<?xml version="1.0" encoding="UTF-8"?>
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" entityID="https://idp.cdh.org.zm/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">cdh.org.zm</shibmd:Scope>

        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel--> 
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEJDCCAoygAwIBAgIVAPUL7ukF/R8Hc3Etn0ZA+b9izjAuMA0GCSqGSIb3DQEB
CwUAMBkxFzAVBgNVBAMMDmlkcC5jZGgub3JnLnptMB4XDTIxMDkxNzExMzY1M1oX
DTQxMDkxNzExMzY1M1owGTEXMBUGA1UEAwwOaWRwLmNkaC5vcmcuem0wggGiMA0G
CSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQCmN5qHecBRlR504MemrMQ/lTiYpxbQ
jQpns9v0YeWQGkp643/+nIyv+qT5WH0vSGy0Inh/0JalvN/D+KsfKTelSzuk9UJJ
zMUiCPpJ8D75Dinv+A+4uXTOXnkMBir9JeJEvl0BVztczLnpe48p+LRbKfw065Dk
f+c8ey9awd8M+E3U+uNUGLTwLS2/ndUwOrT0kJ8YwKh8pxID/32StHk4c3ZH1pEb
ygo53IP4zch+O/xi6TbVXYxoELyKyqaj91pD2nX+tm9VfB4BIsysXjzdbLW6jq7c
N6bJKlZyjE/A5bR3xeJnvjaRCk/6QM9yN0jhEsDGEA79rVTkphrRKhq3zd8YYCp8
xpjQBpvJwwCf3PQVsqxJCYn3BjuBpdtvkzvWCcYf309NYakrGyll2ZMdx9O8lNpN
CGHN39Rq6nXvxK/RKZBO4VxtNAUA5Pz/huHr/GIemh+fxvRzUc+VlQTNInZtjRyu
ECBUCJeGHSmUiGbFZQhyVIdjN6hKizB9/U8CAwEAAaNjMGEwHQYDVR0OBBYEFPas
Rq1ChiYtJUD/t8dsLtzKsUy/MEAGA1UdEQQ5MDeCDmlkcC5jZGgub3JnLnpthiVo
dHRwczovL2lkcC5jZGgub3JnLnptL2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEB
CwUAA4IBgQB5Fep3isd+q/J53XTp3kFf393GSLRt4flGqqVWUwDCSejhYlcGjw3U
dh/8pS+QapcJBHXvqvFVd5Vn/AeMi0i2pBTZHd8bsTHJbw1676StcdFbGnUH3as9
TB0UeT3RhTz1ajkCXqr2GSBo9zKit+kSYl94bCjR2V1Q0Vv8w9rBMOqgDRfLvsOX
K2HC9Cd/IRqTTlFzOpLB5MmuEaUzaSTBbZuBLQ5c6HyUiRy/pnhHiK1liOAFb5xL
jb4LISpUuaZpfMscg2nVAZvKZleHWuz714p00rBYyhFJXQKVlx9InJxkMkJKVUsC
rPrhCeC94McvBW4np9DPlFjIEwCfzw1lHGU6YqE371FutRveRgvROnENlBAQfGQZ
MEOnagQ8CuJriOMXCIvr1ZYq9M0z5WupfbrHdo0rErMu/r9ed655SXSX4rOqCpFg
Rx1v54bzLg978hbCmGAGP4NCchoX1r5GjpNaDGlACi22n1t4rmzNp/n6OkRQ7OMK
6xg4JO70Q30=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEIzCCAougAwIBAgIUScb/oAxBQRWdRGPdPfLk2HVuXW0wDQYJKoZIhvcNAQEL
BQAwGTEXMBUGA1UEAwwOaWRwLmNkaC5vcmcuem0wHhcNMjEwOTE3MTEzNjE4WhcN
NDEwOTE3MTEzNjE4WjAZMRcwFQYDVQQDDA5pZHAuY2RoLm9yZy56bTCCAaIwDQYJ
