<?xml version="1.0" encoding="UTF-8"?>
<!--
     This metadata is not dynamic - it will not change as your configuration changes.
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" entityID="https://idp.th-deg.de/idp/shibboleth">

    <!-- IdP part of the config -->
    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">th-deg.de</shibmd:Scope>
            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">Deggendorf Institute of Technology</mdui:DisplayName>
                <mdui:DisplayName xml:lang="de">Technische Hochschule Deggendorf</mdui:DisplayName>
                <mdui:Description xml:lang="en">Identity Provider of the Deggendorf Institute of Technology</mdui:Description>
                <mdui:Description xml:lang="de">Identity Provider der Technischen Hochschule Deggendorf</mdui:Description>
                <mdui:Logo height="16" width="16">https://www.th-deg.de/static/images/logos/favicon.ico</mdui:Logo>
                <mdui:Logo height="80" width="80">https://idp.th-deg.de/idp/images/thd_logo_mobile.png</mdui:Logo>
            </mdui:UIInfo>
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>MIIE+TCCAuGgAwIBAgIUFvKquCJEcJg9Ceda6X5bRXyasTswDQYJKoZIhvcNAQELBQAwGDEWMBQGA1UEAxMNaWRwLnRoLWRlZy5kZTAeFw0yNTEwMDIwNzEwMzNaFw0yODEyMTUwNzEwMzNaMBgxFjAUBgNVBAMTDWlkcC50aC1kZWcuZGUwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDJ+930iVrVD1XsYJjAAaBqBO9veibZiIl1U0uU026rbhFVx9m6yHsZwI3dWiLKbfAMBSJx5N7idT1X2A6SoolJpLpGXr/ypEpKI4bUckZBh18f/tZlcrzRXnYfSeIN2qfT2nL9qTUAtiXDz8N27gs/6swJEs9nUNsSFA38tJrIvMhT3KRrr48glUaPbsO1x10Zfc6TngMlDBYgiaHRyyOOEo2Qk3vY2o+cX1pxTc6FGB55r/K350UbV1CoMtQ20ePuqmXMH5qzLKFXltIAsgiMKWE7PA36A5YyyvhWA24OUJU2URnwvfS3j+o9SbtZf1y8Qff2lpu6XIhGJYLx9aYGoSCAjNlELCHPbvt9AT2L/oYOv5nK+vfsmKQv0LDG9JT5TWi2BKm0lf5zBNLkFreRinIvMK1+NexZHHA9qm0OjEFAI84KbFB+EP46WPSacO5ev0niPiMh3I03/Cc8TXUPNJrnATS6AcxUJPqlBQhJnKzro5wmtGXEqlJjsorZFVnYHfUkJHF7YpJ0/RlOvlYCuClAU89Qx9NTJg2dBbBsbHry1ofGLMK1jhe/iz9Kd6Ma6h4SDOW+SXTV/Bzt/F933HuDg0NcokC5hsoP5v06L7YKUhMxd0am4J6QBRdLDPKb9jE03gmsazJHqJuOF14q3cWEQ4ZsYY7ykZo/1n9EhQIDAQABozswOTAYBgNVHREEETAPgg1pZHAudGgtZGVnLmRlMB0GA1UdDgQWBBQ2Vgm4La4gyUrneCTHUUV22UrHXzANBgkqhkiG9w0BAQsFAAOCAgEASiyU8Pyzz1jbCwKLO7/ZtdfbAT8HsmK9K82OFaA7ebuTxEHiIeJDjRMVjc0CrPHExnwZhF9bvovXYVG5/sg2x8HySLsl821sZbIsvMvbmfWBUD5P3KV/HY+QL/MnPijb8XWWzp5ftt7Rd8v/vte9Ch7zAfqdPV7RqUEfCuNqZOTTjmTlJsX3ILmos1aCRn/stSS+LLdRWRJZlM2mfbL1w/cLF187BIvP24/MIcikfSnUl3V9Om+7lzm8jjVecS+Q32GNAmoMzcnXcaf0ZBpCUv0+ROFawqQBQHpdKyDt4yFn7kYz7qrQ9Anv3mOkdd+pBJRZsR+/hOQagVmYmabgGnlssreDFXPq8oq9WReDsxNyWR5fFEfk+nXTc+EwBPG/UbUYYukiuhbrcVp4rE52gS8kDKfW1RE3zSWGH2Texk7lArlb4tHCfWDG90Vb5zOjZhzqxxJJAf4l2UZ3nW/87SV/+/GGNro/GrQn2fwv0ZRpeBao2a6I4N+yCsTDwc8d+Eft+zKaTr8nVwgTGoca9dXF1WI+qH7Me89K+qKxG7BC8n1a3HsC8del0oibvJy/LBVzNMksUZG4ji336y6UjR37y1uFFoism3VScHHtgsMggUg+Avk3ixUJbDMTQ4syTRJ8vEQKORaQBHD5nKy7qaCbpXd5c4+qlxAmtPNRKBE=</ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>

