<?xml version="1.0" encoding="UTF-8"?>
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" entityID="https://hosted-login.tuakiri.ac.nz/hosting/toiohomai.ac.nz/idp/shibboleth">

    <Extensions>
      <mdrpi:RegistrationInfo registrationAuthority="https://tuakiri.ac.nz/" registrationInstant="2022-09-12T22:09:08Z" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi">
        <mdrpi:RegistrationPolicy xml:lang="en">https://tuakiri.ac.nz/documents/tuakiri-mrps-1.0.pdf</mdrpi:RegistrationPolicy>
      </mdrpi:RegistrationInfo>
      <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
        <saml:Attribute Name="http://macedir.org/entity-category-support" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
          <saml:AttributeValue>http://refeds.org/category/research-and-scholarship</saml:AttributeValue>
        </saml:Attribute>
        <saml:Attribute Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
          <saml:AttributeValue>https://refeds.org/sirtfi</saml:AttributeValue>
        </saml:Attribute>
      </mdattr:EntityAttributes>
    </Extensions>

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">toiohomai.ac.nz</shibmd:Scope>
            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">Toi Ohomai</mdui:DisplayName>
                <mdui:Logo xml:lang="en" height="150" width="326">https://hosted-login.tuakiri.ac.nz/hosting/toiohomai.ac.nz/idp/images/logo.png</mdui:Logo>
            </mdui:UIInfo>
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEnTCCAwWgAwIBAgIUOw6N8zlFOXjoHSTS2o/fI4NjtGcwDQYJKoZIhvcNAQELBQAwPTE7MDkG
A1UEAwwyaG9zdGVkLWxvZ2luLnR1YWtpcmkuYWMubnovaG9zdGluZy90b2lvaG9tYWkuYWMubnow
HhcNMjIwOTE5MjMyOTMxWhcNNDIwOTE0MjMyOTMxWjA9MTswOQYDVQQDDDJob3N0ZWQtbG9naW4u
dHVha2lyaS5hYy5uei9ob3N0aW5nL3RvaW9ob21haS5hYy5uejCCAaIwDQYJKoZIhvcNAQEBBQAD
ggGPADCCAYoCggGBAMJHGd2kIo1mcLrHqTQoMQlNazmhNSWhC/yaLxxSm7v57FBv7GWT1t5JjmCX
ZU4Rks7/gkp5VcPQaGUFBnulh5rqI+8icmMkMcdLogoe8r/yXrICmlKy6XADx44tEGF8PDnCfCL/
NcnbWSXdG+EX7U5Lb8RpwriXhB3WkVMILzA2rqZCgYboVU1efWtWXU+laMqu6HIde1yvGXYkhyt+
MmazI6IqGn61QLX+Oe08rkBpqaZaf9yT3rDsJz/y3fUjbrwYaeHv4g0ivCC9aXlZp1FpbIH03kLz
VNIy6jYE2oKALGzlN1VNqlxPzITqoGykmXdwns5Lif97lZYcDv50ubN03dnYcEHpEBCQkNrXyX4Z
cSi75HpFwzqtMW7SHYiksqe2xWCdA9nRzuBnR4gp73Gff+ul3+bdlUxdYq3A4CxlsQpVfHO2Mt9n
m8ZVVuVp0bNbGEp7CFskHlxci5xRuJXXor4tqNwvTe6aBQe8hTv1j/4ZybHror29ZCxxDjHRYQID
AQABo4GUMIGRMHAGA1UdEQRpMGeCGmhvc3RlZC1sb2dpbi50dWFraXJpLmFjLm56hklodHRwczov
