<?xml version='1.0' encoding='UTF-8'?>
<md:EntitiesDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xrd="http://docs.oasis-open.org/ns/xri/xrd-1.0" xmlns:pyff="http://pyff.io/NS" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ser="http://eidas.europa.eu/metadata/servicelist" xmlns:eidas="http://eidas.europa.eu/saml-extensions" xmlns:ti="https://seamlessaccess.org/NS/trustinfo" xmlns:ns0="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ns1="http://www.w3.org/2000/09/xmldsig#" xmlns:ns2="urn:oasis:names:tc:SAML:metadata:attribute" xmlns:ns3="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:ns5="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:ns6="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" xmlns:ns7="urn:oasis:names:tc:SAML:metadata:ui" Name="SURF Research Access Management" ID="_20260309T210008Z" validUntil="2026-03-23T21:00:08Z" cacheDuration="P7D"><ds:Signature><ds:SignedInfo><ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/><ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/><ds:Reference URI="#_20260309T210008Z"><ds:Transforms><ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/><ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#WithComments"/></ds:Transforms><ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/><ds:DigestValue>8BpYvxiFHmmbXa+3GQPPK3wEhmoNBOu4iCVuNKDIwTs=</ds:DigestValue></ds:Reference></ds:SignedInfo><ds:SignatureValue>DteZXwjkFvTM3ix3b/ADCe1nhUn/g443mCwFUrtQ/CdjRzlln0aX26LaOY0UJ9gO31PgH16crDmC34gWnxYCoHtI4zhLwIkSBlsDoa+EKPyMYkyl3L62ZTVupdzk+TwBCeaWc13keQz9RrRHgHc6Pu+wxNFuIYlexe8AdIMUT0BCA/t+FAfJI4XDDt1W33t6AdJxeBHPHSd8HV+TwF4z8yd9T2bOhZyDSFo830Pax5AK0DU5vMtVOrBVUsEiDnZ1SyGr97/9Hw33nlhUOqBVwGOUlXRcR4X70dhW0+YOzwfwEdsidM+StUNcKZBxSbn6DiELiMbwqkZfDbPegFVgOw==</ds:SignatureValue><ds:KeyInfo><ds:X509Data><ds:X509Certificate>MIIDDjCCAfYCBS8Ikn8EMA0GCSqGSIb3DQEBCwUAMEsxCzAJBgNVBAYTAk5MMQ0w
CwYDVQQKEwRTVVJGMREwDwYDVQQLEwhTZXJ2aWNlczEaMBgGA1UEAxMRbWV0YS5z
cmFtLnN1cmYubmwwHhcNMjAwNzI4MTIxMjA4WhcNMzAwNzI2MTIxMjA4WjBLMQsw
CQYDVQQGEwJOTDENMAsGA1UEChMEU1VSRjERMA8GA1UECxMIU2VydmljZXMxGjAY
BgNVBAMTEW1ldGEuc3JhbS5zdXJmLm5sMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
MIIBCgKCAQEA7PydIyMo2RJRn6P5XpWrep/SzxUu2gLE3Cb34L9p68fL+CEeWwPZ
mWjspfhLvAe9+ocu2CwvNfyazc3fMxNJfnb+aIVvgw6cAXtUua3xh39bPS3vKkpo
rx7DkSQjqy78sbT2rllUG3AU9amFv5u32ZtYTSH/wm5Ny3VeG5Fp+Bo5Nd+oRZHq
rzdKGAeqQgmfRPSZ1FkbwKVhZe2faNp3P/cQBaM7f7wF7U92fk3gCMkS4uFhc/74
Ceyn9ht5UIwS64lD0mgsOCL7YIB3BzQ0lbiIK6Ps19VLwDMr2OoOLn6eBmlg0l9c
pfoEMQqzfiVnVqE+1IYIzPTHfhMhPKsCswIDAQABMA0GCSqGSIb3DQEBCwUAA4IB
AQAPePNDj14Ho79689ypNfgx/PD8Dr8Mq0veiqQ6i76ADS5+te+wvAfIdDUAcODi
aSbgfSCIUeKW574YfWqthpq6fiqY/pdLsAjquQVQYIeGP/EbyZcR5sHotuSZFv5C
YcK2EqZ2Zbj1Zj5IO1sjXK0zfz25iGAvspQXkdQ5UcoD2FbCBCKjjavM+wA33JjO
NQxqErDu7rKYNpd1jHPtCXL9aZFBDzxOGdTefzR33gkPRuYMogijE3KDOSUdZCt/
LhnrYi43SIe48i12pdHqi748Ln99EZxhHPQlZk5XUguqMziIN5j3DUU/RPvIQSiS
PX/6xOGO6m+bA2QUx/1XzPDY</ds:X509Certificate></ds:X509Data></ds:KeyInfo></ds:Signature><md:EntityDescriptor entityID="https://proxy.sram.surf.nl/metadata/backend.xml">
  
  <md:Extensions>
    
    <ns5:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
    <ns5:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
    <ns5:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
    <ns5:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/>
    <ns5:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/>