        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>MIIE+TCCAuGgAwIBAgIUFvKquCJEcJg9Ceda6X5bRXyasTswDQYJKoZIhvcNAQELBQAwGDEWMBQGA1UEAxMNaWRwLnRoLWRlZy5kZTAeFw0yNTEwMDIwNzEwMzNaFw0yODEyMTUwNzEwMzNaMBgxFjAUBgNVBAMTDWlkcC50aC1kZWcuZGUwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDJ+930iVrVD1XsYJjAAaBqBO9veibZiIl1U0uU026rbhFVx9m6yHsZwI3dWiLKbfAMBSJx5N7idT1X2A6SoolJpLpGXr/ypEpKI4bUckZBh18f/tZlcrzRXnYfSeIN2qfT2nL9qTUAtiXDz8N27gs/6swJEs9nUNsSFA38tJrIvMhT3KRrr48glUaPbsO1x10Zfc6TngMlDBYgiaHRyyOOEo2Qk3vY2o+cX1pxTc6FGB55r/K350UbV1CoMtQ20ePuqmXMH5qzLKFXltIAsgiMKWE7PA36A5YyyvhWA24OUJU2URnwvfS3j+o9SbtZf1y8Qff2lpu6XIhGJYLx9aYGoSCAjNlELCHPbvt9AT2L/oYOv5nK+vfsmKQv0LDG9JT5TWi2BKm0lf5zBNLkFreRinIvMK1+NexZHHA9qm0OjEFAI84KbFB+EP46WPSacO5ev0niPiMh3I03/Cc8TXUPNJrnATS6AcxUJPqlBQhJnKzro5wmtGXEqlJjsorZFVnYHfUkJHF7YpJ0/RlOvlYCuClAU89Qx9NTJg2dBbBsbHry1ofGLMK1jhe/iz9Kd6Ma6h4SDOW+SXTV/Bzt/F933HuDg0NcokC5hsoP5v06L7YKUhMxd0am4J6QBRdLDPKb9jE03gmsazJHqJuOF14q3cWEQ4ZsYY7ykZo/1n9EhQIDAQABozswOTAYBgNVHREEETAPgg1pZHAudGgtZGVnLmRlMB0GA1UdDgQWBBQ2Vgm4La4gyUrneCTHUUV22UrHXzANBgkqhkiG9w0BAQsFAAOCAgEASiyU8Pyzz1jbCwKLO7/ZtdfbAT8HsmK9K82OFaA7ebuTxEHiIeJDjRMVjc0CrPHExnwZhF9bvovXYVG5/sg2x8HySLsl821sZbIsvMvbmfWBUD5P3KV/HY+QL/MnPijb8XWWzp5ftt7Rd8v/vte9Ch7zAfqdPV7RqUEfCuNqZOTTjmTlJsX3ILmos1aCRn/stSS+LLdRWRJZlM2mfbL1w/cLF187BIvP24/MIcikfSnUl3V9Om+7lzm8jjVecS+Q32GNAmoMzcnXcaf0ZBpCUv0+ROFawqQBQHpdKyDt4yFn7kYz7qrQ9Anv3mOkdd+pBJRZsR+/hOQagVmYmabgGnlssreDFXPq8oq9WReDsxNyWR5fFEfk+nXTc+EwBPG/UbUYYukiuhbrcVp4rE52gS8kDKfW1RE3zSWGH2Texk7lArlb4tHCfWDG90Vb5zOjZhzqxxJJAf4l2UZ3nW/87SV/+/GGNro/GrQn2fwv0ZRpeBao2a6I4N+yCsTDwc8d+Eft+zKaTr8nVwgTGoca9dXF1WI+qH7Me89K+qKxG7BC8n1a3HsC8del0oibvJy/LBVzNMksUZG4ji336y6UjR37y1uFFoism3VScHHtgsMggUg+Avk3ixUJbDMTQ4syTRJ8vEQKORaQBHD5nKy7qaCbpXd5c4+qlxAmtPNRKBE=</ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.th-deg.de:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.th-deg.de:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>

