<?xml version="1.0"?>
<EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" entityID="https://ucanridp.ucanr.edu/idp/shibboleth">
  <Extensions xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi">
    <mdrpi:RegistrationInfo registrationAuthority="https://incommon.org"/>
    <mdattr:EntityAttributes xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">
      <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oasis:names:tc:SAML:attribute:assurance-certification">
        <saml:AttributeValue>https://refeds.org/sirtfi</saml:AttributeValue>
      </saml:Attribute>
      <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="http://macedir.org/entity-category-support">
        <saml:AttributeValue>http://refeds.org/category/research-and-scholarship</saml:AttributeValue>
      </saml:Attribute>
      <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="http://macedir.org/entity-category">
        <saml:AttributeValue>http://id.incommon.org/category/registered-by-incommon</saml:AttributeValue>
      </saml:Attribute>
    </mdattr:EntityAttributes>
  </Extensions>
  <IDPSSODescriptor protocolSupportEnumeration="urn:mace:shibboleth:1.0 urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol" errorURL="https://ucanridp.ucanr.edu/idp/sp-error.html?sp=ERRORURL_SP&amp;error=ERRORURL_CODE&amp;addlInfo=ERRORURL_CTX">
    <Extensions>
      <shibmd:Scope regexp="false">ucanr.edu</shibmd:Scope>
      <mdui:UIInfo xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui">
        <mdui:DisplayName xml:lang="en">University of California, Agriculture and Natural Resources</mdui:DisplayName>
        <mdui:Description xml:lang="en">Identity Provider for UCANR</mdui:Description>
        <mdui:PrivacyStatementURL xml:lang="en">https://www.ucop.edu/ethics-compliance-audit-services/_files/compliance/privacy/statement-of-privacy-for-web-based-applications.pdf</mdui:PrivacyStatementURL>
        <mdui:Logo xml:lang="en" width="80" height="60">https://www.ucop.edu/_common/_images/sso/uc.png</mdui:Logo>
      </mdui:UIInfo>
    </Extensions>
    <KeyDescriptor use="signing">
      <ds:KeyInfo>
        <ds:X509Data>
          <!-- Serial No. 536462225106477217453954057090186427894161017160, expires on Sun Nov 23 19:48:00 2036 GMT -->
          <ds:X509Certificate>
MIIDPzCCAiegAwIBAgIUXffMU5sFDAB1FCSA3JaBCMR5CUgwDQYJKoZIhvcNAQEL
BQAwIDEeMBwGA1UEAwwVdWNhbnJzaGliMDEudWNhbnIuZWR1MB4XDTE2MTEyMzE5
NDgwMFoXDTM2MTEyMzE5NDgwMFowIDEeMBwGA1UEAwwVdWNhbnJzaGliMDEudWNh
bnIuZWR1MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAlDjnyoTxp/9m
/qtBcbmFtGKMlnY5PVD/trCRxg7KD9n2ennokClyOIacEDiokK9WaV2ALib7MB27
R1kXraVA8i7Tgq1Wco8ApDMbEzFVzQpUwGaUUYzgvyZ6B5Fp8Qt26suBkboQbz/9
6XQPiigwSsRXni+PihzOMXWj/Bjb8GbjKlDumnyyxViUw8UIDNDWLmzGrx15kiIF
ewPAtZm490oHAUScRPg+9utlWNMRI1dwF0aXUHB111qwvJgj67K6WAVbC9+EXV5s
U6Ksp+/4ZwdjsvAVg9REreEIilLWhqJlhmyd9rdoqk/wlQpOU+rhVH2tiaZir1pC
o84lMSMBvQIDAQABo3EwbzAdBgNVHQ4EFgQUZZv/mI4OWR0ews925MO2UFT0vYEw
TgYDVR0RBEcwRYIVdWNhbnJzaGliMDEudWNhbnIuZWR1hixodHRwczovL3VjYW5y
c2hpYjAxLnVjYW5yLmVkdS9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOC
AQEAgVbOcybA7SyZ8miKHFARvutB/iXI6uXiMUmwztKqrAyRW/VK+O2igZ6YcucQ
GINUdB/LBStodzmT4bYR8UP+gHpdFwkjdXxdwtyM64bR3siS0AvltkJd6hSgALML
7gbv2ulC1jbVfzW8RIaWCJJzu+ZDtQUjTqzIj8JmfrGYymCAz3R27gpEv0180eo+
ziT5ffXTINhlvtZuDoFO4TCg0dckUSssddZt0iarWE3wEGWHji3JQIeeQGtISWJw
vRQRsMIt+qn3eSzhW6hzS28BuvmbhTbTGWDnKF7iKA2qr9yfk+GzPKA9p/lL4q0S
xHMYXB7tpiADzM08Sjggjy7zmw==
          </ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </KeyDescriptor>
    <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://ucanridp.ucanr.edu/idp/profile/SAML2/POST/SSO"/>
    <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://ucanridp.ucanr.edu/idp/profile/SAML2/POST-SimpleSign/SSO"/>
    <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://ucanridp.ucanr.edu/idp/profile/SAML2/Redirect/SSO"/>
    <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://ucanridp.ucanr.edu/idp/profile/Shibboleth/SSO"/>
  </IDPSSODescriptor>
  <Organization>
    <OrganizationName xml:lang="en">University of California - Office of the President</OrganizationName>
    <OrganizationDisplayName xml:lang="en">University of California - Office of the President</OrganizationDisplayName>
    <OrganizationURL xml:lang="en">http://www.ucop.edu/welcome.html</OrganizationURL>
  </Organization>
  <ContactPerson contactType="technical">
    <GivenName>IAM Group</GivenName>
    <EmailAddress>mailto:iamgrp@ucop.edu</EmailAddress>
  </ContactPerson>
  <ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security">
    <GivenName>Security OPerations</GivenName>
    <EmailAddress>mailto:soc@ucop.edu</EmailAddress>
  </ContactPerson>
  <ContactPerson contactType="administrative">
    <GivenName>IAM Group</GivenName>
    <EmailAddress>mailto:IAMGroup@ucop.edu</EmailAddress>
  </ContactPerson>
</EntityDescriptor>