<EntitiesDescriptor
    xmlns="urn:oasis:names:tc:SAML:2.0:metadata"
    xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xmlns:ds="http://www.w3.org/2000/09/xmldsig#"
    xmlns:shibmd="urn:mace:shibboleth:metadata:1.0"
    xsi:schemaLocation="urn:oasis:names:tc:SAML:2.0:metadata saml-schema-metadata-2.0.xsd urn:mace:shibboleth:metadata:1.0 shibboleth-metadata-1.0.xsd http://www.w3.org/2000/09/xmldsig# xmldsig-core-schema.xsd"
    Name="https://shibboleth.mit.edu"
    validUntil="2010-01-01T00:00:00Z">

	<!--
	This is the set of metadata for MIT's Shibboleth IdPs.
	
	The software components do not configure themselves using metadata
	(e.g. the IdP does not configure itself using IdP metadata). Instead,
	metadata about SPs is fed into IdPs and metadata about IdPs is fed into
	SPs. Other metadata is ignored, so the software does not look for
	conflicts between its own configuration and the metadata that might
	be present about itself. Metadata is instead maintained based on the
	external details of your configuration.
	-->

	<Extensions>
		<shibmd:KeyAuthority xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" VerifyDepth="5">
			<!-- MIT CA -->
			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<ds:X509Data>
					<ds:X509Certificate>
MIIDZTCCAs6gAwIBAgIBATANBgkqhkiG9w0BAQUFADB7MQswCQYDVQQGEwJVUzEW
MBQGA1UECBMNTWFzc2FjaHVzZXR0czEuMCwGA1UEChMlTWFzc2FjaHVzZXR0cyBJ
bnN0aXR1dGUgb2YgVGVjaG5vbG9neTEkMCIGA1UECxMbTUlUIENlcnRpZmljYXRp
b24gQXV0aG9yaXR5MB4XDTA2MDQwODE2NTAwNFoXDTI2MDgwMTE2NTAwNFowezEL
MAkGA1UEBhMCVVMxFjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxLjAsBgNVBAoTJU1h
c3NhY2h1c2V0dHMgSW5zdGl0dXRlIG9mIFRlY2hub2xvZ3kxJDAiBgNVBAsTG01J
VCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTCBnzANBgkqhkiG9w0BAQEFAAOBjQAw
gYkCgYEA09Dr51G1M3Wm2KOE6gJwXM+cIOALA4uORm4VJeF39mvEcN3UFgvMEYgx
OAvufFkkV+mNzXX4UmPdMwzwT5+1/JGuMoWMGnVjGZiGHpIjsofz9cmmopdo8uyy
Gq2z9e0J6sznvLRkUBXmVwAaesbe/uEwWFpdq7u0HBHsZMHTpFUCAwEAAaOB+DCB
9TAdBgNVHQ4EFgQUU/WjDwZdZdiKj1JtafrrVS29iwwwgaUGA1UdIwSBnTCBmoAU
U/WjDwZdZdiKj1JtafrrVS29iwyhf6R9MHsxCzAJBgNVBAYTAlVTMRYwFAYDVQQI
Ew1NYXNzYWNodXNldHRzMS4wLAYDVQQKEyVNYXNzYWNodXNldHRzIEluc3RpdHV0
ZSBvZiBUZWNobm9sb2d5MSQwIgYDVQQLExtNSVQgQ2VydGlmaWNhdGlvbiBBdXRo
b3JpdHmCAQEwDAYDVR0TBAUwAwEB/zALBgNVHQ8EBAMCAQYwEQYJYIZIAYb4QgEB
BAQDAgEGMA0GCSqGSIb3DQEBBQUAA4GBAMTjXyVdM89JlPTzoe3o5CIvUP6TrWMN
Bm3/mSX5pXeZWbWLtdVfUgQ9mW6UBYXaQSUPmz9C09ZNBH8N3vOoDS5/jD8MMcV/
U/rOAIb4v2bMRKpPweSINGm72Pv/Pg15t1sRcnatBK94orekYvfJa3PiPU/3pfge
RYhCd9zByXr2
					</ds:X509Certificate>
				</ds:X509Data>
			</ds:KeyInfo>
			<!-- Equifax CA -->
			<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				<ds:X509Data>
					<ds:X509Certificate>
MIIDIDCCAomgAwIBAgIENd70zzANBgkqhkiG9w0BAQUFADBOMQswCQYDVQQGEwJV
UzEQMA4GA1UEChMHRXF1aWZheDEtMCsGA1UECxMkRXF1aWZheCBTZWN1cmUgQ2Vy
dGlmaWNhdGUgQXV0aG9yaXR5MB4XDTk4MDgyMjE2NDE1MVoXDTE4MDgyMjE2NDE1
MVowTjELMAkGA1UEBhMCVVMxEDAOBgNVBAoTB0VxdWlmYXgxLTArBgNVBAsTJEVx
dWlmYXggU2VjdXJlIENlcnRpZmljYXRlIEF1dGhvcml0eTCBnzANBgkqhkiG9w0B
AQEFAAOBjQAwgYkCgYEAwV2xWGcIYu6gmi0fCG2RFGiYCh7+2gRvE4RiIcPRfM6f
BeC4AfBONOziipUEZKzxa1NfBbPLZ4C/QgKO/t0BCezhABRP/PvwDN1Dulsr4R+A
cJkVV5MW8Q+XarfCaCMczE1ZMKxRHjuvK9buY0V7xdlfUNLjUA86iOe/FP3gx7kC
AwEAAaOCAQkwggEFMHAGA1UdHwRpMGcwZaBjoGGkXzBdMQswCQYDVQQGEwJVUzEQ
MA4GA1UEChMHRXF1aWZheDEtMCsGA1UECxMkRXF1aWZheCBTZWN1cmUgQ2VydGlm
aWNhdGUgQXV0aG9yaXR5MQ0wCwYDVQQDEwRDUkwxMBoGA1UdEAQTMBGBDzIwMTgw
ODIyMTY0MTUxWjALBgNVHQ8EBAMCAQYwHwYDVR0jBBgwFoAUSOZo+SvSspXXR9gj
IBBPM5iQn9QwHQYDVR0OBBYEFEjmaPkr0rKV10fYIyAQTzOYkJ/UMAwGA1UdEwQF
MAMBAf8wGgYJKoZIhvZ9B0EABA0wCxsFVjMuMGMDAgbAMA0GCSqGSIb3DQEBBQUA
A4GBAFjOKer89961zgK5F7WF0bnj4JXMJTENAKaSbn+2kmOeUJXRmm/kEd5jhW6Y
7qj/WsjTVbJmcVfewCHrPSqnI0kBBIZCe/zuf6IWUrVnZ9NA2zsmWLIodz2uFHdh
1voqZiegDfqnc1zqcPGUIWVEX/r87yloqaKHee9570+sB3c4
					</ds:X509Certificate>
				</ds:X509Data>
			</ds:KeyInfo>
		</shibmd:KeyAuthority>
	</Extensions>