	<!-- 4 Single-Logout-Services aktivieren -->
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.th-deg.de/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.th-deg.de:8443/idp/profile/SAML2/SOAP/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.th-deg.de/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.th-deg.de/idp/profile/SAML2/POST/SLO"/>

        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://idp.th-deg.de/idp/profile/SAML2/Redirect/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://idp.th-deg.de/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.th-deg.de/idp/profile/Shibboleth/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://idp.th-deg.de/idp/profile/SAML2/POST-SimpleSign/SSO"/>

	<!-- den fehlenden ECP-Endpoint hinzufügen -->
	<SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.th-deg.de/idp/profile/SAML2/SOAP/ECP"/>
				 
	<!-- die fehlenden NameID-Formate hinzufügen -->
	<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
	<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
	<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>

    </IDPSSODescriptor>


    <!--<AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">-->
    <!-- Protocol-Support für SAML2-Queries im Attribute Authority-Descriptor aktivieren -->
    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">th-deg.de</shibmd:Scope>
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>MIIE+TCCAuGgAwIBAgIUFvKquCJEcJg9Ceda6X5bRXyasTswDQYJKoZIhvcNAQELBQAwGDEWMBQGA1UEAxMNaWRwLnRoLWRlZy5kZTAeFw0yNTEwMDIwNzEwMzNaFw0yODEyMTUwNzEwMzNaMBgxFjAUBgNVBAMTDWlkcC50aC1kZWcuZGUwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDJ+930iVrVD1XsYJjAAaBqBO9veibZiIl1U0uU026rbhFVx9m6yHsZwI3dWiLKbfAMBSJx5N7idT1X2A6SoolJpLpGXr/ypEpKI4bUckZBh18f/tZlcrzRXnYfSeIN2qfT2nL9qTUAtiXDz8N27gs/6swJEs9nUNsSFA38tJrIvMhT3KRrr48glUaPbsO1x10Zfc6TngMlDBYgiaHRyyOOEo2Qk3vY2o+cX1pxTc6FGB55r/K350UbV1CoMtQ20ePuqmXMH5qzLKFXltIAsgiMKWE7PA36A5YyyvhWA24OUJU2URnwvfS3j+o9SbtZf1y8Qff2lpu6XIhGJYLx9aYGoSCAjNlELCHPbvt9AT2L/oYOv5nK+vfsmKQv0LDG9JT5TWi2BKm0lf5zBNLkFreRinIvMK1+NexZHHA9qm0OjEFAI84KbFB+EP46WPSacO5ev0niPiMh3I03/Cc8TXUPNJrnATS6AcxUJPqlBQhJnKzro5wmtGXEqlJjsorZFVnYHfUkJHF7YpJ0/RlOvlYCuClAU89Qx9NTJg2dBbBsbHry1ofGLMK1jhe/iz9Kd6Ma6h4SDOW+SXTV/Bzt/F933HuDg0NcokC5hsoP5v06L7YKUhMxd0am4J6QBRdLDPKb9jE03gmsazJHqJuOF14q3cWEQ4ZsYY7ykZo/1n9EhQIDAQABozswOTAYBgNVHREEETAPgg1pZHAudGgtZGVnLmRlMB0GA1UdDgQWBBQ2Vgm4La4gyUrneCTHUUV22UrHXzANBgkqhkiG9w0BAQsFAAOCAgEASiyU8Pyzz1jbCwKLO7/ZtdfbAT8HsmK9K82OFaA7ebuTxEHiIeJDjRMVjc0CrPHExnwZhF9bvovXYVG5/sg2x8HySLsl821sZbIsvMvbmfWBUD5P3KV/HY+QL/MnPijb8XWWzp5ftt7Rd8v/vte9Ch7zAfqdPV7RqUEfCuNqZOTTjmTlJsX3ILmos1aCRn/stSS+LLdRWRJZlM2mfbL1w/cLF187BIvP24/MIcikfSnUl3V9Om+7lzm8jjVecS+Q32GNAmoMzcnXcaf0ZBpCUv0+ROFawqQBQHpdKyDt4yFn7kYz7qrQ9Anv3mOkdd+pBJRZsR+/hOQagVmYmabgGnlssreDFXPq8oq9WReDsxNyWR5fFEfk+nXTc+EwBPG/UbUYYukiuhbrcVp4rE52gS8kDKfW1RE3zSWGH2Texk7lArlb4tHCfWDG90Vb5zOjZhzqxxJJAf4l2UZ3nW/87SV/+/GGNro/GrQn2fwv0ZRpeBao2a6I4N+yCsTDwc8d+Eft+zKaTr8nVwgTGoca9dXF1WI+qH7Me89K+qKxG7BC8n1a3HsC8del0oibvJy/LBVzNMksUZG4ji336y6UjR37y1uFFoism3VScHHtgsMggUg+Avk3ixUJbDMTQ4syTRJ8vEQKORaQBHD5nKy7qaCbpXd5c4+qlxAmtPNRKBE=</ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>