KoZIhvcNAQEBBQADggGPADCCAYoCggGBAMoV1V6w4r27mJLtmeAZMKeo2Sk2rhIZ
csE+y5AcZ8tWr+I5CiWjkWPIUT5XmdOJLnXXAZZnwyyUMls+icy+ExEWhOmYWj3I
n+kkanYVpQpgjHO9GP6He/807RjRMox9ZDZ4QpzKRvYwSI/1JlNOKFs/FyC1cHs5
1CE0sLrGTQjH4HlCSZ0eXVY4+NA0Zo9Amm2bDbtKRxELfr74HSd3zLqTUlIhWQb/
jODgdGNVuSPYb4roZv5xqriYEciUg8wbY8Lo6QLo0PrLW/GcuhuFawTIBxv1Skcm
F2VPIoN+xqgH28OwyXps37O5MHnE3SwB6UM8EFibwZ+N4YMpW7ozWg7ReW7cogy/
7KWL0I0PQoK0n7JLhXyP56KYgyzTExEkvfctqGsrWHWmh0B292udxS/yLkClvYrA
eXBmniqVFUzK/vZRKxrgDEjd204U1Vfdhga9aYUyFp2N1FXpB/SuKRctTWGlooGN
5MwR3gnbZ1VePrf82gA+A9SDuxaKJw8wLQIDAQABo2MwYTAdBgNVHQ4EFgQUy58r
aIHCde9HoiD2A/rkuxjJUYMwQAYDVR0RBDkwN4IOaWRwLmNkaC5vcmcuem2GJWh0
dHBzOi8vaWRwLmNkaC5vcmcuem0vaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQEL
BQADggGBALMlmIL+EQdACNexVS+dg2R6FhmkxFod+UC3TR44FZDB3wXu+TtvPz+e
IIk4f/k/J7dmtncnPfuC09wK0WZ99a8Kgtyi0kwVytMH4DFkLhefHmbB+nDXvyWp
vb57mTEX6M33TdEO3kTT783lxTEgq69sGO3Q1lSgU5yr3LGoKaB8q4Gs8xOzp70Q
C67onznMgFJmmLH7SwNKwvTOpmICbKev/OX64GSKDIraLdRRXPM3/aqRt3TatPcp
YIDZqM6F+KGt7bM9JzI5wcIYoKoCQtmsgJ0gEOy6oaUXrcAHClfSx5UsFW+WQZKr
8HLwHsGXXRX9j7DF6DYyK44EesjqSemX1eNTHx8r1wp06dl/ovQ3IVN7VvrhQLEy
nyUQcR9/GhlcGRjcPIg9bI/ZDANpPWxtWUqidB548XkwcSX7TdPRKxLmfbVsy5f3
+iHdRkgJsIDEz2kOBhk/C7t+S9UI0u1aEXeNUYua6FDbwmZvyuxNY16fyCgBBLiT
djdycNzLjw==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEJDCCAoygAwIBAgIVAP/ur6Da1QbIDGKnI8s2tIDfwMLfMA0GCSqGSIb3DQEB
CwUAMBkxFzAVBgNVBAMMDmlkcC5jZGgub3JnLnptMB4XDTIxMDkxNzExMzYxOFoX
DTQxMDkxNzExMzYxOFowGTEXMBUGA1UEAwwOaWRwLmNkaC5vcmcuem0wggGiMA0G
CSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQCL1PpntJLjVU1X6j4/AcMuhXbWtord
FyboiN+JErF4NOREWh+pl8aiOAyskVMyA6A+S5aZHBVQzjnkl2Nrn8asB2w2fCV+
tyTqdHH9oOp1andaikiBgHrd3TrWeu24wdQhtoPj6bsD1t/WyL9u37dJcQn7H7vo
hhM7ErqMMvbgQdPE5R4juCxl1V88owpeK7OZXv4577RA4hLjstr2MfH18tCyFflU
naFqPKCv2XxkXiSzp6c/xQ+G5wXmjf1snzH5/YBvjvmSmCKhXGXNgMnrUGY4/9Am
8tlzbEumUJK3YsimPeMofbLZgRGrPM/S0otdJWqThjFsYPio13qnEzPsn1FtbtgH
Pw932T/2l4utR1mp5P9G8XEgZSidxbJXQeuIJqR0Dc9c+lm5rLHj9Oy5DOiF+mop
CJ9XdQnjk3j702Hrf3rJUDhmXQ4Bjb4wpJw9C8mmDqSGnYj/S2emcG+to4HPJ5hp