    <ns5:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/>
    <ns5:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/>
    <ns5:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
    <ns5:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
    <ns5:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
  <mdattr:EntityAttributes><saml:Attribute Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml:AttributeValue>https://refeds.org/sirtfi2</saml:AttributeValue><saml:AttributeValue>https://refeds.org/sirtfi</saml:AttributeValue></saml:Attribute><saml:Attribute Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml:AttributeValue>http://refeds.org/category/research-and-scholarship</saml:AttributeValue><saml:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</saml:AttributeValue></saml:Attribute></mdattr:EntityAttributes></md:Extensions>
  <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" AuthnRequestsSigned="false" WantAssertionsSigned="false">
    <md:Extensions>
      <ns6:DiscoveryResponse Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://proxy.sram.surf.nl/saml2sp/disco" index="1"/>
      <mdui:UIInfo>
        <mdui:DisplayName xml:lang="en">SURF Research Access Management</mdui:DisplayName>
        <mdui:Description xml:lang="en">SURF Research Access Management</mdui:Description>
        <mdui:Logo height="160" width="200">https://static.surfconext.nl/logos/idp/surf.svg</mdui:Logo>
        <mdui:InformationURL xml:lang="en">https://www.surf.nl/en/surf-research-access-management-collaborating-easily-and-securely-in-research-services</mdui:InformationURL>
        <mdui:PrivacyStatementURL xml:lang="en">https://edu.nl/93cdm</mdui:PrivacyStatementURL>
      </mdui:UIInfo>
    </md:Extensions>
    <md:KeyDescriptor use="signing">
      <ds:KeyInfo>
        <ds:X509Data>
          <ds:X509Certificate>MIIC1DCCAbwCCQDM9v704oVBezANBgkqhkiG9w0BAQsFADAsMSowKAYDVQQDDCFzdXJmX3JhbSBwcm9kIHByb3h5IHNhbWwyX2JhY2tlbmQwHhcNMjAwNTI4MTA1NDM2WhcNMzAwNTI2MTA1NDM2WjAsMSowKAYDVQQDDCFzdXJmX3JhbSBwcm9kIHByb3h5IHNhbWwyX2JhY2tlbmQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC5Wcdmrn3L+wwfd/xs5IdEOQHp9VkhHTdgcVXt8SEH7YHBB4OauFOH8eQiQj543wKjLP06VV3MgD2cBTrSoOBSigCc/r8wNFPr9PP3XEeX3hXoQUTzKkbv7zOnQGf/8fRoAHSCUitdJkwXvi+wDkKr3qel8lVY0rl2kf1H/NSZkgwiPUsB8/VpThDL+55oH47dB3JrpfSNaduNElBIPVNtWZO64rqb/vHlLhkS9R6Ri6oKbJK0fP/HBcDMS/ngKAFRhxteaIdxQc9KosYejA/B/3tXRb5TqFCt6Uf7KU7mCR36VU/g6ii/IhB2uNrIhploeoj/abhjAaH29eqsQcSFAgMBAAEwDQYJKoZIhvcNAQELBQADggEBAJ4YOT1YYN5E2s/lMJSp/tU2syGiVTPpJM5oA2nt+So+9KKotNpWKsCDCve1+4P+R6EN1wxcrjHModcZYmmJlq6Lh3YDcgki56FvvVwiV/dDTtzzj/stej9nM51UoLjeH8VvsgQ80cTV0kAIOl0JI1zuiivUMNXWvU8UKYsVrhqsz/lCfP5Ov5Lkw1RXOfJ4KkHjpyPvSAdeEYG5XmKD7ni5yURHaEkhQxqHo5C6lqkiy9aoO3hhzn3Weja4PS0UrZsrziz9cYa0U/XMO6SwzK6IjY0Q6bsXYmdK/+YCN+OEXPnujMfxsgFKHTVkYJ2OaYcl7BrvR9BqhVuQcI8i0vg=</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:KeyDescriptor use="encryption">
      <ds:KeyInfo>
        <ds:X509Data>