        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>MIIE+TCCAuGgAwIBAgIUFvKquCJEcJg9Ceda6X5bRXyasTswDQYJKoZIhvcNAQELBQAwGDEWMBQGA1UEAxMNaWRwLnRoLWRlZy5kZTAeFw0yNTEwMDIwNzEwMzNaFw0yODEyMTUwNzEwMzNaMBgxFjAUBgNVBAMTDWlkcC50aC1kZWcuZGUwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDJ+930iVrVD1XsYJjAAaBqBO9veibZiIl1U0uU026rbhFVx9m6yHsZwI3dWiLKbfAMBSJx5N7idT1X2A6SoolJpLpGXr/ypEpKI4bUckZBh18f/tZlcrzRXnYfSeIN2qfT2nL9qTUAtiXDz8N27gs/6swJEs9nUNsSFA38tJrIvMhT3KRrr48glUaPbsO1x10Zfc6TngMlDBYgiaHRyyOOEo2Qk3vY2o+cX1pxTc6FGB55r/K350UbV1CoMtQ20ePuqmXMH5qzLKFXltIAsgiMKWE7PA36A5YyyvhWA24OUJU2URnwvfS3j+o9SbtZf1y8Qff2lpu6XIhGJYLx9aYGoSCAjNlELCHPbvt9AT2L/oYOv5nK+vfsmKQv0LDG9JT5TWi2BKm0lf5zBNLkFreRinIvMK1+NexZHHA9qm0OjEFAI84KbFB+EP46WPSacO5ev0niPiMh3I03/Cc8TXUPNJrnATS6AcxUJPqlBQhJnKzro5wmtGXEqlJjsorZFVnYHfUkJHF7YpJ0/RlOvlYCuClAU89Qx9NTJg2dBbBsbHry1ofGLMK1jhe/iz9Kd6Ma6h4SDOW+SXTV/Bzt/F933HuDg0NcokC5hsoP5v06L7YKUhMxd0am4J6QBRdLDPKb9jE03gmsazJHqJuOF14q3cWEQ4ZsYY7ykZo/1n9EhQIDAQABozswOTAYBgNVHREEETAPgg1pZHAudGgtZGVnLmRlMB0GA1UdDgQWBBQ2Vgm4La4gyUrneCTHUUV22UrHXzANBgkqhkiG9w0BAQsFAAOCAgEASiyU8Pyzz1jbCwKLO7/ZtdfbAT8HsmK9K82OFaA7ebuTxEHiIeJDjRMVjc0CrPHExnwZhF9bvovXYVG5/sg2x8HySLsl821sZbIsvMvbmfWBUD5P3KV/HY+QL/MnPijb8XWWzp5ftt7Rd8v/vte9Ch7zAfqdPV7RqUEfCuNqZOTTjmTlJsX3ILmos1aCRn/stSS+LLdRWRJZlM2mfbL1w/cLF187BIvP24/MIcikfSnUl3V9Om+7lzm8jjVecS+Q32GNAmoMzcnXcaf0ZBpCUv0+ROFawqQBQHpdKyDt4yFn7kYz7qrQ9Anv3mOkdd+pBJRZsR+/hOQagVmYmabgGnlssreDFXPq8oq9WReDsxNyWR5fFEfk+nXTc+EwBPG/UbUYYukiuhbrcVp4rE52gS8kDKfW1RE3zSWGH2Texk7lArlb4tHCfWDG90Vb5zOjZhzqxxJJAf4l2UZ3nW/87SV/+/GGNro/GrQn2fwv0ZRpeBao2a6I4N+yCsTDwc8d+Eft+zKaTr8nVwgTGoca9dXF1WI+qH7Me89K+qKxG7BC8n1a3HsC8del0oibvJy/LBVzNMksUZG4ji336y6UjR37y1uFFoism3VScHHtgsMggUg+Avk3ixUJbDMTQ4syTRJ8vEQKORaQBHD5nKy7qaCbpXd5c4+qlxAmtPNRKBE=</ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.th-deg.de:8443/idp/profile/SAML2/SOAP/AttributeQuery"/>
        <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->
        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.th-deg.de:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>