GlxBAieM32lKAlWbBA2f00gT6G92OWwtW70CAwEAAaNjMGEwHQYDVR0OBBYEFB67
G2lL+0U+i0iFQmZzPZ+inl5ZMEAGA1UdEQQ5MDeCDmlkcC5jZGgub3JnLnpthiVo
dHRwczovL2lkcC5jZGgub3JnLnptL2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEB
CwUAA4IBgQBxGJhtQdjTVVY/xl5v7t0AtD8dCjNjyUbDze7k6UwslywMFnKos2wf
/OcJmPpLworJN19BlpQl218g+u77BmNIYDHe+6KAZHHqmFEz0yrZLgubeVC3nKLJ
msf3YYLHz5/PsrqSNKtTbh3u7D5HG9DEmweClk9bs4Jg9Jf2al9P2FCLMbR6A9cD
ytjuSNuIzuU5GsCv9/fJ3yVv954AEGmdLgwJv+iUZv9kG3o/WG9ociKKoQk1kMoV
RkaYsbMIbd3AAWADven7iLacsfzoo826GqPGalLLNYm0A8/CqN0l8Qz5GRfxA2OX
oE9k9zGlvq0dpeTpDIknXfpzOJ/3TztMJo6pRY3paB2iG59HYta3+dP5Ga8mMYpC
AuUw2DBO1zQfZobpeJB8Zmgb+0RNnn5EA6weZn2Q54Xn73JqTlrPY2d2cqgRokvj
Xux1b7D1AxHkRjwkwLBs4e7JHvBPyntJiwjoMKEqdiVPgZ5IQ/8+xLPEjg3pEr7D
29+rBR1CrOs=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.cdh.org.zm/idp/profile/SAML2/SOAP/ArtifactResolution" index="1"/>
	<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>

        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://idp.cdh.org.zm/idp/profile/SAML2/POST-SimpleSign/SSO"/>
         <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://idp.cdh.org.zm/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://idp.cdh.org.zm/idp/profile/SAML2/Redirect/SSO"/>

    </IDPSSODescriptor>


<!--    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">cdh.org.zm</shibmd:Scope>
        </Extensions>

        --> <!-- First signing certificate is BackChannel, the Second is FrontChannel-->  <!--
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEJDCCAoygAwIBAgIVAPUL7ukF/R8Hc3Etn0ZA+b9izjAuMA0GCSqGSIb3DQEB
CwUAMBkxFzAVBgNVBAMMDmlkcC5jZGgub3JnLnptMB4XDTIxMDkxNzExMzY1M1oX
DTQxMDkxNzExMzY1M1owGTEXMBUGA1UEAwwOaWRwLmNkaC5vcmcuem0wggGiMA0G
CSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQCmN5qHecBRlR504MemrMQ/lTiYpxbQ
jQpns9v0YeWQGkp643/+nIyv+qT5WH0vSGy0Inh/0JalvN/D+KsfKTelSzuk9UJJ
zMUiCPpJ8D75Dinv+A+4uXTOXnkMBir9JeJEvl0BVztczLnpe48p+LRbKfw065Dk
f+c8ey9awd8M+E3U+uNUGLTwLS2/ndUwOrT0kJ8YwKh8pxID/32StHk4c3ZH1pEb
ygo53IP4zch+O/xi6TbVXYxoELyKyqaj91pD2nX+tm9VfB4BIsysXjzdbLW6jq7c
