﻿<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" validUntil="2021-01-19T19:10:29.052Z" entityID="https://idp.npu.cz/idp/shibboleth">

    <Extensions>
        <!-- eduGAIN -->
        <eduidmd:RepublishRequest xmlns:eduidmd="http://eduid.cz/schema/metadata/1.0">
            <eduidmd:RepublishTarget>http://edugain.org/</eduidmd:RepublishTarget>
        </eduidmd:RepublishRequest>
    </Extensions>

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">npu.cz</shibmd:Scope>
            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">The National Heritage Institute</mdui:DisplayName>
                <mdui:DisplayName xml:lang="cs">Národní památkový ústav</mdui:DisplayName>
                <mdui:Description xml:lang="en">The National Heritage Institute's Identity Provider</mdui:Description>
                <mdui:Description xml:lang="cs">Poskytovatel identity pro Národní památkový ústav</mdui:Description>
                <mdui:InformationURL xml:lang="en">https://www.npu.cz/en</mdui:InformationURL>
                <mdui:InformationURL xml:lang="cs">https://www.npu.cz/cs</mdui:InformationURL>
                <mdui:Logo height="129" width="146">https://idp.npu.cz/idp/images/NPU_logo.jpg</mdui:Logo>
            </mdui:UIInfo>

        </Extensions>
        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEQDCCAqigAwIBAgIVAMefGEEeBfbfqs3neTFGmQw86RlFMA0GCSqGSIb3DQEB
CwUAMCAxHjAcBgNVBAMMFURURURVSUQwMS5ucHVkdC5sb2NhbDAeFw0yMTAxMTkx
OTA5NTFaFw00MTAxMTkxOTA5NTFaMCAxHjAcBgNVBAMMFURURURVSUQwMS5ucHVk
dC5sb2NhbDCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAIJ3Gx5DmuoC
JvuveLPl27eoPoIC0p0/c5rwS20vYCkmnZYSXfO5Wy8XaK1e2zwPvYxBAyXsYpEq
dCTwNBsQ8sKuLOHELYp0j5Q1/PZcR0PfYnkVcqxCIPQZclXZTcjKO7RF0LwcgYbC
ZsuoEs4DoXJ9mfKdz9+7l6LFHZ9k7ejNbd4/2uicHg9qLA4n7+wOGO7iVXC9cMjg
LWjn6mnTIY+y+zxsu2pow2C9gpy6WQo+xbbpB89xr9y0E9KZwraCdhoxHMRom1wN
ncu3UGXfYjss6CkRrGCAeg0e8VtmIIupPHmy1wtKEanuzUzrnb+28lzBBWxPbuvG
pU9DRLb3+ZQyDrAZPy0vJxk9PIBih372ceGFxqOZtaMUl7N1mIp1j0GOTmy6UoCG
24rZAylpkmLZ3j2q2musNaA6NHBmD5AaPQ9et5zeQTHrbk9XD6flDG+Ng4SPad0s
1Kxg+vv42uKAOXdbYnDHJpRdx26euicPh2OvQUHj3NkqTjJol3EYPwIDAQABo3Ew
bzAdBgNVHQ4EFgQUDGmIpm8HjI1tOD6GeqbEa5qml04wTgYDVR0RBEcwRYIVRFRF
RFVJRDAxLm5wdWR0LmxvY2FshixodHRwczovL0RURURVSUQwMS5ucHVkdC5sb2Nh
bC9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAYEAOi2Nhsaia6h25ry+
Xh+HpQtiT/sLP2ggjspS1QXxcAJiu4lR9f/8W3bYd0+1pvef1oZfmznexBxtLy6s
h/5gI5voejZ7eeSuCEuKtQ8qI7KirJsstVHW0seVXSrt1sVq9P4fJRUyoakWrccn
lWPmqCLnblRuHt840zTMV1h+9ft/OGa51qZcSasr+nz+qWTAiSLzMx/FGZuGE3c+
CjK34LQajfhN6m1BYHp08iN4HZBk0E5AgbfXe6N6DL8gGPlmBvGj0iVhKxgGVxaZ
xrt8s3pO/kzF8ONEe6NnXyLKuKSz1DGJsybREWyopstEZSqSKXMNa7DdUKBjS7Ay
97B7RVLqDYoQKO5r0hDdmQKVr4+uWzHLQF7WyHoCwTgO32NAiSeE600MIotyS/sZ
6UVTXTPB0L7x7eMzNPDQNrI71jUaPDtZPLYlNhu6YrBMPiqDmmSBHjXkFI82kaW6
vPRHA93QubU+IWwn8Y2EXzgxPXFcjtGUITZ1YX14XsRnybaS
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEQDCCAqigAwIBAgIVAJyiWX3fvWI5sGgnkVey3EV+VdCIMA0GCSqGSIb3DQEB