	<!-- MIT's pilot IdP. -->
	<EntityDescriptor entityID="https://idp.mit.edu/shibboleth">
	<!--
	The entityID above looks like a location, but it's actually just a name.
	Each entity is assigned a URI name. By convention, it will often be a
	URL, but it should never contain a physical machine hostname that you
	would not otherwise publish to users of the service. For example, if your
	installation runs on a machine named "gryphon.example.org", you would
	generally register that machine in DNS under a second, logical name
	(such as idp.example.org). This logical name should be used in favor
	of the real hostname when you assign an entityID. You should use a name
	like this even if you don't actually register the server in DNS using it.
	The URL does *not* have to resolve into anything to use it as a name.
	The point is for the name you choose to be stable, which is why including
	hostnames is generally bad, since they tend to change.
	-->
		
		<!-- A Shib IdP contains this element with protocol support as shown. -->
		<IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
			<Extensions>
				<!-- This is a Shibboleth extension to express attribute scope rules. -->
				<shibmd:Scope>mit.edu</shibmd:Scope>
			</Extensions>
			
			<!--
			One or more KeyDescriptors tell SPs how the IdP will authenticate itself. A single
			descriptor can be used for both signing and for server-TLS if its use attribute
			is set to "signing". You can place an X.509 certificate directly in this element
			to specify the exact public key certificate to use. This only reflects the public
			half of the keypair used by the IdP.
			
			When the IdP signs XML, it uses the private key included in its Credentials
			configuration element, and when TLS is used, the web server will use the
			certificate and private key defined by the web server's configuration.
			An SP will then try to match the certificates in the KeyDescriptors here
			to the ones presented in the XML Signature or SSL session.
			
			When an inline certificate is used, do not assume that an expired certificate
			will be detected and rejected. Often only the key will be extracted without
			regard for the certificate, but at the same time, it may be risky to include
			an expired certificate and assume it will work. Your SAML implementation
			may provide specific guidance on this.
			-->
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>idp.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>

			<!-- This tells SPs where/how to resolve SAML 1.x artifacts into SAML assertions. -->
			<ArtifactResolutionService index="1"
				Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
				Location="https://idp.mit.edu:8443/shibboleth-idp/Artifact"/>

			<!-- This tells SPs that you support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
			
			<!-- This tells SPs how and where to request authentication. -->
			<SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest"
			    Location="https://idp.mit.edu/shibboleth-idp/SSO"/>

		</IDPSSODescriptor>
		
		<!-- Most Shib IdPs also support SAML attribute queries, so this role is also included. -->
		<AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
			<Extensions>
				<!-- This is a Shibboleth extension to express attribute scope rules. -->
				<shibmd:Scope>mit.edu</shibmd:Scope>
				<shibmd:Scope>ATHENA.MIT.EDU</shibmd:Scope>
			</Extensions>
			
			<!-- The certificate has to be repeated here (or a different one specified if necessary). -->
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>idp.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>

			<!-- This tells SPs how and where to send queries. -->
			<AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
			    Location="https://idp.mit.edu:8443/shibboleth-idp/AA"/>

			<!-- This tells SPs that you support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		</AttributeAuthorityDescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
		    <OrganizationName xml:lang="en">MIT IS&amp;T</OrganizationName>
		    <OrganizationDisplayName xml:lang="en">MIT Information Services and Technology</OrganizationDisplayName>
		    <OrganizationURL xml:lang="en">http://web.mit.edu/ist/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
		    <EmailAddress>network@mit.edu</EmailAddress>
		</ContactPerson>

	</EntityDescriptor>

	<!-- MIT's core staging IdP. -->
	<EntityDescriptor entityID="https://idp-staging.mit.edu/shibboleth">
	<!--
	The entityID above looks like a location, but it's actually just a name.
	Each entity is assigned a URI name. By convention, it will often be a
	URL, but it should never contain a physical machine hostname that you
	would not otherwise publish to users of the service. For example, if your
	installation runs on a machine named "gryphon.example.org", you would
	generally register that machine in DNS under a second, logical name
	(such as idp.example.org). This logical name should be used in favor
	of the real hostname when you assign an entityID. You should use a name
	like this even if you don't actually register the server in DNS using it.
	The URL does *not* have to resolve into anything to use it as a name.
	The point is for the name you choose to be stable, which is why including
	hostnames is generally bad, since they tend to change.
	-->
		
		<!-- A Shib IdP contains this element with protocol support as shown. -->
		<IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
			<Extensions>
				<!-- This is a Shibboleth extension to express attribute scope rules. -->
				<shibmd:Scope>mit.edu</shibmd:Scope>
			</Extensions>
			
			<!--
			One or more KeyDescriptors tell SPs how the IdP will authenticate itself. A single
			descriptor can be used for both signing and for server-TLS if its use attribute
			is set to "signing". You can place an X.509 certificate directly in this element
			to specify the exact public key certificate to use. This only reflects the public
			half of the keypair used by the IdP.
			
			When the IdP signs XML, it uses the private key included in its Credentials
			configuration element, and when TLS is used, the web server will use the
			certificate and private key defined by the web server's configuration.
			An SP will then try to match the certificates in the KeyDescriptors here
			to the ones presented in the XML Signature or SSL session.
			
			When an inline certificate is used, do not assume that an expired certificate
			will be detected and rejected. Often only the key will be extracted without
			regard for the certificate, but at the same time, it may be risky to include
			an expired certificate and assume it will work. Your SAML implementation
			may provide specific guidance on this.
			-->
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>idp-staging.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>

			<!-- This tells SPs where/how to resolve SAML 1.x artifacts into SAML assertions. -->
			<ArtifactResolutionService index="1"
				Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
				Location="https://idp-staging.mit.edu:8443/shibboleth-idp/Artifact"/>

			<!-- This tells SPs that you support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
			
			<!-- This tells SPs how and where to request authentication. -->
			<SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest"
			    Location="https://idp-staging.mit.edu/shibboleth-idp/SSO"/>

		</IDPSSODescriptor>
		
		<!-- Most Shib IdPs also support SAML attribute queries, so this role is also included. -->
		<AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
			<Extensions>
				<!-- This is a Shibboleth extension to express attribute scope rules. -->
				<shibmd:Scope>mit.edu</shibmd:Scope>
				<shibmd:Scope>ATHENA.MIT.EDU</shibmd:Scope>
			</Extensions>
			
			<!-- The certificate has to be repeated here (or a different one specified if necessary). -->
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>idp-staging.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>

			<!-- This tells SPs how and where to send queries. -->
			<AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
			    Location="https://idp-staging.mit.edu:8443/shibboleth-idp/AA"/>

			<!-- This tells SPs that you support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		</AttributeAuthorityDescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
		    <OrganizationName xml:lang="en">MIT IS&amp;T</OrganizationName>
		    <OrganizationDisplayName xml:lang="en">MIT Information Services and Technology</OrganizationDisplayName>
		    <OrganizationURL xml:lang="en">http://web.mit.edu/ist/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
		    <EmailAddress>network@mit.edu</EmailAddress>
		</ContactPerson>

	</EntityDescriptor>

	<!-- foonalagoona.mit.edu, ISDA's test IdP. -->
	<EntityDescriptor entityID="https://idp.foonalagoona.mit.edu/shibboleth">
	<!--
	The entityID above looks like a location, but it's actually just a name.
	Each entity is assigned a URI name. By convention, it will often be a
	URL, but it should never contain a physical machine hostname that you
	would not otherwise publish to users of the service. For example, if your
	installation runs on a machine named "gryphon.example.org", you would
	generally register that machine in DNS under a second, logical name
	(such as idp.example.org). This logical name should be used in favor
	of the real hostname when you assign an entityID. You should use a name
	like this even if you don't actually register the server in DNS using it.
	The URL does *not* have to resolve into anything to use it as a name.
	The point is for the name you choose to be stable, which is why including
	hostnames is generally bad, since they tend to change.
	-->
		
		<!-- A Shib IdP contains this element with protocol support as shown. -->
		<IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
			<Extensions>
				<!-- This is a Shibboleth extension to express attribute scope rules. -->
				<shibmd:Scope>mit.edu</shibmd:Scope>
			</Extensions>
			
			<!--
			One or more KeyDescriptors tell SPs how the IdP will authenticate itself. A single
			descriptor can be used for both signing and for server-TLS if its use attribute
			is set to "signing". You can place an X.509 certificate directly in this element
			to specify the exact public key certificate to use. This only reflects the public
			half of the keypair used by the IdP.
			
