HhcNMjIwMzE0MDMyMjQxWhcNNDIwMzA5MDMyMjQxWjA9MTswOQYDVQQDDDJob3N0ZWQtbG9naW4u
dHVha2lyaS5hYy5uei9ob3N0aW5nL21hbGFnaGFuLm9yZy5uejCCAaIwDQYJKoZIhvcNAQEBBQAD
ggGPADCCAYoCggGBAMJTXjWNUqqM7CJQN0/A4dEJIkzv3DzCy0WSeGadTzqGX6mMqjvvp+l+tuEe
OJ/V8pQU0hloVK3GiqJGrMhSXr4j9R6CkznkEa+xWGnosjarcu8xDXBAzXRJ4j64NEXT56iPa9SP
HQugjgbK6ueg98Civacm6H768/hgOG84uRBJecMRvPuBjBPikOZDp8thQEF+QpzsuqnVAK0ch9c6
EXiWY2L3V3iMieSd9kmD3nhnS9Sq84QO0+UwX4KWa1D5TkQz0kZjbHDMXJ5S0+j6X8+w7U9Lp2W+
m699+hOD0dXjzuQpv4bSh9vVJbCzSaSqfcxUOq6qFG9PMYiZGsdlGBgFrfJRJ1B1gfdQrzhvzPke
r0gPZZ+tfW2OBGeRU9oS5C93ip2KrOeQlggtQCk0BIrHcI7eAgEUwKsH6QIZ98zfh4f5IeA8LHLK
9QWu8rv93v7mTDpTAFguINA5dFcvMwL3xtJgZiucoy1FyKkg539Qi2F3mxNxF3RsdNZs7JUjzwID
AQABo4GUMIGRMHAGA1UdEQRpMGeCGmhvc3RlZC1sb2dpbi50dWFraXJpLmFjLm56hklodHRwczov
L2hvc3RlZC1sb2dpbi50dWFraXJpLmFjLm56L2hvc3RpbmcvbWFsYWdoYW4ub3JnLm56L2lkcC9z
aGliYm9sZXRoMB0GA1UdDgQWBBRiYFjC0mPB8uihdmggD+t/lgdOdjANBgkqhkiG9w0BAQsFAAOC
AYEABr6z7Ld+yDnniTy54LcEc7+VwvGbfU2Rtj/53jJ27ltU1JMuU+kugghrvbwZ+PEbkIERI2ik
G8NbpUIQoEDJPgLHMRFXoM58q4QRL8yhv8wofqXRZVwEMHEGahFukK/l4hhyWuWrXcTzr2AeM2qK
avCPCL8gAt69U3/Vr7soaFleS6T1ZS2teCw+HjF/Ye9u+L6PPgkcgSKS02VwSfynSXG/j+IhOJLt
XP162L8c/wskfYIjThCiq+ToAqTcpJY6GwH+OkNDm4m8za9fL2ibwXWLuvi0yZJ2WE5koOhtf5n9
4GFxhAHY8TB1regOUmyb4xd9jxemFWDEZRI0W79xYG3MRKrvlRBEr3pn0BahgvegjHa0npMYE2hr
WuD6tQmMwpVwzm+wxIIfwxVRnY3gInM6Yq4UM8iiyjI3WGFEHURpVJ7yMnXlaOTZJ2QXY4DoBoaL
wvcL0Kfa2RC8LuDR0YYB5wtnK9MrtyqTSO4RJa9BzyejZo656GOHwEdwpB+4
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>


        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://hosted-login.tuakiri.ac.nz/hosting/malaghan.org.nz/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://hosted-login.tuakiri.ac.nz/hosting/malaghan.org.nz/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://hosted-login.tuakiri.ac.nz/hosting/malaghan.org.nz/idp/profile/SAML2/Redirect/SLO"/>

        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>

        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://hosted-login.tuakiri.ac.nz/hosting/malaghan.org.nz/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://hosted-login.tuakiri.ac.nz/hosting/malaghan.org.nz/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://hosted-login.tuakiri.ac.nz/hosting/malaghan.org.nz/idp/profile/SAML2/Redirect/SSO"/>

        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.27856.1.2.5" FriendlyName="auEduPersonSharedToken" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:2.5.4.3" FriendlyName="cn" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:2.16.840.1.113730.3.1.241" FriendlyName="displayName" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.1" FriendlyName="eduPersonAffiliation" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.11" FriendlyName="eduPersonAssurance" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.7" FriendlyName="eduPersonEntitlement" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.5" FriendlyName="eduPersonPrimaryAffiliation" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" FriendlyName="eduPersonPrincipalName" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" FriendlyName="eduPersonScopedAffiliation" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:2.5.4.42" FriendlyName="givenName" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:0.9.2342.19200300.100.1.3" FriendlyName="mail" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:2.5.4.10" FriendlyName="o" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.25178.1.2.9" FriendlyName="schacHomeOrganization" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.25178.1.2.10" FriendlyName="schacHomeOrganizationType" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:2.5.4.4" FriendlyName="sn" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oasis:names:tc:SAML:attribute:pairwise-id" FriendlyName="samlPairwiseID" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oasis:names:tc:SAML:attribute:subject-id" FriendlyName="samlSubjectID" />
    </IDPSSODescriptor>


    <Organization>
        <OrganizationName xml:lang="en">malaghan.org.nz</OrganizationName>
        <OrganizationDisplayName xml:lang="en">Malaghan Institute of Medical Research</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">https://www.malaghan.org.nz/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="technical">
      <Company>REANNZ</Company>
      <GivenName>Tuakiri</GivenName>
      <SurName>Support</SurName>
      <EmailAddress>mailto:tuakiri@reannz.co.nz</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
      <Company>REANNZ</Company>
      <GivenName>Tuakiri</GivenName>
      <SurName>Support</SurName>
      <EmailAddress>mailto:tuakiri@reannz.co.nz</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security" xmlns:remd="http://refeds.org/metadata" >
      <Company>REANNZ</Company>
      <GivenName>Tuakiri</GivenName>
      <SurName>Security</SurName>
      <EmailAddress>mailto:security@reannz.co.nz</EmailAddress>
    </ContactPerson>

</EntityDescriptor>
