<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" validUntil="2021-07-27T13:39:24.446Z" entityID="https://idp.hea.ie/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">hea.ie</shibmd:Scope>
<!--
    Fill in the details for your IdP here 

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">A Name for the IdP at idp.hea.ie</mdui:DisplayName>
                <mdui:Description xml:lang="en">Enter a description of your IdP at idp.hea.ie</mdui:Description>
                <mdui:Logo height="80" width="80">https://idp.hea.ie/Path/To/Logo.png</mdui:Logo>
            </mdui:UIInfo>
-->
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEEzCCAnugAwIBAgIURtN/2+SpvfNtpSLPKDvcUzF0MSIwDQYJKoZIhvcNAQEL
BQAwFTETMBEGA1UEAwwKaWRwLmhlYS5pZTAeFw0yMTA3MjcxMzM5MTFaFw00MTA3
MjcxMzM5MTFaMBUxEzARBgNVBAMMCmlkcC5oZWEuaWUwggGiMA0GCSqGSIb3DQEB
AQUAA4IBjwAwggGKAoIBgQCMaKbqxF4HkM5ze/9GcBFgOLAfggGG5l1hhVzZbm3H
2cSiasO5QpZoBcmdvCGj8KdcuwiygdVKXot742UxTaEAr0jfqfJ6a2cc6b05F0Ms
ngY9GBXWVX1NwXz2RQ8xME62mdk2BRN/Kh13iIfZuxkmiAqP5cZ7tH0km4yjpVXg
jPFcwqwzE0moKdonET14sLgLulBIAC8+mXiAbntn2ZyYbI+HwYoRxCrQksOrRZ1U
7ySAT3DmfdE0WymikHQPABZfeHU3e1d+FRDy9kzphLMq0urSPz7NCx6xHmgrT5Eo
xTy+2ALflL1iLcq0LDFuDjOQpsfXdU3wfFEA+aKD3jkKXDpekDlkLHxou6bfu6TY
fCEcJ+9jD7Qa0UR7roiXvaofF2efU3HO5yprFo4CwLuM2UNCyb1RGX96kWgAxPT9
qRMamRWARqd6V4TK4SfmpLOKVtBj1UyMZLSUDtX/B8NguKg74BhocB11JH5caDff
aoZsmNuEHQkL7YMwNa0kC8MCAwEAAaNbMFkwHQYDVR0OBBYEFEk9+npjt2gvN7Dx
I+2zusP3+4YKMDgGA1UdEQQxMC+CCmlkcC5oZWEuaWWGIWh0dHBzOi8vaWRwLmhl
YS5pZS9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAYEACLUEkTVHxwaF
XvpQPmmVFJmpqs3XWhLkQVpwGYZZLfhHOc9XU7dFjGF+Q4uAfqS3MSZ7CWu2QNIm
bZ69WUJIjeXdsKyAD2daxFiHfKn2X6E7r9eYUijq1t2GxUKxUWIuyedGajvehmys
6ExySZfa/lpAgw5hUpgIaTSZOn1gns0fL8//smjGaOyD5bfnCNlwKfhDuOq23NDX
FeBuMmBhk9f9YdrWCTCOBZalMdjo0q0Zvu5boswBRXxAzfXfYmb2x4M4RCsWZ2K1
+tMloJ3k1zjceym1MqMcb+aFM96FUhsWuekSxiuYUcrVxrST13B7LR3rmWs0QT5H
DeEOywo3jLN39RTqNqMZrn+vLJkf5oMdMVO3bnYS0Q1tqqS1hlrSr43qW+jOiWz5
GpyIF+s09hNyV8Srgt77g/yLlIuqZhD3bpPoeP3GIUYYT+DQ9OvRtmpr3ASxRBkT
8XB4szkk1a1D1ByzjlwpVJbPuMvbz1pIYVrtF+ahzJPEG0KjdaS9
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEEzCCAnugAwIBAgIUbMJzoHUvK0TFQJ54R3H/nU+UurQwDQYJKoZIhvcNAQEL
BQAwFTETMBEGA1UEAwwKaWRwLmhlYS5pZTAeFw0yMTA3MjcxMzM5MDJaFw00MTA3