          <ds:X509Certificate>MIIC1DCCAbwCCQDM9v704oVBezANBgkqhkiG9w0BAQsFADAsMSowKAYDVQQDDCFzdXJmX3JhbSBwcm9kIHByb3h5IHNhbWwyX2JhY2tlbmQwHhcNMjAwNTI4MTA1NDM2WhcNMzAwNTI2MTA1NDM2WjAsMSowKAYDVQQDDCFzdXJmX3JhbSBwcm9kIHByb3h5IHNhbWwyX2JhY2tlbmQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC5Wcdmrn3L+wwfd/xs5IdEOQHp9VkhHTdgcVXt8SEH7YHBB4OauFOH8eQiQj543wKjLP06VV3MgD2cBTrSoOBSigCc/r8wNFPr9PP3XEeX3hXoQUTzKkbv7zOnQGf/8fRoAHSCUitdJkwXvi+wDkKr3qel8lVY0rl2kf1H/NSZkgwiPUsB8/VpThDL+55oH47dB3JrpfSNaduNElBIPVNtWZO64rqb/vHlLhkS9R6Ri6oKbJK0fP/HBcDMS/ngKAFRhxteaIdxQc9KosYejA/B/3tXRb5TqFCt6Uf7KU7mCR36VU/g6ii/IhB2uNrIhploeoj/abhjAaH29eqsQcSFAgMBAAEwDQYJKoZIhvcNAQELBQADggEBAJ4YOT1YYN5E2s/lMJSp/tU2syGiVTPpJM5oA2nt+So+9KKotNpWKsCDCve1+4P+R6EN1wxcrjHModcZYmmJlq6Lh3YDcgki56FvvVwiV/dDTtzzj/stej9nM51UoLjeH8VvsgQ80cTV0kAIOl0JI1zuiivUMNXWvU8UKYsVrhqsz/lCfP5Ov5Lkw1RXOfJ4KkHjpyPvSAdeEYG5XmKD7ni5yURHaEkhQxqHo5C6lqkiy9aoO3hhzn3Weja4PS0UrZsrziz9cYa0U/XMO6SwzK6IjY0Q6bsXYmdK/+YCN+OEXPnujMfxsgFKHTVkYJ2OaYcl7BrvR9BqhVuQcI8i0vg=</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat>
    <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://proxy.sram.surf.nl/saml2sp/acs/post" index="1"/>
    <md:AttributeConsumingService index="1">
      <md:ServiceName xml:lang="en">SURF Research Access Management</md:ServiceName>
      <md:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonPrincipalName" isRequired="true"/>
      <md:RequestedAttribute Name="urn:oid:2.5.4.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="cn" isRequired="true"/>
      <md:RequestedAttribute Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="displayName" isRequired="true"/>
      <md:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonScopedAffiliation" isRequired="true"/>
      <md:RequestedAttribute Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="sn" isRequired="true"/>
      <md:RequestedAttribute Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="givenName" isRequired="true"/>
      <md:RequestedAttribute Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="mail" isRequired="true"/>
      <md:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.16" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonOrcid" isRequired="false"/>
      <md:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonAssurance" isRequired="false"/>
      <md:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.25178.1.2.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="schacHomeOrganization" isRequired="false"/>
      <md:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonTargetedID" isRequired="false"/>
    </md:AttributeConsumingService>
  </md:SPSSODescriptor>
  <md:Organization>
    <md:OrganizationName xml:lang="en">SURF</md:OrganizationName>
    <md:OrganizationDisplayName xml:lang="en">SURF</md:OrganizationDisplayName>
    <md:OrganizationURL xml:lang="en">https://www.surf.nl/</md:OrganizationURL>
  </md:Organization>
  <md:ContactPerson contactType="technical">
    <md:GivenName>SURF Research Access Management</md:GivenName>
    <md:EmailAddress>mailto:sram-support@surf.nl</md:EmailAddress>
  </md:ContactPerson>
  <md:ContactPerson contactType="administrative">
    <md:GivenName>SURF Research Access Management</md:GivenName>
    <md:EmailAddress>mailto:sram-support@surf.nl</md:EmailAddress>
  </md:ContactPerson>
  <md:ContactPerson contactType="support">
    <md:GivenName>SURF Research Access Management</md:GivenName>
    <md:EmailAddress>mailto:sram-support@surf.nl</md:EmailAddress>
  </md:ContactPerson>
<md:ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security"><md:GivenName>Security Response Team</md:GivenName><md:EmailAddress>mailto:securityincident@surf.nl</md:EmailAddress></md:ContactPerson></md:EntityDescriptor></md:EntitiesDescriptor>