			When the IdP signs XML, it uses the private key included in its Credentials
			configuration element, and when TLS is used, the web server will use the
			certificate and private key defined by the web server's configuration.
			An SP will then try to match the certificates in the KeyDescriptors here
			to the ones presented in the XML Signature or SSL session.
			
			When an inline certificate is used, do not assume that an expired certificate
			will be detected and rejected. Often only the key will be extracted without
			regard for the certificate, but at the same time, it may be risky to include
			an expired certificate and assume it will work. Your SAML implementation
			may provide specific guidance on this.
			-->
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>foonalagoona.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>

			<!-- This tells SPs where/how to resolve SAML 1.x artifacts into SAML assertions. -->
			<ArtifactResolutionService index="1"
				Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
				Location="https://foonalagoona.mit.edu:8443/shibboleth-idp/Artifact"/>

			<!-- This tells SPs that you support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
			
			<!-- This tells SPs how and where to request authentication. -->
			<SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest"
			    Location="https://foonalagoona.mit.edu/shibboleth-idp/SSO"/>

		</IDPSSODescriptor>
		
		<!-- Most Shib IdPs also support SAML attribute queries, so this role is also included. -->
		<AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
			<Extensions>
				<!-- This is a Shibboleth extension to express attribute scope rules. -->
				<shibmd:Scope>mit.edu</shibmd:Scope>
				<shibmd:Scope>ATHENA.MIT.EDU</shibmd:Scope>
			</Extensions>
			
			<!-- The certificate has to be repeated here (or a different one specified if necessary). -->
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>foonalagoona.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>

			<!-- This tells SPs how and where to send queries. -->
			<AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
			    Location="https://foonalagoona.mit.edu:8443/shibboleth-idp/AA"/>

			<!-- This tells SPs that you support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		</AttributeAuthorityDescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
		    <OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
		    <OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
		    <OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
		    <GivenName>Robert</GivenName>
		    <SurName>Basch</SurName>
		    <EmailAddress>rbasch@mit.edu</EmailAddress>
		</ContactPerson>

	</EntityDescriptor>

	<!-- extrovert.mit.edu, ISDA's prototype CAMS IdP. -->
	<EntityDescriptor entityID="https://extrovert.mit.edu/shibboleth">
	<!--
	The entityID above looks like a location, but it's actually just a name.
	Each entity is assigned a URI name. By convention, it will often be a
	URL, but it should never contain a physical machine hostname that you
	would not otherwise publish to users of the service. For example, if your
	installation runs on a machine named "gryphon.example.org", you would
	generally register that machine in DNS under a second, logical name
	(such as idp.example.org). This logical name should be used in favor
	of the real hostname when you assign an entityID. You should use a name
	like this even if you don't actually register the server in DNS using it.
	The URL does *not* have to resolve into anything to use it as a name.
	The point is for the name you choose to be stable, which is why including
	hostnames is generally bad, since they tend to change.
	-->
		
		<!-- A Shib IdP contains this element with protocol support as shown. -->
		<IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
			
			<Extensions>
				<!-- This is a Shibboleth extension to express attribute scope rules. -->
				<shibmd:Scope>touchstonenetwork.net</shibmd:Scope>
			</Extensions>

			<!--
			One or more KeyDescriptors tell SPs how the IdP will authenticate itself. A single
			descriptor can be used for both signing and for server-TLS if its use attribute
			is set to "signing". You can place an X.509 certificate directly in this element
			to specify the exact public key certificate to use. This only reflects the public
			half of the keypair used by the IdP.
			
			When the IdP signs XML, it uses the private key included in its Credentials
			configuration element, and when TLS is used, the web server will use the
			certificate and private key defined by the web server's configuration.
			An SP will then try to match the certificates in the KeyDescriptors here
			to the ones presented in the XML Signature or SSL session.
			
			When an inline certificate is used, do not assume that an expired certificate
			will be detected and rejected. Often only the key will be extracted without
			regard for the certificate, but at the same time, it may be risky to include
			an expired certificate and assume it will work. Your SAML implementation
			may provide specific guidance on this.
			-->
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				        <ds:X509Data>
						<ds:X509Certificate>
MIIEfDCCA+WgAwIBAgIJAIXt4FdZdkFoMA0GCSqGSIb3DQEBBQUAMIHaMQswCQYD
VQQGEwJVUzEWMBQGA1UECBMNTWFzc2FjaHVzZXR0czESMBAGA1UEBxMJQ2FtYnJp
ZGdlMS4wLAYDVQQKEyVNYXNzYWNodXNldHRzIEluc3RpdHV0ZSBvZiBUZWNobm9s
b2d5MSwwKgYDVQQLEyNJbmZvcm1hdGlvbiBTZXJ2aWNlcyBhbmQgVGVjaG5vbG9n
eTEaMBgGA1UEAxMRZXh0cm92ZXJ0Lm1pdC5lZHUxJTAjBgkqhkiG9w0BCQEWFnRv
dWNoc3RvbmUtZGV2QG1pdC5lZHUwHhcNMDgwNzE0MjIzNjIyWhcNMDkwNzE0MjIz
NjIyWjCB2jELMAkGA1UEBhMCVVMxFjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQ
BgNVBAcTCUNhbWJyaWRnZTEuMCwGA1UEChMlTWFzc2FjaHVzZXR0cyBJbnN0aXR1
dGUgb2YgVGVjaG5vbG9neTEsMCoGA1UECxMjSW5mb3JtYXRpb24gU2VydmljZXMg
YW5kIFRlY2hub2xvZ3kxGjAYBgNVBAMTEWV4dHJvdmVydC5taXQuZWR1MSUwIwYJ
KoZIhvcNAQkBFhZ0b3VjaHN0b25lLWRldkBtaXQuZWR1MIGfMA0GCSqGSIb3DQEB
AQUAA4GNADCBiQKBgQDAWLMcfGyd8Ut0916twqkcgDQhcHiVxIwqa9T9R/UtQ006
59yhVZjeuMfIEkBfRB368rUzDAjEGpZdRVhungdZMk/QvYMlv26XMl5Swp2tMjqd
DCZCTR1FK+0Gic6j53yuhUm2U5ZvorgFZWD4vbaTrJRyd87JmsJdy7MJfmvb8QID
AQABo4IBRjCCAUIwHQYDVR0OBBYEFAG/8LcsyGuQbrr3spyWqc2jndqVMIIBEQYD
VR0jBIIBCDCCAQSAFAG/8LcsyGuQbrr3spyWqc2jndqVoYHgpIHdMIHaMQswCQYD
VQQGEwJVUzEWMBQGA1UECBMNTWFzc2FjaHVzZXR0czESMBAGA1UEBxMJQ2FtYnJp
ZGdlMS4wLAYDVQQKEyVNYXNzYWNodXNldHRzIEluc3RpdHV0ZSBvZiBUZWNobm9s
b2d5MSwwKgYDVQQLEyNJbmZvcm1hdGlvbiBTZXJ2aWNlcyBhbmQgVGVjaG5vbG9n
eTEaMBgGA1UEAxMRZXh0cm92ZXJ0Lm1pdC5lZHUxJTAjBgkqhkiG9w0BCQEWFnRv
dWNoc3RvbmUtZGV2QG1pdC5lZHWCCQCF7eBXWXZBaDAMBgNVHRMEBTADAQH/MA0G
CSqGSIb3DQEBBQUAA4GBALzXMAmGw6dK4dfy5z84Avl+NQOZui8Nl41o3xyD1y54
fGe5WiqIKyUUFqNaX6cvWSBK2wj9KEtnpijuqZlXow5k+NVq2RgcHBwroS8SVs+/
stYG3zFPQ3wWiYq6QlL8zbJD9of9RP2l1pFoday96PscvQ2Gz+ihGf3NPmlf8f7s
				        	</ds:X509Certificate>
				        </ds:X509Data>
				</ds:KeyInfo>
			</KeyDescriptor>