L2hvc3RlZC1sb2dpbi50dWFraXJpLmFjLm56L2hvc3RpbmcvdG9pb2hvbWFpLmFjLm56L2lkcC9z
aGliYm9sZXRoMB0GA1UdDgQWBBQGL2tyun0skgWYBxn3kCFlUgT4GDANBgkqhkiG9w0BAQsFAAOC
AYEAmBgtYIwo1nsor3zsv5ZykEfyNlWJrpd3TJCUFVWE1uZyZT8f/PfTft6DfNJ2XPQLD/Y1rlww
B6Rw+ziqV71mN/sh6I1xj0eD5Ymzte5hmAXvXPZY/fy5F5zmiXG/0buInaN014SUTevDuf0HZ5HD
xaze3i/jv5lKC6vmcgjhUxNYED07X02npjxzBerMpm/Wr9BBrbY5aru4TxGykt1vLKgM02qtcQw2
YGkytCWgebiitPQuw/k+XPDtwmJ2nw+Q+rlEZvkSQQ80Mo2MyT1+wpmsS9eCg6kdSx/MfSw0Q1Nz
Lwmopj5ykj/IUbg6AUMqgqVMSFjBVF4z/V4p26pYlw7eVoxgfMRTQ5aO3STqxA9FTRUlk/+vQF2O
0cDyXCZ9/wRjMczt2n+9guu+4IWKt7QhB5iK+kOa67yWDozUBGz/+1pviHRkHzryGv8Xom2UaXd7
kbSDqc+o4ziiO5zMmrb+v5qtqLa84VpXeQ8wwop+plYJN0z+4o8Byny06yIq
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEnTCCAwWgAwIBAgIUHOhUd61p/pGxANOzDiCw0z1AgsUwDQYJKoZIhvcNAQELBQAwPTE7MDkG
A1UEAwwyaG9zdGVkLWxvZ2luLnR1YWtpcmkuYWMubnovaG9zdGluZy90b2lvaG9tYWkuYWMubnow
HhcNMjIwOTE5MjMyOTM1WhcNNDIwOTE0MjMyOTM1WjA9MTswOQYDVQQDDDJob3N0ZWQtbG9naW4u
dHVha2lyaS5hYy5uei9ob3N0aW5nL3RvaW9ob21haS5hYy5uejCCAaIwDQYJKoZIhvcNAQEBBQAD
ggGPADCCAYoCggGBANKwR+5eDW9mLtjPM7REoG/Cjg5bBBvoIZsbH3wetvv/emCc+ne4/l7kBuz0
vXqEnLJjDUuaKifxKi30otd7AfzbF25wAw/w5A25ocvmJ0rC5VljApZgB0racxDiNANNQ7/BisY5
/RIuDJQJDAsoKKNUpJEaAPgn+UL1cuxxspVjMhhBeg3Kk/g3mFLKThcMjXQ2zZIJphQOAcWuA2kO
amJR1GEiRXYQItgDrmO/BAgQQr6rtZwDGUvEigAe0MQjProzuqt2seF9WclO83MXE3SQtdsPFHlq
ZHUHTB07jHPk3fYS+2kGHqKCUu8org5wXVTUqGLetlFT7fAZfizjUgu0PkBrOuI7K9iq56P6k0CD
dhDIRfC+OD31cpNXb5zgkeVdg8KhUVa8ePp9UpUVcaLTRzkI+JUEihZ5eYVPl4MEqf982UJfWPsu
GHvzRTLoNadAHBe+RjODHNJzAtElzYNMMG3jSYHl8erjDAyq2CFvuugQtug6rGtF8+FuUDXqpwID
AQABo4GUMIGRMHAGA1UdEQRpMGeCGmhvc3RlZC1sb2dpbi50dWFraXJpLmFjLm56hklodHRwczov
L2hvc3RlZC1sb2dpbi50dWFraXJpLmFjLm56L2hvc3RpbmcvdG9pb2hvbWFpLmFjLm56L2lkcC9z
aGliYm9sZXRoMB0GA1UdDgQWBBTfPObKk2SPCOk+za4NV6dZNSzYTjANBgkqhkiG9w0BAQsFAAOC
AYEAj70F/Fz0Twyv9HJ55WSzuZQ2pot2S+huT/2752czms0DK74SZRczUHj2sTMljZKMwB9OwUAR
AbhzcavVBBGmcb7i6pq0UWF8xxa05G9nS30rxwMtRjeL2oE79HtCrz6a0Hc/Avlse7mcMSpPkDke
qNW8jOXO7QW5pGSO/g5jmsDLrxxW2aDmBGgW3bMgmEevq++9UdTZmBC1Qdw/1wSM3o3Z8npifgim
WFwmVPWmD6Bu+5xslcgpgnK+lDi4RIy2WOAN0sNVa70VuqZMb7rlHOC/4aYIersNOvPxi9cdqTuL
JOzx654wB1QXJQo7Gdv8RLhOsazJMe9avy4NsS4ZGiyjjO2i0uv/MaTBXeSmracvCClEYo9WAKqr
5IG8sqpA+5QhRA+EmMaif9oF8hHWzkOSgcRKbYiSz0xC8BTHENlztVZq3gPMdYqUdgJOO1+2oSXQ
x/cd8Duu9+MWtrI8H6GjEeWLwGTLqf1VUP+yX6jxeHSux3vCcZFEeJjOxc3c
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>