MjcxMzM5MDJaMBUxEzARBgNVBAMMCmlkcC5oZWEuaWUwggGiMA0GCSqGSIb3DQEB
AQUAA4IBjwAwggGKAoIBgQCayrAJAPIPRgbYs3805IQeVP+8AbALkHFcCSCS4GND
x18cUDOFwi3fhGmOG71jkIZcqCXZ3FXQEDQgfqsA/OXBSdyAZ3IKKOkMvmurG+w9
3or64rCwKCBjknsMFBRs/Hzjp8/+c4HClJH165NRS/Pv0YbVQjNRjHM4dApstShL
a8euScm5yEXVgvTE/jlhMcXvRjRYumKY0SnyjPP9gihkOt7TTAubXliafyEupJcC
8u5jy2/CUzQA6R0kIc3Wki7/wgwk+p6PnaQll/UcWXbPVvoRyf8m8YgxkA66Xd5Z
5W0Mkh2xEk9ZdD1gUHSG6dvquBsF926O/3uEQ8Jbbp5hI/I/4Nd55GqmaynwJks1
VIZN0szkHWb5tjq0zNpWTbwViP15PJs6RfLCmAWgHZuT6i2Lng5dTs4H6b+nWwZg
e4SSQTCvv9Qo4Qh9QzFy3gLPo0Ae81ZxsJCUSgWbgMVHTrRHW8G1hWKZJ+TA4IyD
CLReckyrza0BrOyO8tO9lr8CAwEAAaNbMFkwHQYDVR0OBBYEFNPfOq68joo4Bchp
oGRW6nh+efwQMDgGA1UdEQQxMC+CCmlkcC5oZWEuaWWGIWh0dHBzOi8vaWRwLmhl
YS5pZS9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAYEAmk9ENOZINld/
Y84hNS/nJUwCPk7cgHkWOwZ7YbDZJfdFKXw9ri0Xwjky9hEpRzxxm1SMWSepDfIh
to9pb68KT35NGM2UHTyHXBJFC9BEccMt9PI8sWctmEm8ryI/LiDTskwDoNXWQ8qt
4JQDg2UltNIrtie+qAiiAs5KhYbaaixbjw+nA055YtqwyysBmM4yJHO5WRbNUjD9
wtfZOVxYaehhe13s+j7bcOFz6Vi6e0aZEhEtAjMierSeobu8bMENAI8Mq9O0xvi6
mhGyeIe8YpnEAWrhYbLoMAondC1/uaoSN/VGU9R3XH2hMdpgYUAVeve4Om9ST12w
vbBzwJILwRVQGe2la6f4udQzQcATuX8ekIoNBkoQPCeWQsQ/2cO4M1UHyGhRh4Kz
zezkgDiDyp6/TirQXjYl+DkvVc+8o3saoYR40VDlcuIjEnnfBjIUDT/FHbF5Ed7E
/jbL8AE97BMwrOCjHMXgInzt9yMCmsiwRsRrBdHFYDmoweL7uSjH
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEFDCCAnygAwIBAgIVAMUPFSn8mUF/O/g4ruzXzlD7UY//MA0GCSqGSIb3DQEB
CwUAMBUxEzARBgNVBAMMCmlkcC5oZWEuaWUwHhcNMjEwNzI3MTMzOTAyWhcNNDEw
NzI3MTMzOTAyWjAVMRMwEQYDVQQDDAppZHAuaGVhLmllMIIBojANBgkqhkiG9w0B
AQEFAAOCAY8AMIIBigKCAYEAp51PUj6P3PtQXQcHL35rQ1RwIQ3xg/1rERu26sSI
PCU+TDbWKc5L9MGg2naKTjwy1OvSUp9XHtDXIACprHzSUhm+ln5BE5B3hQQ5hW00
oM9HXJe9v+6y2/a/SkNWIaiOMPfQCSKknO9//i/BKmql250y67hN7f2IvbDHzIat
usz9VYoStrp3i0srNgP/mEq9zMEjx8TtCkGSkN74WzcBctL3pOu4E+1fL0WzaQps
PegfHX6wps+DJ6oUtbQMLwIfJiuFAyy6XMuQW8nnsprqsgxOgmcthHVwk49wWDaE
GIdclYpvTTfew/wEVog1zc0bAEfK7rEE9FPzL0EoCc9UQrV7+DgaE+wXA1/bL85T
LDWftBkgN5jh0OHc8mqjc+salkx2xlHS57A1SianOSZb1Bw7zD8zDYoUDgU79epG
qc5HQ5WZRl8MEIIkNI55J8BkVR09YvPjMOjnE3+alDgGtP7Gf9tNywAP6wEJffdm
NaSPRoQ/xGVL6UsFIGEbRlqfAgMBAAGjWzBZMB0GA1UdDgQWBBRrqn+krwuDUel2
r2HPUkiKFpsOpDA4BgNVHREEMTAvggppZHAuaGVhLmllhiFodHRwczovL2lkcC5o
ZWEuaWUvaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggGBAHoM0VTPB1JV
6q0kcmh0/xaVxknpwIMTOxCo1WepikRMwX8DXc+LCXl7Q3MHEIE823ZAhIEsLo23
S5RKRpcdfpaYTGZzPjMRzGMPYUQfJ1YhdwpDTtPt6HTb6hRbipBlVC5s4M94Pp74
4Hmh/T/fdpMvj6oy9RbNqD1Uyd/baUmOtbJp6Okz5G1ducahgibi50W+3T8zO37s
7qlIU2llAb6Wg2mPB3k0LjBJ83cgG4k8XfHYGNLBElGmdjXwKmj0LCzbMoLe4U9O
Sh4hDY87CRWAdOcvTSWkhrmH3l9g9b3uOAoA76Y2dIGWL7ZaigbjTm/MFiPUGnvp
51cG0oxX0lWjZP4dUH3WAAqqjUNCDQKZHReW8D/B0okQF4m7GVFA7dLWE5/2LtFe
yxNEUfp+b8P9zOHHTV8SS6BGrLj2LfMsep+7wBBYBeNQbgpqwBfZIqQgbe9UWtgf
tUQIJpzVlVRdpa+hHYcBJE6D1iNJLZQ4NWjDoXlDByLQK2JyaJI+QA==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.hea.ie:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.hea.ie:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>

        <!--
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.hea.ie/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.hea.ie/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.hea.ie/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.hea.ie:8443/idp/profile/SAML2/SOAP/SLO"/>
        -->

        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.hea.ie/idp/profile/Shibboleth/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://idp.hea.ie/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://idp.hea.ie/idp/profile/SAML2/Redirect/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://idp.hea.ie/idp/profile/SAML2/POST/SSO"/>

    </IDPSSODescriptor>


    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">hea.ie</shibmd:Scope>
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEEzCCAnugAwIBAgIURtN/2+SpvfNtpSLPKDvcUzF0MSIwDQYJKoZIhvcNAQEL
BQAwFTETMBEGA1UEAwwKaWRwLmhlYS5pZTAeFw0yMTA3MjcxMzM5MTFaFw00MTA3
MjcxMzM5MTFaMBUxEzARBgNVBAMMCmlkcC5oZWEuaWUwggGiMA0GCSqGSIb3DQEB
AQUAA4IBjwAwggGKAoIBgQCMaKbqxF4HkM5ze/9GcBFgOLAfggGG5l1hhVzZbm3H
2cSiasO5QpZoBcmdvCGj8KdcuwiygdVKXot742UxTaEAr0jfqfJ6a2cc6b05F0Ms
ngY9GBXWVX1NwXz2RQ8xME62mdk2BRN/Kh13iIfZuxkmiAqP5cZ7tH0km4yjpVXg
jPFcwqwzE0moKdonET14sLgLulBIAC8+mXiAbntn2ZyYbI+HwYoRxCrQksOrRZ1U
7ySAT3DmfdE0WymikHQPABZfeHU3e1d+FRDy9kzphLMq0urSPz7NCx6xHmgrT5Eo
xTy+2ALflL1iLcq0LDFuDjOQpsfXdU3wfFEA+aKD3jkKXDpekDlkLHxou6bfu6TY
fCEcJ+9jD7Qa0UR7roiXvaofF2efU3HO5yprFo4CwLuM2UNCyb1RGX96kWgAxPT9