			<!-- This tells SPs where/how to resolve SAML 1.x artifacts into SAML assertions. -->
			<ArtifactResolutionService index="1"
				Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
				Location="https://extrovert.mit.edu:8443/shibboleth-idp/Artifact"/>

			<!-- This tells SPs that you support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
			
			<!-- This tells SPs how and where to request authentication. -->
			<SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest"
			    Location="https://extrovert.mit.edu/shibboleth-idp/SSO"/>

		</IDPSSODescriptor>
		
		<!-- Most Shib IdPs also support SAML attribute queries, so this role is also included. -->
		<AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
			
			<Extensions>
				<!-- This is a Shibboleth extension to express attribute scope rules. -->
				<shibmd:Scope>touchstonenetwork.net</shibmd:Scope>
			</Extensions>

			<!-- The certificate has to be repeated here (or a different one specified if necessary). -->
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				        <ds:X509Data>
						<ds:X509Certificate>
MIIEfDCCA+WgAwIBAgIJAIXt4FdZdkFoMA0GCSqGSIb3DQEBBQUAMIHaMQswCQYD
VQQGEwJVUzEWMBQGA1UECBMNTWFzc2FjaHVzZXR0czESMBAGA1UEBxMJQ2FtYnJp
ZGdlMS4wLAYDVQQKEyVNYXNzYWNodXNldHRzIEluc3RpdHV0ZSBvZiBUZWNobm9s
b2d5MSwwKgYDVQQLEyNJbmZvcm1hdGlvbiBTZXJ2aWNlcyBhbmQgVGVjaG5vbG9n
eTEaMBgGA1UEAxMRZXh0cm92ZXJ0Lm1pdC5lZHUxJTAjBgkqhkiG9w0BCQEWFnRv
dWNoc3RvbmUtZGV2QG1pdC5lZHUwHhcNMDgwNzE0MjIzNjIyWhcNMDkwNzE0MjIz
NjIyWjCB2jELMAkGA1UEBhMCVVMxFjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQ
BgNVBAcTCUNhbWJyaWRnZTEuMCwGA1UEChMlTWFzc2FjaHVzZXR0cyBJbnN0aXR1
dGUgb2YgVGVjaG5vbG9neTEsMCoGA1UECxMjSW5mb3JtYXRpb24gU2VydmljZXMg
YW5kIFRlY2hub2xvZ3kxGjAYBgNVBAMTEWV4dHJvdmVydC5taXQuZWR1MSUwIwYJ
KoZIhvcNAQkBFhZ0b3VjaHN0b25lLWRldkBtaXQuZWR1MIGfMA0GCSqGSIb3DQEB
AQUAA4GNADCBiQKBgQDAWLMcfGyd8Ut0916twqkcgDQhcHiVxIwqa9T9R/UtQ006
59yhVZjeuMfIEkBfRB368rUzDAjEGpZdRVhungdZMk/QvYMlv26XMl5Swp2tMjqd
DCZCTR1FK+0Gic6j53yuhUm2U5ZvorgFZWD4vbaTrJRyd87JmsJdy7MJfmvb8QID
AQABo4IBRjCCAUIwHQYDVR0OBBYEFAG/8LcsyGuQbrr3spyWqc2jndqVMIIBEQYD
VR0jBIIBCDCCAQSAFAG/8LcsyGuQbrr3spyWqc2jndqVoYHgpIHdMIHaMQswCQYD
VQQGEwJVUzEWMBQGA1UECBMNTWFzc2FjaHVzZXR0czESMBAGA1UEBxMJQ2FtYnJp
ZGdlMS4wLAYDVQQKEyVNYXNzYWNodXNldHRzIEluc3RpdHV0ZSBvZiBUZWNobm9s
b2d5MSwwKgYDVQQLEyNJbmZvcm1hdGlvbiBTZXJ2aWNlcyBhbmQgVGVjaG5vbG9n
eTEaMBgGA1UEAxMRZXh0cm92ZXJ0Lm1pdC5lZHUxJTAjBgkqhkiG9w0BCQEWFnRv
dWNoc3RvbmUtZGV2QG1pdC5lZHWCCQCF7eBXWXZBaDAMBgNVHRMEBTADAQH/MA0G
CSqGSIb3DQEBBQUAA4GBALzXMAmGw6dK4dfy5z84Avl+NQOZui8Nl41o3xyD1y54
fGe5WiqIKyUUFqNaX6cvWSBK2wj9KEtnpijuqZlXow5k+NVq2RgcHBwroS8SVs+/
stYG3zFPQ3wWiYq6QlL8zbJD9of9RP2l1pFoday96PscvQ2Gz+ihGf3NPmlf8f7s
				        	</ds:X509Certificate>
				        </ds:X509Data>
				</ds:KeyInfo>
			</KeyDescriptor>

			<!-- This tells SPs how and where to send queries. -->
			<AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
			    Location="https://extrovert.mit.edu:8443/shibboleth-idp/AA"/>

			<!-- This tells SPs that you support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		</AttributeAuthorityDescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
		    <OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
		    <OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
		    <OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
		    <GivenName>Robert</GivenName>
		    <SurName>Basch</SurName>
		    <EmailAddress>rbasch@mit.edu</EmailAddress>
		</ContactPerson>

