<?xml version='1.0' encoding='UTF-8'?>
<md:EntitiesDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xrd="http://docs.oasis-open.org/ns/xri/xrd-1.0" xmlns:pyff="http://pyff.io/NS" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ser="http://eidas.europa.eu/metadata/servicelist" xmlns:eidas="http://eidas.europa.eu/saml-extensions" xmlns:ti="https://seamlessaccess.org/NS/trustinfo" xmlns:ns0="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ns1="http://www.w3.org/2000/09/xmldsig#" xmlns:ns2="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:ns3="urn:mace:shibboleth:metadata:1.0" Name="SURF Research Access Management" ID="_20260309T210006Z" validUntil="2026-03-23T21:00:06Z" cacheDuration="P7D"><ds:Signature><ds:SignedInfo><ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/><ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/><ds:Reference URI="#_20260309T210006Z"><ds:Transforms><ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/><ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#WithComments"/></ds:Transforms><ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/><ds:DigestValue>SsblV25THQYKnBQw+E7LhU9o8lxEbY+PIbAjofIllK4=</ds:DigestValue></ds:Reference></ds:SignedInfo><ds:SignatureValue>Y9UiDcrCwu0B8WIQPJY7sbx5N9Xpiwn10j+JJBFr4f4l0siYQ4QV87XhKpRjbTKBloZ+jhal5W87rsdobWSc6tgnCnDYvSaCFBqzxwnQtiH0Vy/oQxgZIBE6b/mmPe5oLWIWT/i9oKd4WUrhaAQmb3XHl/y1vpM6yA7V7TSn6LLQCAeMRFdicwwVIAULII71Ecrc5YBT+XzARexsK28wza6eN54sJpXy1ZVBE4MHitCpDo5nCP8zYLF+XfvhcCXLLIXczGZZuTjDTJe+r0ckkLg2GnOaM3PXBDf+oNDSBVoLIWOUGyilwXJBwuP4vPtTvDV/3DfUEZLar8hRHAf/Rg==</ds:SignatureValue><ds:KeyInfo><ds:X509Data><ds:X509Certificate>MIIDDjCCAfYCBS8Ikn8EMA0GCSqGSIb3DQEBCwUAMEsxCzAJBgNVBAYTAk5MMQ0w
CwYDVQQKEwRTVVJGMREwDwYDVQQLEwhTZXJ2aWNlczEaMBgGA1UEAxMRbWV0YS5z
cmFtLnN1cmYubmwwHhcNMjAwNzI4MTIxMjA4WhcNMzAwNzI2MTIxMjA4WjBLMQsw
CQYDVQQGEwJOTDENMAsGA1UEChMEU1VSRjERMA8GA1UECxMIU2VydmljZXMxGjAY
BgNVBAMTEW1ldGEuc3JhbS5zdXJmLm5sMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
MIIBCgKCAQEA7PydIyMo2RJRn6P5XpWrep/SzxUu2gLE3Cb34L9p68fL+CEeWwPZ
mWjspfhLvAe9+ocu2CwvNfyazc3fMxNJfnb+aIVvgw6cAXtUua3xh39bPS3vKkpo
rx7DkSQjqy78sbT2rllUG3AU9amFv5u32ZtYTSH/wm5Ny3VeG5Fp+Bo5Nd+oRZHq
rzdKGAeqQgmfRPSZ1FkbwKVhZe2faNp3P/cQBaM7f7wF7U92fk3gCMkS4uFhc/74
Ceyn9ht5UIwS64lD0mgsOCL7YIB3BzQ0lbiIK6Ps19VLwDMr2OoOLn6eBmlg0l9c
pfoEMQqzfiVnVqE+1IYIzPTHfhMhPKsCswIDAQABMA0GCSqGSIb3DQEBCwUAA4IB
AQAPePNDj14Ho79689ypNfgx/PD8Dr8Mq0veiqQ6i76ADS5+te+wvAfIdDUAcODi
aSbgfSCIUeKW574YfWqthpq6fiqY/pdLsAjquQVQYIeGP/EbyZcR5sHotuSZFv5C
YcK2EqZ2Zbj1Zj5IO1sjXK0zfz25iGAvspQXkdQ5UcoD2FbCBCKjjavM+wA33JjO
NQxqErDu7rKYNpd1jHPtCXL9aZFBDzxOGdTefzR33gkPRuYMogijE3KDOSUdZCt/
LhnrYi43SIe48i12pdHqi748Ln99EZxhHPQlZk5XUguqMziIN5j3DUU/RPvIQSiS
PX/6xOGO6m+bA2QUx/1XzPDY</ds:X509Certificate></ds:X509Data></ds:KeyInfo></ds:Signature><md:EntityDescriptor entityID="https://proxy.sram.surf.nl/proxy">
  
  <md:Extensions>
    <ns2:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
    <ns2:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
    <ns2:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
    <ns2:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/>
    <ns2:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/>
    <ns2:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/>
    <ns2:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/>
    <ns2:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