	<!-- die fehlenden NameID-Formate hinzufügen -->
	<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
	<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
	<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>

    </AttributeAuthorityDescriptor>

    <!-- SP part, needed for connection to Azure AD -->
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
        <KeyDescriptor use="signing">
	    <ds:KeyInfo>
	        <ds:X509Data>
                    <ds:X509Certificate>MIIE+TCCAuGgAwIBAgIUFvKquCJEcJg9Ceda6X5bRXyasTswDQYJKoZIhvcNAQELBQAwGDEWMBQGA1UEAxMNaWRwLnRoLWRlZy5kZTAeFw0yNTEwMDIwNzEwMzNaFw0yODEyMTUwNzEwMzNaMBgxFjAUBgNVBAMTDWlkcC50aC1kZWcuZGUwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDJ+930iVrVD1XsYJjAAaBqBO9veibZiIl1U0uU026rbhFVx9m6yHsZwI3dWiLKbfAMBSJx5N7idT1X2A6SoolJpLpGXr/ypEpKI4bUckZBh18f/tZlcrzRXnYfSeIN2qfT2nL9qTUAtiXDz8N27gs/6swJEs9nUNsSFA38tJrIvMhT3KRrr48glUaPbsO1x10Zfc6TngMlDBYgiaHRyyOOEo2Qk3vY2o+cX1pxTc6FGB55r/K350UbV1CoMtQ20ePuqmXMH5qzLKFXltIAsgiMKWE7PA36A5YyyvhWA24OUJU2URnwvfS3j+o9SbtZf1y8Qff2lpu6XIhGJYLx9aYGoSCAjNlELCHPbvt9AT2L/oYOv5nK+vfsmKQv0LDG9JT5TWi2BKm0lf5zBNLkFreRinIvMK1+NexZHHA9qm0OjEFAI84KbFB+EP46WPSacO5ev0niPiMh3I03/Cc8TXUPNJrnATS6AcxUJPqlBQhJnKzro5wmtGXEqlJjsorZFVnYHfUkJHF7YpJ0/RlOvlYCuClAU89Qx9NTJg2dBbBsbHry1ofGLMK1jhe/iz9Kd6Ma6h4SDOW+SXTV/Bzt/F933HuDg0NcokC5hsoP5v06L7YKUhMxd0am4J6QBRdLDPKb9jE03gmsazJHqJuOF14q3cWEQ4ZsYY7ykZo/1n9EhQIDAQABozswOTAYBgNVHREEETAPgg1pZHAudGgtZGVnLmRlMB0GA1UdDgQWBBQ2Vgm4La4gyUrneCTHUUV22UrHXzANBgkqhkiG9w0BAQsFAAOCAgEASiyU8Pyzz1jbCwKLO7/ZtdfbAT8HsmK9K82OFaA7ebuTxEHiIeJDjRMVjc0CrPHExnwZhF9bvovXYVG5/sg2x8HySLsl821sZbIsvMvbmfWBUD5P3KV/HY+QL/MnPijb8XWWzp5ftt7Rd8v/vte9Ch7zAfqdPV7RqUEfCuNqZOTTjmTlJsX3ILmos1aCRn/stSS+LLdRWRJZlM2mfbL1w/cLF187BIvP24/MIcikfSnUl3V9Om+7lzm8jjVecS+Q32GNAmoMzcnXcaf0ZBpCUv0+ROFawqQBQHpdKyDt4yFn7kYz7qrQ9Anv3mOkdd+pBJRZsR+/hOQagVmYmabgGnlssreDFXPq8oq9WReDsxNyWR5fFEfk+nXTc+EwBPG/UbUYYukiuhbrcVp4rE52gS8kDKfW1RE3zSWGH2Texk7lArlb4tHCfWDG90Vb5zOjZhzqxxJJAf4l2UZ3nW/87SV/+/GGNro/GrQn2fwv0ZRpeBao2a6I4N+yCsTDwc8d+Eft+zKaTr8nVwgTGoca9dXF1WI+qH7Me89K+qKxG7BC8n1a3HsC8del0oibvJy/LBVzNMksUZG4ji336y6UjR37y1uFFoism3VScHHtgsMggUg+Avk3ixUJbDMTQ4syTRJ8vEQKORaQBHD5nKy7qaCbpXd5c4+qlxAmtPNRKBE=</ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>