	</EntityDescriptor>

	<!-- map-dev-ts1.mit.edu, ISDA's CAMS dev IdP. -->
	<EntityDescriptor entityID="https://map-dev-ts1.mit.edu/shibboleth-idp">
	<!--
	The entityID above looks like a location, but it's actually just a name.
	Each entity is assigned a URI name. By convention, it will often be a
	URL, but it should never contain a physical machine hostname that you
	would not otherwise publish to users of the service. For example, if your
	installation runs on a machine named "gryphon.example.org", you would
	generally register that machine in DNS under a second, logical name
	(such as idp.example.org). This logical name should be used in favor
	of the real hostname when you assign an entityID. You should use a name
	like this even if you don't actually register the server in DNS using it.
	The URL does *not* have to resolve into anything to use it as a name.
	The point is for the name you choose to be stable, which is why including
	hostnames is generally bad, since they tend to change.
	-->
		
		<!-- A Shib IdP contains this element with protocol support as shown. -->
		<IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
			
			<Extensions>
				<!-- This is a Shibboleth extension to express attribute scope rules. -->
				<shibmd:Scope>touchstonenetwork.net</shibmd:Scope>
			</Extensions>

			<!--
			One or more KeyDescriptors tell SPs how the IdP will authenticate itself. A single
			descriptor can be used for both signing and for server-TLS if its use attribute
			is set to "signing". You can place an X.509 certificate directly in this element
			to specify the exact public key certificate to use. This only reflects the public
			half of the keypair used by the IdP.
			
			When the IdP signs XML, it uses the private key included in its Credentials
			configuration element, and when TLS is used, the web server will use the
			certificate and private key defined by the web server's configuration.
			An SP will then try to match the certificates in the KeyDescriptors here
			to the ones presented in the XML Signature or SSL session.
			
			When an inline certificate is used, do not assume that an expired certificate
			will be detected and rejected. Often only the key will be extracted without
			regard for the certificate, but at the same time, it may be risky to include
			an expired certificate and assume it will work. Your SAML implementation
			may provide specific guidance on this.
			-->
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>map-dev-ts1.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>

			<!-- This tells SPs where/how to resolve SAML 1.x artifacts into SAML assertions. -->
			<ArtifactResolutionService index="1"
				Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
				Location="https://map-dev-ts1.mit.edu:8443/shibboleth-idp/Artifact"/>

			<!-- This tells SPs that you support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
			
			<!-- This tells SPs how and where to request authentication. -->
			<SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest"
			    Location="https://map-dev-ts1.mit.edu/shibboleth-idp/SSO"/>

		</IDPSSODescriptor>
		
		<!-- Most Shib IdPs also support SAML attribute queries, so this role is also included. -->
		<AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
			
			<Extensions>
				<!-- This is a Shibboleth extension to express attribute scope rules. -->
				<shibmd:Scope>touchstonenetwork.net</shibmd:Scope>
			</Extensions>

			<!-- The certificate has to be repeated here (or a different one specified if necessary). -->
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>map-dev-ts1.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>

			<!-- This tells SPs how and where to send queries. -->
			<AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
			    Location="https://map-dev-ts1.mit.edu:8443/shibboleth-idp/AA"/>

			<!-- This tells SPs that you support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		</AttributeAuthorityDescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
		    <OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
		    <OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
		    <OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
		    <EmailAddress>touchstone-dev@mit.edu</EmailAddress>
		</ContactPerson>

	</EntityDescriptor>

	<!-- idpe-staging.mit.edu, ISDA's CAMS staging IdP. -->
	<EntityDescriptor entityID="https://idpe-staging.mit.edu/shibboleth-idp">
	<!--
	The entityID above looks like a location, but it's actually just a name.
	Each entity is assigned a URI name. By convention, it will often be a
	URL, but it should never contain a physical machine hostname that you
	would not otherwise publish to users of the service. For example, if your
	installation runs on a machine named "gryphon.example.org", you would
	generally register that machine in DNS under a second, logical name
	(such as idp.example.org). This logical name should be used in favor
	of the real hostname when you assign an entityID. You should use a name
	like this even if you don't actually register the server in DNS using it.
	The URL does *not* have to resolve into anything to use it as a name.
	The point is for the name you choose to be stable, which is why including
	hostnames is generally bad, since they tend to change.
	-->
		
		<!-- A Shib IdP contains this element with protocol support as shown. -->
		<IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
			
			<Extensions>
				<!-- This is a Shibboleth extension to express attribute scope rules. -->
				<shibmd:Scope>touchstonenetwork.net</shibmd:Scope>
			</Extensions>

			<!--
			One or more KeyDescriptors tell SPs how the IdP will authenticate itself. A single
			descriptor can be used for both signing and for server-TLS if its use attribute
			is set to "signing". You can place an X.509 certificate directly in this element
			to specify the exact public key certificate to use. This only reflects the public
			half of the keypair used by the IdP.
			
			When the IdP signs XML, it uses the private key included in its Credentials
			configuration element, and when TLS is used, the web server will use the
			certificate and private key defined by the web server's configuration.
			An SP will then try to match the certificates in the KeyDescriptors here
			to the ones presented in the XML Signature or SSL session.
			
			When an inline certificate is used, do not assume that an expired certificate
			will be detected and rejected. Often only the key will be extracted without
			regard for the certificate, but at the same time, it may be risky to include
			an expired certificate and assume it will work. Your SAML implementation
			may provide specific guidance on this.
			-->
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>idpe-staging.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>

			<!-- This tells SPs where/how to resolve SAML 1.x artifacts into SAML assertions. -->
			<ArtifactResolutionService index="1"
				Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
				Location="https://idpe-staging.mit.edu:8443/shibboleth-idp/Artifact"/>

			<!-- This tells SPs that you support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
			
			<!-- This tells SPs how and where to request authentication. -->
			<SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest"
			    Location="https://idpe-staging.mit.edu/shibboleth-idp/SSO"/>

		</IDPSSODescriptor>
		
		<!-- Most Shib IdPs also support SAML attribute queries, so this role is also included. -->
		<AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
			
			<Extensions>
				<!-- This is a Shibboleth extension to express attribute scope rules. -->
				<shibmd:Scope>touchstonenetwork.net</shibmd:Scope>
			</Extensions>

			<!-- The certificate has to be repeated here (or a different one specified if necessary). -->
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>idpe-staging.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>

			<!-- This tells SPs how and where to send queries. -->
			<AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
			    Location="https://idpe-staging.mit.edu:8443/shibboleth-idp/AA"/>

			<!-- This tells SPs that you support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		</AttributeAuthorityDescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
		    <OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
		    <OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
		    <OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
		    <EmailAddress>touchstone-dev@mit.edu</EmailAddress>
		</ContactPerson>

	</EntityDescriptor>

	<!-- idp.touchstonenetwork.net, CAMS pilot IdP. -->
	<EntityDescriptor entityID="https://idp.touchstonenetwork.net/shibboleth-idp">
	<!--
	The entityID above looks like a location, but it's actually just a name.
	Each entity is assigned a URI name. By convention, it will often be a
	URL, but it should never contain a physical machine hostname that you
	would not otherwise publish to users of the service. For example, if your
	installation runs on a machine named "gryphon.example.org", you would
	generally register that machine in DNS under a second, logical name
	(such as idp.example.org). This logical name should be used in favor
	of the real hostname when you assign an entityID. You should use a name
	like this even if you don't actually register the server in DNS using it.
	The URL does *not* have to resolve into anything to use it as a name.
	The point is for the name you choose to be stable, which is why including
	hostnames is generally bad, since they tend to change.
	-->
		
		<!-- A Shib IdP contains this element with protocol support as shown. -->
		<IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
			
			<Extensions>
				<!-- This is a Shibboleth extension to express attribute scope rules. -->
				<shibmd:Scope>touchstonenetwork.net</shibmd:Scope>
			</Extensions>

			<!--
			One or more KeyDescriptors tell SPs how the IdP will authenticate itself. A single
			descriptor can be used for both signing and for server-TLS if its use attribute
			is set to "signing". You can place an X.509 certificate directly in this element
			to specify the exact public key certificate to use. This only reflects the public
			half of the keypair used by the IdP.
			