N6bJKlZyjE/A5bR3xeJnvjaRCk/6QM9yN0jhEsDGEA79rVTkphrRKhq3zd8YYCp8
xpjQBpvJwwCf3PQVsqxJCYn3BjuBpdtvkzvWCcYf309NYakrGyll2ZMdx9O8lNpN
CGHN39Rq6nXvxK/RKZBO4VxtNAUA5Pz/huHr/GIemh+fxvRzUc+VlQTNInZtjRyu
ECBUCJeGHSmUiGbFZQhyVIdjN6hKizB9/U8CAwEAAaNjMGEwHQYDVR0OBBYEFPas
Rq1ChiYtJUD/t8dsLtzKsUy/MEAGA1UdEQQ5MDeCDmlkcC5jZGgub3JnLnpthiVo
dHRwczovL2lkcC5jZGgub3JnLnptL2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEB
CwUAA4IBgQB5Fep3isd+q/J53XTp3kFf393GSLRt4flGqqVWUwDCSejhYlcGjw3U
dh/8pS+QapcJBHXvqvFVd5Vn/AeMi0i2pBTZHd8bsTHJbw1676StcdFbGnUH3as9
TB0UeT3RhTz1ajkCXqr2GSBo9zKit+kSYl94bCjR2V1Q0Vv8w9rBMOqgDRfLvsOX
K2HC9Cd/IRqTTlFzOpLB5MmuEaUzaSTBbZuBLQ5c6HyUiRy/pnhHiK1liOAFb5xL
jb4LISpUuaZpfMscg2nVAZvKZleHWuz714p00rBYyhFJXQKVlx9InJxkMkJKVUsC
rPrhCeC94McvBW4np9DPlFjIEwCfzw1lHGU6YqE371FutRveRgvROnENlBAQfGQZ
MEOnagQ8CuJriOMXCIvr1ZYq9M0z5WupfbrHdo0rErMu/r9ed655SXSX4rOqCpFg
Rx1v54bzLg978hbCmGAGP4NCchoX1r5GjpNaDGlACi22n1t4rmzNp/n6OkRQ7OMK
6xg4JO70Q30=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEIzCCAougAwIBAgIUScb/oAxBQRWdRGPdPfLk2HVuXW0wDQYJKoZIhvcNAQEL
BQAwGTEXMBUGA1UEAwwOaWRwLmNkaC5vcmcuem0wHhcNMjEwOTE3MTEzNjE4WhcN
NDEwOTE3MTEzNjE4WjAZMRcwFQYDVQQDDA5pZHAuY2RoLm9yZy56bTCCAaIwDQYJ
KoZIhvcNAQEBBQADggGPADCCAYoCggGBAMoV1V6w4r27mJLtmeAZMKeo2Sk2rhIZ
csE+y5AcZ8tWr+I5CiWjkWPIUT5XmdOJLnXXAZZnwyyUMls+icy+ExEWhOmYWj3I
n+kkanYVpQpgjHO9GP6He/807RjRMox9ZDZ4QpzKRvYwSI/1JlNOKFs/FyC1cHs5
1CE0sLrGTQjH4HlCSZ0eXVY4+NA0Zo9Amm2bDbtKRxELfr74HSd3zLqTUlIhWQb/
jODgdGNVuSPYb4roZv5xqriYEciUg8wbY8Lo6QLo0PrLW/GcuhuFawTIBxv1Skcm
F2VPIoN+xqgH28OwyXps37O5MHnE3SwB6UM8EFibwZ+N4YMpW7ozWg7ReW7cogy/
7KWL0I0PQoK0n7JLhXyP56KYgyzTExEkvfctqGsrWHWmh0B292udxS/yLkClvYrA
eXBmniqVFUzK/vZRKxrgDEjd204U1Vfdhga9aYUyFp2N1FXpB/SuKRctTWGlooGN
5MwR3gnbZ1VePrf82gA+A9SDuxaKJw8wLQIDAQABo2MwYTAdBgNVHQ4EFgQUy58r
aIHCde9HoiD2A/rkuxjJUYMwQAYDVR0RBDkwN4IOaWRwLmNkaC5vcmcuem2GJWh0
dHBzOi8vaWRwLmNkaC5vcmcuem0vaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQEL
BQADggGBALMlmIL+EQdACNexVS+dg2R6FhmkxFod+UC3TR44FZDB3wXu+TtvPz+e
IIk4f/k/J7dmtncnPfuC09wK0WZ99a8Kgtyi0kwVytMH4DFkLhefHmbB+nDXvyWp
vb57mTEX6M33TdEO3kTT783lxTEgq69sGO3Q1lSgU5yr3LGoKaB8q4Gs8xOzp70Q