    <ns2:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
    <ns2:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
  <mdattr:EntityAttributes><saml:Attribute Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml:AttributeValue>https://refeds.org/sirtfi2</saml:AttributeValue><saml:AttributeValue>https://refeds.org/sirtfi</saml:AttributeValue></saml:Attribute><saml:Attribute Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml:AttributeValue>http://refeds.org/category/research-and-scholarship</saml:AttributeValue><saml:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</saml:AttributeValue></saml:Attribute></mdattr:EntityAttributes></md:Extensions>
  <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" WantAuthnRequestsSigned="false">
    <md:Extensions>
      <shibmd:Scope regexp="false">sram.surf.nl</shibmd:Scope>
    </md:Extensions>
    <md:KeyDescriptor use="signing">
      <ds:KeyInfo>
        <ds:X509Data>
          <ds:X509Certificate>MIIC1jCCAb4CCQCBbqCKfgja2jANBgkqhkiG9w0BAQsFADAtMSswKQYDVQQDDCJzdXJmX3JhbSBwcm9kIHByb3h5IHNhbWwyX2Zyb250ZW5kMB4XDTIwMDUyODEwNTQzNVoXDTMwMDUyNjEwNTQzNVowLTErMCkGA1UEAwwic3VyZl9yYW0gcHJvZCBwcm94eSBzYW1sMl9mcm9udGVuZDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJnJrjVymfyHXB65lazQbn2Yoa2stavsok7ssXcBBXk2ID/GUQ0TBppTXi0oXCjoqD5zaQCqocPim86vfGh8r/K/hWY+tn7ZJZB53PTuaiGKaa124+xMPwIPIKO7YGQpf2hj3ek+EFAFakZ6PRL9EvZp/7r43vU1wg/EMWmQG9ktpvGDvY8Tu8zJfxYTznVHqO/lUPwnN7gVylM/FXKb3dmTLwzzvSmFjY06KEB+kWdk8GnpDa9Y367ddHhQ9VtEwUpZ93H7AAdx4zQZlCx2gKTeuSkqglKUzWX+pJKcjLwNBA7oMo9+hoHq2Yl0h04e4LWmhvmRmGemS7jw+bvRyHECAwEAATANBgkqhkiG9w0BAQsFAAOCAQEACm9L6DmOnZWIX5w/5xNJEQSoQcrDOzHAoshb/cL14q7I60PrPUXI5H93i17SEQffJa9dlxA6DuyjHvv0DoTV5jF1Gwyy+ODAjxs9Ac82DjIZ/KOiQvqoLSxHMjdZE+AjbhgaD1AdAyv8g5Fq7tLGY3jF8FVterna0tdKDJ+WyQM0YZdEpTgLs3ckH/boxkO/1ROoTTFTWYYBVfgJ6ciIau7KMrLlCpT9HU8DXMzlg1dUDa78mraAXhaN7unMDbZS6bWyUBpoKwqNGDGJMT7gsYT/EHUcViu15enziOsG/u8Sp2O1i1I1Tez5Ol0zq9vrZ/T3t6YUzcFOPC9Sk2vOHg==</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat>
    <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
    <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://proxy.sram.surf.nl/saml2sp/sso/redirect"/>
    <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://proxy.sram.surf.nl/saml2sp/sso/post"/>
  </md:IDPSSODescriptor>
  <md:Organization>
    <md:OrganizationName xml:lang="en">SURF</md:OrganizationName>
    <md:OrganizationDisplayName xml:lang="en">SURF</md:OrganizationDisplayName>
    <md:OrganizationURL xml:lang="en">https://www.surf.nl/</md:OrganizationURL>
  </md:Organization>
  <md:ContactPerson contactType="technical">
    <md:GivenName>SURF Research Access Management</md:GivenName>
    <md:EmailAddress>mailto:sram-support@surf.nl</md:EmailAddress>
  </md:ContactPerson>
  <md:ContactPerson contactType="administrative">
    <md:GivenName>SURF Research Access Management</md:GivenName>
    <md:EmailAddress>mailto:sram-support@surf.nl</md:EmailAddress>
  </md:ContactPerson>
  <md:ContactPerson contactType="support">
    <md:GivenName>SURF Research Access Management</md:GivenName>
    <md:EmailAddress>mailto:sram-support@surf.nl</md:EmailAddress>
  </md:ContactPerson>
<md:ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security"><md:GivenName>Security Response Team</md:GivenName><md:EmailAddress>mailto:securityincident@surf.nl</md:EmailAddress></md:ContactPerson></md:EntityDescriptor></md:EntitiesDescriptor>