			When the IdP signs XML, it uses the private key included in its Credentials
			configuration element, and when TLS is used, the web server will use the
			certificate and private key defined by the web server's configuration.
			An SP will then try to match the certificates in the KeyDescriptors here
			to the ones presented in the XML Signature or SSL session.
			
			When an inline certificate is used, do not assume that an expired certificate
			will be detected and rejected. Often only the key will be extracted without
			regard for the certificate, but at the same time, it may be risky to include
			an expired certificate and assume it will work. Your SAML implementation
			may provide specific guidance on this.
			-->
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>idp.touchstonenetwork.net</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>

			<!-- This tells SPs where/how to resolve SAML 1.x artifacts into SAML assertions. -->
			<ArtifactResolutionService index="1"
				Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
				Location="https://idp.touchstonenetwork.net:8443/shibboleth-idp/Artifact"/>

			<!-- This tells SPs that you support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
			
			<!-- This tells SPs how and where to request authentication. -->
			<SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest"
			    Location="https://idp.touchstonenetwork.net/shibboleth-idp/SSO"/>

		</IDPSSODescriptor>
		
		<!-- Most Shib IdPs also support SAML attribute queries, so this role is also included. -->
		<AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
			
			<Extensions>
				<!-- This is a Shibboleth extension to express attribute scope rules. -->
				<shibmd:Scope>touchstonenetwork.net</shibmd:Scope>
			</Extensions>

			<!-- The certificate has to be repeated here (or a different one specified if necessary). -->
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>idp.touchstonenetwork.net</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>

			<!-- This tells SPs how and where to send queries. -->
			<AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
			    Location="https://idp.touchstonenetwork.net:8443/shibboleth-idp/AA"/>

			<!-- This tells SPs that you support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		</AttributeAuthorityDescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
		    <OrganizationName xml:lang="en">MIT IS&amp;T</OrganizationName>
		    <OrganizationDisplayName xml:lang="en">MIT Information Services and Technology</OrganizationDisplayName>
		    <OrganizationURL xml:lang="en">http://web.mit.edu/ist/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
		    <EmailAddress>network@mit.edu</EmailAddress>
		</ContactPerson>