        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>MIIE+TCCAuGgAwIBAgIUFvKquCJEcJg9Ceda6X5bRXyasTswDQYJKoZIhvcNAQELBQAwGDEWMBQGA1UEAxMNaWRwLnRoLWRlZy5kZTAeFw0yNTEwMDIwNzEwMzNaFw0yODEyMTUwNzEwMzNaMBgxFjAUBgNVBAMTDWlkcC50aC1kZWcuZGUwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDJ+930iVrVD1XsYJjAAaBqBO9veibZiIl1U0uU026rbhFVx9m6yHsZwI3dWiLKbfAMBSJx5N7idT1X2A6SoolJpLpGXr/ypEpKI4bUckZBh18f/tZlcrzRXnYfSeIN2qfT2nL9qTUAtiXDz8N27gs/6swJEs9nUNsSFA38tJrIvMhT3KRrr48glUaPbsO1x10Zfc6TngMlDBYgiaHRyyOOEo2Qk3vY2o+cX1pxTc6FGB55r/K350UbV1CoMtQ20ePuqmXMH5qzLKFXltIAsgiMKWE7PA36A5YyyvhWA24OUJU2URnwvfS3j+o9SbtZf1y8Qff2lpu6XIhGJYLx9aYGoSCAjNlELCHPbvt9AT2L/oYOv5nK+vfsmKQv0LDG9JT5TWi2BKm0lf5zBNLkFreRinIvMK1+NexZHHA9qm0OjEFAI84KbFB+EP46WPSacO5ev0niPiMh3I03/Cc8TXUPNJrnATS6AcxUJPqlBQhJnKzro5wmtGXEqlJjsorZFVnYHfUkJHF7YpJ0/RlOvlYCuClAU89Qx9NTJg2dBbBsbHry1ofGLMK1jhe/iz9Kd6Ma6h4SDOW+SXTV/Bzt/F933HuDg0NcokC5hsoP5v06L7YKUhMxd0am4J6QBRdLDPKb9jE03gmsazJHqJuOF14q3cWEQ4ZsYY7ykZo/1n9EhQIDAQABozswOTAYBgNVHREEETAPgg1pZHAudGgtZGVnLmRlMB0GA1UdDgQWBBQ2Vgm4La4gyUrneCTHUUV22UrHXzANBgkqhkiG9w0BAQsFAAOCAgEASiyU8Pyzz1jbCwKLO7/ZtdfbAT8HsmK9K82OFaA7ebuTxEHiIeJDjRMVjc0CrPHExnwZhF9bvovXYVG5/sg2x8HySLsl821sZbIsvMvbmfWBUD5P3KV/HY+QL/MnPijb8XWWzp5ftt7Rd8v/vte9Ch7zAfqdPV7RqUEfCuNqZOTTjmTlJsX3ILmos1aCRn/stSS+LLdRWRJZlM2mfbL1w/cLF187BIvP24/MIcikfSnUl3V9Om+7lzm8jjVecS+Q32GNAmoMzcnXcaf0ZBpCUv0+ROFawqQBQHpdKyDt4yFn7kYz7qrQ9Anv3mOkdd+pBJRZsR+/hOQagVmYmabgGnlssreDFXPq8oq9WReDsxNyWR5fFEfk+nXTc+EwBPG/UbUYYukiuhbrcVp4rE52gS8kDKfW1RE3zSWGH2Texk7lArlb4tHCfWDG90Vb5zOjZhzqxxJJAf4l2UZ3nW/87SV/+/GGNro/GrQn2fwv0ZRpeBao2a6I4N+yCsTDwc8d+Eft+zKaTr8nVwgTGoca9dXF1WI+qH7Me89K+qKxG7BC8n1a3HsC8del0oibvJy/LBVzNMksUZG4ji336y6UjR37y1uFFoism3VScHHtgsMggUg+Avk3ixUJbDMTQ4syTRJ8vEQKORaQBHD5nKy7qaCbpXd5c4+qlxAmtPNRKBE=</ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>

	<AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.th-deg.de/idp/profile/Authn/SAML2/POST/SSO" index="0"/>

    </SPSSODescriptor>
    <!-- End of SP part, needed for connection to Azure AD -->

</EntityDescriptor>