qRMamRWARqd6V4TK4SfmpLOKVtBj1UyMZLSUDtX/B8NguKg74BhocB11JH5caDff
aoZsmNuEHQkL7YMwNa0kC8MCAwEAAaNbMFkwHQYDVR0OBBYEFEk9+npjt2gvN7Dx
I+2zusP3+4YKMDgGA1UdEQQxMC+CCmlkcC5oZWEuaWWGIWh0dHBzOi8vaWRwLmhl
YS5pZS9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAYEACLUEkTVHxwaF
XvpQPmmVFJmpqs3XWhLkQVpwGYZZLfhHOc9XU7dFjGF+Q4uAfqS3MSZ7CWu2QNIm
bZ69WUJIjeXdsKyAD2daxFiHfKn2X6E7r9eYUijq1t2GxUKxUWIuyedGajvehmys
6ExySZfa/lpAgw5hUpgIaTSZOn1gns0fL8//smjGaOyD5bfnCNlwKfhDuOq23NDX
FeBuMmBhk9f9YdrWCTCOBZalMdjo0q0Zvu5boswBRXxAzfXfYmb2x4M4RCsWZ2K1
+tMloJ3k1zjceym1MqMcb+aFM96FUhsWuekSxiuYUcrVxrST13B7LR3rmWs0QT5H
DeEOywo3jLN39RTqNqMZrn+vLJkf5oMdMVO3bnYS0Q1tqqS1hlrSr43qW+jOiWz5
GpyIF+s09hNyV8Srgt77g/yLlIuqZhD3bpPoeP3GIUYYT+DQ9OvRtmpr3ASxRBkT
8XB4szkk1a1D1ByzjlwpVJbPuMvbz1pIYVrtF+ahzJPEG0KjdaS9
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEEzCCAnugAwIBAgIUbMJzoHUvK0TFQJ54R3H/nU+UurQwDQYJKoZIhvcNAQEL
BQAwFTETMBEGA1UEAwwKaWRwLmhlYS5pZTAeFw0yMTA3MjcxMzM5MDJaFw00MTA3
MjcxMzM5MDJaMBUxEzARBgNVBAMMCmlkcC5oZWEuaWUwggGiMA0GCSqGSIb3DQEB
AQUAA4IBjwAwggGKAoIBgQCayrAJAPIPRgbYs3805IQeVP+8AbALkHFcCSCS4GND
x18cUDOFwi3fhGmOG71jkIZcqCXZ3FXQEDQgfqsA/OXBSdyAZ3IKKOkMvmurG+w9
3or64rCwKCBjknsMFBRs/Hzjp8/+c4HClJH165NRS/Pv0YbVQjNRjHM4dApstShL
a8euScm5yEXVgvTE/jlhMcXvRjRYumKY0SnyjPP9gihkOt7TTAubXliafyEupJcC
8u5jy2/CUzQA6R0kIc3Wki7/wgwk+p6PnaQll/UcWXbPVvoRyf8m8YgxkA66Xd5Z
5W0Mkh2xEk9ZdD1gUHSG6dvquBsF926O/3uEQ8Jbbp5hI/I/4Nd55GqmaynwJks1
VIZN0szkHWb5tjq0zNpWTbwViP15PJs6RfLCmAWgHZuT6i2Lng5dTs4H6b+nWwZg
e4SSQTCvv9Qo4Qh9QzFy3gLPo0Ae81ZxsJCUSgWbgMVHTrRHW8G1hWKZJ+TA4IyD
CLReckyrza0BrOyO8tO9lr8CAwEAAaNbMFkwHQYDVR0OBBYEFNPfOq68joo4Bchp
oGRW6nh+efwQMDgGA1UdEQQxMC+CCmlkcC5oZWEuaWWGIWh0dHBzOi8vaWRwLmhl
YS5pZS9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAYEAmk9ENOZINld/
Y84hNS/nJUwCPk7cgHkWOwZ7YbDZJfdFKXw9ri0Xwjky9hEpRzxxm1SMWSepDfIh
to9pb68KT35NGM2UHTyHXBJFC9BEccMt9PI8sWctmEm8ryI/LiDTskwDoNXWQ8qt
4JQDg2UltNIrtie+qAiiAs5KhYbaaixbjw+nA055YtqwyysBmM4yJHO5WRbNUjD9
wtfZOVxYaehhe13s+j7bcOFz6Vi6e0aZEhEtAjMierSeobu8bMENAI8Mq9O0xvi6
mhGyeIe8YpnEAWrhYbLoMAondC1/uaoSN/VGU9R3XH2hMdpgYUAVeve4Om9ST12w
vbBzwJILwRVQGe2la6f4udQzQcATuX8ekIoNBkoQPCeWQsQ/2cO4M1UHyGhRh4Kz
zezkgDiDyp6/TirQXjYl+DkvVc+8o3saoYR40VDlcuIjEnnfBjIUDT/FHbF5Ed7E
/jbL8AE97BMwrOCjHMXgInzt9yMCmsiwRsRrBdHFYDmoweL7uSjH