	</EntityDescriptor>

	<!-- posteverything.mit.edu, ISDA's test SP. -->
	<EntityDescriptor entityID="https://posteverything.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>posteverything.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://posteverything.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://posteverything.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			<AssertionConsumerService index="3"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://posteverything.mit.edu/Shibboleth2.sso/SAML/Artifact"/>
			<AssertionConsumerService index="4"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://posteverything.mit.edu/secure/other/Shibboleth.sso/SAML/POST"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<GivenName>Robert</GivenName>
			<SurName>Basch</SurName>
			<EmailAddress>rbasch@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- chelsea.mit.edu, our test IIS SP. -->
	<EntityDescriptor entityID="https://chelsea.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>chelsea.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://chelsea.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://chelsea.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<GivenName>Paul</GivenName>
			<SurName>Hill</SurName>
			<EmailAddress>pbh@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- anomie.mit.edu, our test Solaris SP. -->
	<EntityDescriptor entityID="https://anomie.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				        <ds:X509Data>
				        	<ds:X509Certificate>
MIIEYjCCA8ugAwIBAgIJAJOyVyILq8w1MA0GCSqGSIb3DQEBBQUAMIHSMQswCQYD
VQQGEwJVUzEWMBQGA1UECBMNTWFzc2FjaHVzZXR0czESMBAGA1UEBxMJQ2FtYnJp
ZGdlMS4wLAYDVQQKEyVNYXNzYWNodXNldHRzIEluc3RpdHV0ZSBvZiBUZWNobm9s
b2d5MSwwKgYDVQQLEyNJbmZvcm1hdGlvbiBTZXJ2aWNlcyBhbmQgVGVjaG5vbG9n
eTEaMBgGA1UEAxMRYW5vbWllLXNwLm1pdC5lZHUxHTAbBgkqhkiG9w0BCQEWDnJi
YXNjaEBtaXQuZWR1MB4XDTA4MDYyMDIzMTA0NFoXDTA5MDYyMDIzMTA0NFowgdIx
CzAJBgNVBAYTAlVTMRYwFAYDVQQIEw1NYXNzYWNodXNldHRzMRIwEAYDVQQHEwlD
YW1icmlkZ2UxLjAsBgNVBAoTJU1hc3NhY2h1c2V0dHMgSW5zdGl0dXRlIG9mIFRl
Y2hub2xvZ3kxLDAqBgNVBAsTI0luZm9ybWF0aW9uIFNlcnZpY2VzIGFuZCBUZWNo
bm9sb2d5MRowGAYDVQQDExFhbm9taWUtc3AubWl0LmVkdTEdMBsGCSqGSIb3DQEJ
ARYOcmJhc2NoQG1pdC5lZHUwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMo9
ajJG1JeiWETtGTrGuGM9qeex/Of5t+En5OtuLy95iyEoDXuE7h+rBCRkSA+MBc1c
klsvpRt6Q5Xkb7L9vbQES4CI8W+uXP7iLb+FPKtlvTMz5PsXCsm86doBcx2zT9Kj
sqM+sr+lV1clAtz0K0X4HBz/saJfs5LZtFeeSQqbAgMBAAGjggE8MIIBODAdBgNV
HQ4EFgQUp+8/h2E1qIOlrZVjGQzMW+0uXaAwggEHBgNVHSMEgf8wgfyAFKfvP4dh
NaiDpa2VYxkMzFvtLl2goYHYpIHVMIHSMQswCQYDVQQGEwJVUzEWMBQGA1UECBMN
TWFzc2FjaHVzZXR0czESMBAGA1UEBxMJQ2FtYnJpZGdlMS4wLAYDVQQKEyVNYXNz
YWNodXNldHRzIEluc3RpdHV0ZSBvZiBUZWNobm9sb2d5MSwwKgYDVQQLEyNJbmZv
cm1hdGlvbiBTZXJ2aWNlcyBhbmQgVGVjaG5vbG9neTEaMBgGA1UEAxMRYW5vbWll
LXNwLm1pdC5lZHUxHTAbBgkqhkiG9w0BCQEWDnJiYXNjaEBtaXQuZWR1ggkAk7JX
IgurzDUwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQUFAAOBgQBB3tzuUjZP3fwe
K2/HKBcn3XmElGPHvkBvIM1G20cure8BNyoVRdOGAlydP6oDzM59fbKj5SFnvUkK
lXQ/77TcqzWsQMeC8I5Qfwyw7DtsvV+8gqgaLUk2Ojh3o4ewyuFflX/gqzHQAwBS
jSpmOwQoOuu99UFj8ZCmxdmfoVbm5g==
				        	</ds:X509Certificate>
				        </ds:X509Data>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://anomie.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://anomie.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<GivenName>Robert</GivenName>
			<SurName>Basch</SurName>
			<EmailAddress>rbasch@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- stellar-dev.mit.edu, Stellar development SP. -->
	<EntityDescriptor entityID="https://stellar-dev.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>stellar-dev.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://stellar-dev.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://stellar-dev.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">Stellar Development</OrganizationName>
			<OrganizationDisplayName xml:lang="en">Stellar Development</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://stellar.mit.edu/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<GivenName>Craig</GivenName>
			<SurName>Counterman</SurName>
			<EmailAddress>ccount@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- Added stellar-test.mit.edu, test Stellar SP. -->
	<EntityDescriptor entityID="https://stellar-test.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>stellar-test.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://stellar-test.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://stellar-test.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">Stellar</OrganizationName>
			<OrganizationDisplayName xml:lang="en">Stellar</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://stellar.mit.edu/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<GivenName>Craig</GivenName>
			<SurName>Counterman</SurName>
			<EmailAddress>ccount@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- stellar.mit.edu, the Stellar production SP. -->
	<EntityDescriptor entityID="https://stellar.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>stellar.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://stellar.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://stellar.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">Stellar</OrganizationName>
			<OrganizationDisplayName xml:lang="en">Stellar</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://stellar.mit.edu/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<GivenName>Craig</GivenName>
			<SurName>Counterman</SurName>
			<EmailAddress>ccount@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- Added confab-two.mit.edu, test Confluence SP. -->
	<EntityDescriptor entityID="https://confab-two.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>confab-two.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://confab-two.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://confab-two.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>collab-admin@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- wikis.mit.edu, production Confluence SP. -->
	<EntityDescriptor entityID="https://wikis.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>wikis.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://wikis.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://wikis.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>collab-admin@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- Jira server. -->
	<EntityDescriptor entityID="https://jira.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>jira.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://jira.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://jira.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>collab-admin@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- Touchstone test applications server -->
	<EntityDescriptor entityID="https://touchstone-tester.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>touchstone-tester.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://touchstone-tester.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://touchstone-tester.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT IS&amp;T</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT IS&amp;T</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>touchstone-support@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- didnt-ctx01.mit.edu, NIST's IIS server for Citrix -->
	<EntityDescriptor entityID="https://didnt-ctx01.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>didnt-ctx01.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://didnt-ctx01.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://didnt-ctx01.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT NIST</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT NIST</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/network/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>gyying@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- websdls.mit.edu -->
	<EntityDescriptor entityID="https://websdls.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>websdls.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://websdls.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://websdls.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT IS&amp;T</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT IS&amp;T</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>sdls-team@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- ist-dev-sdls1.mit.edu -->
	<EntityDescriptor entityID="https://ist-dev-sdls1.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>ist-dev-sdls1.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://ist-dev-sdls1.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://ist-dev-sdls1.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT IS&amp;T</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT IS&amp;T</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>sdls-team@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- oeit-deb1.mit.edu, OEIT's dev Second Life server -->
	<EntityDescriptor entityID="https://oeit-deb1.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				        <ds:X509Data>
				        	<ds:X509Certificate>
MIIBnzCCAQgCCQC228oMnLQ5TTANBgkqhkiG9w0BAQUFADAUMRIwEAYDVQQDEwls
b2NhbGhvc3QwHhcNMDgwNTA2MjAzODUwWhcNMTgwNTA0MjAzODUwWjAUMRIwEAYD
VQQDEwlsb2NhbGhvc3QwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAKrdio2x
gRhIi39dbd9sqyyGdz4544YTUKKy0mICOmAhb+XTLsOn33CnsjwDXDo/EwdPGuFa
npwJq7qyEpmkqS8qvQW5W1fU19DQvNnxNkzjM0nporJ4/PxhHlDtwmancC4ub5Qh
LaRsJON0G7bWQWpZplSm847ui0zJaqR1znDrAgMBAAEwDQYJKoZIhvcNAQEFBQAD
gYEAlF+RfqzwvwDL5TVomO+NuE5Z/7Uad6AchEj9w1M8qSrrwl8zY/Xl2Va96BJa
syJtMKw4jsiZoMnxQ6Iu7eX4OehLU+veYA5TqvVpH34gU3wsdcd5Z1h98WzZw3H3
8OkSf1O/m2Rx/a1Sw/52Js4R3eUuQPdW5o966MwphDwyDSk=
				        	</ds:X509Certificate>
				        </ds:X509Data>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://oeit-deb1.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://oeit-deb1.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT OEIT</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT OEIT</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/oeit/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>ryoken@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- walter.mit.edu, Libraries' Aleph test server -->
	<EntityDescriptor entityID="https://walter.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>walter.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://walter.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://walter.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT Libraries</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT Libraries</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://libraries.mit.edu/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>fix-lib@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- map-dev-ts1 service provider -->
	<EntityDescriptor entityID="https://map-dev-ts1.mit.edu/shibboleth-sp">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
				        <ds:X509Data>
						<ds:X509Certificate>
MIIDKzCCApSgAwIBAgIDCLD3MA0GCSqGSIb3DQEBBQUAME4xCzAJBgNVBAYTAlVT
MRAwDgYDVQQKEwdFcXVpZmF4MS0wKwYDVQQLEyRFcXVpZmF4IFNlY3VyZSBDZXJ0
aWZpY2F0ZSBBdXRob3JpdHkwHhcNMDgwMjA2MTYyMTIzWhcNMTAwMjA2MTYyMTIz
WjCBtTELMAkGA1UEBhMCVVMxFjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQBgNV
BAcTCUNhbWJyaWRnZTEuMCwGA1UEChMlTWFzc2FjaHVzZXR0cyBJbnN0aXR1dGUg
b2YgVGVjaG5vbG9neTEsMCoGA1UECxMjSW5mb3JtYXRpb24gU2VydmljZXMgYW5k
IFRlY2hub2xvZ3kxHDAaBgNVBAMTE21hcC1kZXYtdHMxLm1pdC5lZHUwgZ8wDQYJ
KoZIhvcNAQEBBQADgY0AMIGJAoGBAOuVryHWRM/XdyJM4dEDfzV+zvXDUp6OJWlq
bDYKLwwqlOH8nGiA4jmNk/QmE+xgYLkoH3tVqKRjFNEWAgyW68b1cNfY0r00FL1w
qSc1MNiyvBIVVpmE8yXgvR0YN26DcvZpiTbsUblhtQVRzGPVmLBLlJz49mZUkzZY
wx15SC4jAgMBAAGjga4wgaswDgYDVR0PAQH/BAQDAgTwMB0GA1UdDgQWBBQmLcB7
GXjyTAWX3thKv4zpX9w7yjA6BgNVHR8EMzAxMC+gLaArhilodHRwOi8vY3JsLmdl
b3RydXN0LmNvbS9jcmxzL3NlY3VyZWNhLmNybDAfBgNVHSMEGDAWgBRI5mj5K9Ky
lddH2CMgEE8zmJCf1DAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDQYJ
KoZIhvcNAQEFBQADgYEAtkjeSeYp3/JnLyIYMp1SEq5kNb4uqA+vt21MU4jvfQKt
s6KJmn/jVfbSird2CwCfb6TShptTE6PC7TjowfuDzUkcdsEXgJ/kA7BT1FvdT4mj
0X7LCgwuKs3Lliyh304D/pmwqyi7iTYpxumJB2z3iCOdcJMjdYEzWcxRTKkZqJc=
				        	</ds:X509Certificate>
				        </ds:X509Data>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://map-dev-ts1.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://map-dev-ts1.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			<AssertionConsumerService index="3"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://map-dev-ts1.mit.edu/cams/admin/Shibboleth.sso/SAML/POST"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT IS&amp;T</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT IS&amp;T</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>touchstone-dev@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- CAMS staging applications server -->
	<EntityDescriptor entityID="https://idpe-staging.mit.edu/shibboleth-sp">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>idpe-staging.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://idpe-staging.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://idpe-staging.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			<AssertionConsumerService index="3"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://idpe-staging.mit.edu/cams/admin/Shibboleth.sso/SAML/POST"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
		    <OrganizationName xml:lang="en">MIT IS&amp;T</OrganizationName>
		    <OrganizationDisplayName xml:lang="en">MIT Information Services and Technology</OrganizationDisplayName>
		    <OrganizationURL xml:lang="en">http://web.mit.edu/ist/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
		    <EmailAddress>network@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- CAMS applications server -->
	<EntityDescriptor entityID="https://idp.touchstonenetwork.net/shibboleth-sp">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>idp.touchstonenetwork.net</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://idp.touchstonenetwork.net/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://idp.touchstonenetwork.net/Shibboleth.sso/SAML/Artifact"/>
			<AssertionConsumerService index="3"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://idp.touchstonenetwork.net/cams/admin/Shibboleth.sso/SAML/POST"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
		    <OrganizationName xml:lang="en">MIT IS&amp;T</OrganizationName>
		    <OrganizationDisplayName xml:lang="en">MIT Information Services and Technology</OrganizationDisplayName>
		    <OrganizationURL xml:lang="en">http://web.mit.edu/ist/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
		    <EmailAddress>network@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- Clearspace dev SP. -->
	<EntityDescriptor entityID="https://cms-dev-tspace1.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>cms-dev-tspace1.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://cms-dev-tspace1.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://cms-dev-tspace1.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>collab-admin@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- Clearspace test SP. -->
	<EntityDescriptor entityID="https://cms-test-tspace1.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>cms-test-tspace1.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://cms-test-tspace1.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://cms-test-tspace1.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>collab-admin@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- Clearspace staging SP. -->
	<EntityDescriptor entityID="https://cms-stage-tspace1.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>cms-stage-tspace1.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://cms-stage-tspace1.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://cms-stage-tspace1.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>map-support@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- Clearspace production SP. -->
	<EntityDescriptor entityID="https://teamspaces.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>teamspaces.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://teamspaces.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://teamspaces.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>map-support@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- Hermes test SP. -->
	<EntityDescriptor entityID="https://divergence.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>divergence.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://divergence.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://divergence.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
		    <OrganizationName xml:lang="en">MIT IS&amp;T</OrganizationName>
		    <OrganizationDisplayName xml:lang="en">MIT Information Services and Technology</OrganizationDisplayName>
		    <OrganizationURL xml:lang="en">http://web.mit.edu/ist/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>hermes-root@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>
		