C67onznMgFJmmLH7SwNKwvTOpmICbKev/OX64GSKDIraLdRRXPM3/aqRt3TatPcp
YIDZqM6F+KGt7bM9JzI5wcIYoKoCQtmsgJ0gEOy6oaUXrcAHClfSx5UsFW+WQZKr
8HLwHsGXXRX9j7DF6DYyK44EesjqSemX1eNTHx8r1wp06dl/ovQ3IVN7VvrhQLEy
nyUQcR9/GhlcGRjcPIg9bI/ZDANpPWxtWUqidB548XkwcSX7TdPRKxLmfbVsy5f3
+iHdRkgJsIDEz2kOBhk/C7t+S9UI0u1aEXeNUYua6FDbwmZvyuxNY16fyCgBBLiT
djdycNzLjw==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEJDCCAoygAwIBAgIVAP/ur6Da1QbIDGKnI8s2tIDfwMLfMA0GCSqGSIb3DQEB
CwUAMBkxFzAVBgNVBAMMDmlkcC5jZGgub3JnLnptMB4XDTIxMDkxNzExMzYxOFoX
DTQxMDkxNzExMzYxOFowGTEXMBUGA1UEAwwOaWRwLmNkaC5vcmcuem0wggGiMA0G
CSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQCL1PpntJLjVU1X6j4/AcMuhXbWtord
FyboiN+JErF4NOREWh+pl8aiOAyskVMyA6A+S5aZHBVQzjnkl2Nrn8asB2w2fCV+
tyTqdHH9oOp1andaikiBgHrd3TrWeu24wdQhtoPj6bsD1t/WyL9u37dJcQn7H7vo
hhM7ErqMMvbgQdPE5R4juCxl1V88owpeK7OZXv4577RA4hLjstr2MfH18tCyFflU
naFqPKCv2XxkXiSzp6c/xQ+G5wXmjf1snzH5/YBvjvmSmCKhXGXNgMnrUGY4/9Am
8tlzbEumUJK3YsimPeMofbLZgRGrPM/S0otdJWqThjFsYPio13qnEzPsn1FtbtgH
Pw932T/2l4utR1mp5P9G8XEgZSidxbJXQeuIJqR0Dc9c+lm5rLHj9Oy5DOiF+mop
CJ9XdQnjk3j702Hrf3rJUDhmXQ4Bjb4wpJw9C8mmDqSGnYj/S2emcG+to4HPJ5hp
GlxBAieM32lKAlWbBA2f00gT6G92OWwtW70CAwEAAaNjMGEwHQYDVR0OBBYEFB67
G2lL+0U+i0iFQmZzPZ+inl5ZMEAGA1UdEQQ5MDeCDmlkcC5jZGgub3JnLnpthiVo
dHRwczovL2lkcC5jZGgub3JnLnptL2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEB
CwUAA4IBgQBxGJhtQdjTVVY/xl5v7t0AtD8dCjNjyUbDze7k6UwslywMFnKos2wf
/OcJmPpLworJN19BlpQl218g+u77BmNIYDHe+6KAZHHqmFEz0yrZLgubeVC3nKLJ
msf3YYLHz5/PsrqSNKtTbh3u7D5HG9DEmweClk9bs4Jg9Jf2al9P2FCLMbR6A9cD
ytjuSNuIzuU5GsCv9/fJ3yVv954AEGmdLgwJv+iUZv9kG3o/WG9ociKKoQk1kMoV
RkaYsbMIbd3AAWADven7iLacsfzoo826GqPGalLLNYm0A8/CqN0l8Qz5GRfxA2OX
oE9k9zGlvq0dpeTpDIknXfpzOJ/3TztMJo6pRY3paB2iG59HYta3+dP5Ga8mMYpC
AuUw2DBO1zQfZobpeJB8Zmgb+0RNnn5EA6weZn2Q54Xn73JqTlrPY2d2cqgRokvj
Xux1b7D1AxHkRjwkwLBs4e7JHvBPyntJiwjoMKEqdiVPgZ5IQ/8+xLPEjg3pEr7D
29+rBR1CrOs=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.cdh.org.zm/idp/profile/SAML2/SOAP/AttributeQuery"/>

    </AttributeAuthorityDescriptor>--> 

</EntityDescriptor>