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEFDCCAnygAwIBAgIVAMUPFSn8mUF/O/g4ruzXzlD7UY//MA0GCSqGSIb3DQEB
CwUAMBUxEzARBgNVBAMMCmlkcC5oZWEuaWUwHhcNMjEwNzI3MTMzOTAyWhcNNDEw
NzI3MTMzOTAyWjAVMRMwEQYDVQQDDAppZHAuaGVhLmllMIIBojANBgkqhkiG9w0B
AQEFAAOCAY8AMIIBigKCAYEAp51PUj6P3PtQXQcHL35rQ1RwIQ3xg/1rERu26sSI
PCU+TDbWKc5L9MGg2naKTjwy1OvSUp9XHtDXIACprHzSUhm+ln5BE5B3hQQ5hW00
oM9HXJe9v+6y2/a/SkNWIaiOMPfQCSKknO9//i/BKmql250y67hN7f2IvbDHzIat
usz9VYoStrp3i0srNgP/mEq9zMEjx8TtCkGSkN74WzcBctL3pOu4E+1fL0WzaQps
PegfHX6wps+DJ6oUtbQMLwIfJiuFAyy6XMuQW8nnsprqsgxOgmcthHVwk49wWDaE
GIdclYpvTTfew/wEVog1zc0bAEfK7rEE9FPzL0EoCc9UQrV7+DgaE+wXA1/bL85T
LDWftBkgN5jh0OHc8mqjc+salkx2xlHS57A1SianOSZb1Bw7zD8zDYoUDgU79epG
qc5HQ5WZRl8MEIIkNI55J8BkVR09YvPjMOjnE3+alDgGtP7Gf9tNywAP6wEJffdm
NaSPRoQ/xGVL6UsFIGEbRlqfAgMBAAGjWzBZMB0GA1UdDgQWBBRrqn+krwuDUel2
r2HPUkiKFpsOpDA4BgNVHREEMTAvggppZHAuaGVhLmllhiFodHRwczovL2lkcC5o
ZWEuaWUvaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggGBAHoM0VTPB1JV
6q0kcmh0/xaVxknpwIMTOxCo1WepikRMwX8DXc+LCXl7Q3MHEIE823ZAhIEsLo23
S5RKRpcdfpaYTGZzPjMRzGMPYUQfJ1YhdwpDTtPt6HTb6hRbipBlVC5s4M94Pp74
4Hmh/T/fdpMvj6oy9RbNqD1Uyd/baUmOtbJp6Okz5G1ducahgibi50W+3T8zO37s
7qlIU2llAb6Wg2mPB3k0LjBJ83cgG4k8XfHYGNLBElGmdjXwKmj0LCzbMoLe4U9O
Sh4hDY87CRWAdOcvTSWkhrmH3l9g9b3uOAoA76Y2dIGWL7ZaigbjTm/MFiPUGnvp
51cG0oxX0lWjZP4dUH3WAAqqjUNCDQKZHReW8D/B0okQF4m7GVFA7dLWE5/2LtFe
yxNEUfp+b8P9zOHHTV8SS6BGrLj2LfMsep+7wBBYBeNQbgpqwBfZIqQgbe9UWtgf
tUQIJpzVlVRdpa+hHYcBJE6D1iNJLZQ4NWjDoXlDByLQK2JyaJI+QA==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <!-- <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.hea.ie:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> -->
        <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->
        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.hea.ie:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>

    </AttributeAuthorityDescriptor>

    <!-- New SP block -->
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
 
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
MIIDFDCCAfygAwIBAgIVAP/wzz9ofeGBqzdIklz+3Vu+8wsxMA0GCSqGSIb3DQEB
BQUAMBUxEzARBgNVBAMTCmlkcC5oZWEuaWUwHhcNMTQwMjEwMTE1NzE5WhcNMzQw
MjEwMTE1NzE5WjAVMRMwEQYDVQQDEwppZHAuaGVhLmllMIIBIjANBgkqhkiG9w0B