	<!-- Hermes staging SP. -->
	<EntityDescriptor entityID="https://dolios.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>dolios.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://dolios.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://dolios.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
		    <OrganizationName xml:lang="en">MIT IS&amp;T</OrganizationName>
		    <OrganizationDisplayName xml:lang="en">MIT Information Services and Technology</OrganizationDisplayName>
		    <OrganizationURL xml:lang="en">http://web.mit.edu/ist/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>hermes-root@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- cspace.mit.edu, used for Drupal multisite prototype -->
	<EntityDescriptor entityID="https://cspace.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>cspace.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://cspace.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://cspace.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>map-support@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- ist-dev-pubs1, MIT Website Publications development machine -->
	<EntityDescriptor entityID="https://ist-dev-pubs1.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>ist-dev-pubs1.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://ist-dev-pubs1.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://ist-dev-pubs1.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>map-support@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- ist-test-pubs1, MIT Website Publications test machine -->
	<EntityDescriptor entityID="https://ist-test-pubs1.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>ist-test-pubs1.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://ist-test-pubs1.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://ist-test-pubs1.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>map-support@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- virt-proto-alpha.mit.edu, used for Moodle testing -->
	<EntityDescriptor entityID="https://virt-proto-alpha.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>virt-proto-alpha.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://virt-proto-alpha.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://virt-proto-alpha.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>map-support@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- Quick Pages test SP. -->
	<EntityDescriptor entityID="https://cms-test-qp1.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>cms-test-qp1.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://cms-test-qp1.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://cms-test-qp1.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>map-support@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- Quick Pages production SP. -->
	<EntityDescriptor entityID="https://cms-prod-qp1.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>cms-prod-qp1.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://cms-prod-qp1.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://cms-prod-qp1.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>map-support@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- pch2.mit.edu, used for Drupal testing -->
	<EntityDescriptor entityID="https://pch2.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>pch2.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://pch2.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://pch2.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
		    <OrganizationName xml:lang="en">MIT IS&amp;T</OrganizationName>
		    <OrganizationDisplayName xml:lang="en">MIT Information Services and Technology</OrganizationDisplayName>
		    <OrganizationURL xml:lang="en">http://web.mit.edu/ist/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
		    <EmailAddress>network@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- developers-dev.mit.edu -->
	<EntityDescriptor entityID="https://developers-dev.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>developers-dev.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://developers-dev.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://developers-dev.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>map-support@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

	<!-- developers.mit.edu -->
	<EntityDescriptor entityID="https://developers.mit.edu/shibboleth">
	
		<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
		
			<KeyDescriptor use="signing">
				<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
					<ds:KeyName>developers.mit.edu</ds:KeyName>
				</ds:KeyInfo>
			</KeyDescriptor>
			
			<!-- We support only the Shib handle format. -->
			<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
		    
			<!-- Tell IdPs where and how to send authentication assertions. -->
			<AssertionConsumerService index="1" isDefault="true"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
				Location="https://developers.mit.edu/Shibboleth.sso/SAML/POST"/>
			<AssertionConsumerService index="2"
				Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
				Location="https://developers.mit.edu/Shibboleth.sso/SAML/Artifact"/>
			
		</SPSSODescriptor>

		<!-- This is just information about the entity in human terms. -->
		<Organization>
			<OrganizationName xml:lang="en">MIT ISDA</OrganizationName>
			<OrganizationDisplayName xml:lang="en">MIT ISDA</OrganizationDisplayName>
			<OrganizationURL xml:lang="en">http://web.mit.edu/ist/org/isda/</OrganizationURL>
		</Organization>
		<ContactPerson contactType="technical">
			<EmailAddress>map-support@mit.edu</EmailAddress>
		</ContactPerson>
		
	</EntityDescriptor>

</EntitiesDescriptor>