        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://hosted-login.tuakiri.ac.nz/hosting/toiohomai.ac.nz/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://hosted-login.tuakiri.ac.nz/hosting/toiohomai.ac.nz/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://hosted-login.tuakiri.ac.nz/hosting/toiohomai.ac.nz/idp/profile/SAML2/Redirect/SLO"/>

        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>

        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://hosted-login.tuakiri.ac.nz/hosting/toiohomai.ac.nz/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://hosted-login.tuakiri.ac.nz/hosting/toiohomai.ac.nz/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://hosted-login.tuakiri.ac.nz/hosting/toiohomai.ac.nz/idp/profile/SAML2/Redirect/SSO"/>

        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.27856.1.2.5" FriendlyName="auEduPersonSharedToken" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:2.5.4.3" FriendlyName="cn" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:2.16.840.1.113730.3.1.241" FriendlyName="displayName" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.1" FriendlyName="eduPersonAffiliation" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.11" FriendlyName="eduPersonAssurance" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.7" FriendlyName="eduPersonEntitlement" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.5" FriendlyName="eduPersonPrimaryAffiliation" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" FriendlyName="eduPersonPrincipalName" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" FriendlyName="eduPersonScopedAffiliation" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:2.5.4.42" FriendlyName="givenName" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:0.9.2342.19200300.100.1.3" FriendlyName="mail" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:2.5.4.10" FriendlyName="o" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.25178.1.2.9" FriendlyName="schacHomeOrganization" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.25178.1.2.10" FriendlyName="schacHomeOrganizationType" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:2.5.4.4" FriendlyName="sn" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oasis:names:tc:SAML:attribute:pairwise-id" FriendlyName="samlPairwiseID" />
        <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oasis:names:tc:SAML:attribute:subject-id" FriendlyName="samlSubjectID" />
    </IDPSSODescriptor>


    <Organization>
        <OrganizationName xml:lang="en">toiohomai.ac.nz</OrganizationName>
        <OrganizationDisplayName xml:lang="en">Toi Ohomai</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">https://www.toiohomai.ac.nz/</OrganizationURL>
    </Organization>
    <ContactPerson contactType="technical">
      <Company>REANNZ</Company>
      <GivenName>Tuakiri</GivenName>
      <SurName>Support</SurName>
      <EmailAddress>mailto:tuakiri@reannz.co.nz</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="administrative">
      <Company>REANNZ</Company>
      <GivenName>Tuakiri</GivenName>
      <SurName>Support</SurName>
      <EmailAddress>mailto:tuakiri@reannz.co.nz</EmailAddress>
    </ContactPerson>
    <ContactPerson contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security" xmlns:remd="http://refeds.org/metadata" >
      <Company>REANNZ</Company>
      <GivenName>Tuakiri</GivenName>
      <SurName>Security</SurName>
      <EmailAddress>mailto:security@reannz.co.nz</EmailAddress>
    </ContactPerson>

</EntityDescriptor>