AQEFAAOCAQ8AMIIBCgKCAQEAqagqDt+UqXunyajTqtGR/dtFAk27xsXNf5Kbe1tL
SdUQiUobGZu0bwaUWXeWel4nq+JdDUU08ZCZK8On7kblJkrpfQ22AppzNot4cees
ovjAMPQZlCKR0HXFn/ME/c5VCW8Yfh04wT20o73KQq8d+KPtKW8i0qu5RCAI+w7G
wgHD4v5+rwuLah3nYI4Udml3IWGQEVw+fMq37Do+Z+RGxHUWL/xEJCdVkTZBSGXk
1fV7T2XkYYXNfPreddndPAgw2N8cAPJrpr9rqZmJlFAULaKb1vk9zQJ0lm1dOEzi
Hsv4pVZGfDmFQtNW9Blh0nrrclq7jhw7Rffzm8F8UxLW5wIDAQABo1swWTA4BgNV
HREEMTAvggppZHAuaGVhLmllhiFodHRwczovL2lkcC5oZWEuaWUvaWRwL3NoaWJi
b2xldGgwHQYDVR0OBBYEFPc684+HhKjXb/u71yOUcWJUMnCKMA0GCSqGSIb3DQEB
BQUAA4IBAQCBopzYeYC/QudXVEZWc6Nw5fMALyYOksOi/XCoMM24hNfJrtt6+88N
WijMP+SA1E5i9jUJL1rbHqvnGpnWfSiTNmFILbnpy4DrNXFC1/osrC2FCRkHU/kX
Tn7T3LMDQEmgD1NIpmtnchrU4csGsuHaJPOAK59F4oV05hztv98bhzX8Y5D3/P0L
6U4AELLFOq5offi8kGmIZc78kSSI1ukCXoaKI7k1HWXTlY+zoCsPnRmySGAGYKlo
u71rxzlFXtZm0WtWZDUtO3vt6JqgGeBiS9z4sC790VypY2buf+s+OxcVA8ljf1cL
CZaG8uOZUP4WOr2r79dyXd2+eMAj5zvC
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
MIIDFDCCAfygAwIBAgIVAP/wzz9ofeGBqzdIklz+3Vu+8wsxMA0GCSqGSIb3DQEB
BQUAMBUxEzARBgNVBAMTCmlkcC5oZWEuaWUwHhcNMTQwMjEwMTE1NzE5WhcNMzQw
MjEwMTE1NzE5WjAVMRMwEQYDVQQDEwppZHAuaGVhLmllMIIBIjANBgkqhkiG9w0B
AQEFAAOCAQ8AMIIBCgKCAQEAqagqDt+UqXunyajTqtGR/dtFAk27xsXNf5Kbe1tL
SdUQiUobGZu0bwaUWXeWel4nq+JdDUU08ZCZK8On7kblJkrpfQ22AppzNot4cees
ovjAMPQZlCKR0HXFn/ME/c5VCW8Yfh04wT20o73KQq8d+KPtKW8i0qu5RCAI+w7G
wgHD4v5+rwuLah3nYI4Udml3IWGQEVw+fMq37Do+Z+RGxHUWL/xEJCdVkTZBSGXk
1fV7T2XkYYXNfPreddndPAgw2N8cAPJrpr9rqZmJlFAULaKb1vk9zQJ0lm1dOEzi
Hsv4pVZGfDmFQtNW9Blh0nrrclq7jhw7Rffzm8F8UxLW5wIDAQABo1swWTA4BgNV
HREEMTAvggppZHAuaGVhLmllhiFodHRwczovL2lkcC5oZWEuaWUvaWRwL3NoaWJi
b2xldGgwHQYDVR0OBBYEFPc684+HhKjXb/u71yOUcWJUMnCKMA0GCSqGSIb3DQEB
BQUAA4IBAQCBopzYeYC/QudXVEZWc6Nw5fMALyYOksOi/XCoMM24hNfJrtt6+88N
WijMP+SA1E5i9jUJL1rbHqvnGpnWfSiTNmFILbnpy4DrNXFC1/osrC2FCRkHU/kX
Tn7T3LMDQEmgD1NIpmtnchrU4csGsuHaJPOAK59F4oV05hztv98bhzX8Y5D3/P0L
6U4AELLFOq5offi8kGmIZc78kSSI1ukCXoaKI7k1HWXTlY+zoCsPnRmySGAGYKlo
u71rxzlFXtZm0WtWZDUtO3vt6JqgGeBiS9z4sC790VypY2buf+s+OxcVA8ljf1cL
CZaG8uOZUP4WOr2r79dyXd2+eMAj5zvC
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
 
    <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.hea.ie/idp/profile/Authn/SAML2/POST/SSO" index="0"/>
</SPSSODescriptor>

</EntityDescriptor>