CwUAMCAxHjAcBgNVBAMMFURURURVSUQwMS5ucHVkdC5sb2NhbDAeFw0yMTAxMTkx
OTA5MjhaFw00MTAxMTkxOTA5MjhaMCAxHjAcBgNVBAMMFURURURVSUQwMS5ucHVk
dC5sb2NhbDCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAJfqHtBqKJJk
a0gzOin0Uf+YRAkXSlTL0pHTwDNa/Ne5neggC4u6kN6M+0pw+N5+AYtpNOiUfxMY
UV/yXki5GuqZZ7fkpbfkSLsxW4Gp4onX4wFRTiVtNRlUAD/AzeP/GfuGc5Pt1HgK
LrTqcZ3Xa/h8ikJI2bMPLmhPoRQ1PB2C2Dy/NS8LTBLv5fvPquJz8ceRGjnXWv2A
pZlVBu18yPADk1mSBWxLy+N0e0k5+oWBG8F7qLYxDFvtBm/VtMQmt9Uz+bVmAq3D
2i4jeKrBfEwryr8pFAgaGTAGcebFPkd3NBJskR36xD2QyRZh4U3Zr+K5dKw15m7L
ENWBzB7YP1jMsUEdn4IktFtS1OJ5GdqvnMu5pmCmXYAU8AfPTrbxiz2WIfMIqnue
ReqMwa0gY/ArI5OpbiMANaykILstfqNmgs8Mg1TceMDhOfsxu74u00D2ASPxJOgg
U8RUb6HGRxljFCabIjo+DPVF5Rzbw65MEwJ7SquVkRExS86uGpRWnQIDAQABo3Ew
bzAdBgNVHQ4EFgQUEvzxrBCmQLIOiEcPttJ4jSu50iYwTgYDVR0RBEcwRYIVRFRF
RFVJRDAxLm5wdWR0LmxvY2FshixodHRwczovL0RURURVSUQwMS5ucHVkdC5sb2Nh
bC9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAYEADUTgDi06TPY3kxT5
/E8YAzRGd/2FZpKN5RAglOWUsSUxdM8bWjzRr3U5oU5vMi6OyRlmCejNQolrn8Tz
4puLNR3/pbLYRN6QDNzccU5hT6xUa1fqYUpoEWqkMqU6NyvkUV85AH+T0jT8SyMj
gbKrox9J6N28ELCZx4qmG3flJZ3/It1HwiLU8Z5Ku0Tj46SdrKrd7u9tCRXA2kx2
PnKnCbFn/mexLmJsbX+RPv5+VZRDnbbc4q4JHSzuPjvdUUpJLDY3LrhvCfZOlMgV
LoKi+jJ5fkmnU0AXk3AUpZAdHYUbOVJiC1oAdRjWhi2x3kcwo8q8SZVH0x4lFqbs
if96EyrOtSnE1vtEpPd5w0YrIm1FXPsrJly1pLCiNxj3dLdLGhpfGihZn8+C/OIh
dWEupDyGw6Vitr8FJGm3/6E1N85UcoxNL3FGGsHKyHVBC3rgW7Rjmhj1R2Eg6qMm
voVV6Kpfz6C9rCZwzjtaA+BBeD0YSFgSgpu/6DHXJonKa5Sc
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEPzCCAqegAwIBAgIUNbqwFgFDI5AppBQ23MuwQaZ+ftIwDQYJKoZIhvcNAQEL
BQAwIDEeMBwGA1UEAwwVRFRFRFVJRDAxLm5wdWR0LmxvY2FsMB4XDTIxMDExOTE5
MDkzMFoXDTQxMDExOTE5MDkzMFowIDEeMBwGA1UEAwwVRFRFRFVJRDAxLm5wdWR0
LmxvY2FsMIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEAg0uEwnz4vJD0
Yrp1oH+Ljd1a21Q18gwtpGLbzj9yXg/iswW9Qyv3jCnJUxhq/L/XONrs2d5g19zW
bUQbn3Dg21kwFbiLH4vlF+tC/C0msnS1dgRKpwbaa/F+fJmbvMIu8xeg3x016emT
dCKxXt8FhuX2UJ+j6xRb5X/7NCz6f7z9Ex/WeRHMSH6fCMFKWBNZx0mFgyCiICmF
/kLlnPzWQgffb6O+6s1YvUuz9r9REmNayvwuKVo59LAwtK/rLeqyZU8ZZaeC2xLO
neakkRiZdeptYzNPpUjLKcvxmbhe8KzuDiPqyT7PZvmTYeTCd4TBHdyXwxXWF7fg
13hqi4ekjCAFlQxyCpujLTfKSa/l9X4s3jFCPcSV2v2VBSgJNEm4WPEVkzDbvEYq
Ak3/fNTb+H4H/D0S6DltrDq4NjDNrOWtfUBM9Diw8sqviuWjssWLCiCmE4PsdDtZ
p7k98BHKIouALosi+SaMv7kzl57mXpHF/buCNk+JJNxu7LRHPRrjAgMBAAGjcTBv
MB0GA1UdDgQWBBSAASX82HyQmxAab36SucRWxclZyDBOBgNVHREERzBFghVEVEVE
VUlEMDEubnB1ZHQubG9jYWyGLGh0dHBzOi8vRFRFRFVJRDAxLm5wdWR0LmxvY2Fs
L2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBgQBqrFJg6rRmwq9wH9RK
PEtOmMe9MKYc58NwATC6UQQfSKe/qw39kGfooQsxDe+VsyeS7GEVpB5+LOasgCSD
je2fTuVy9n84d8dWB+RBwBn+qe8TVMRs4xvN71sHa3gto2SMMa/nR6+ngB+a1QZ3
aiPWcgRzOCK/x30H8lOpVW/yNfbBrYhDq0QMzZyFjCFk62GG6Kxxyq7/asweqaka
EOYXAHQ4ft8qDo65H5qu6eCyo6q6NKg+XgDZfYbLSdWaWHo6AO+S0LuCAARkgjlg
OlH66vt9Tc+RnE0aI8tA7cKIA7jbtdFpnEhvTj2TwgUwzZV6Mk5KKGdI2F48tZ8y
goIDibgNGOem1sox2uKBRuAKjTwEu9kBmBytDo+B99AYFZZktcJMcc7mPYp2EqGi
+EhcY8fNy7JH5QKq/uOWvFNd/Gu5aQNUlWo8wyTzj8o5G/A6jiygKfQ6dr28cHtA
wYjWCrbCbOnu5aXqxBTNgpZEzhQQOU0Fr8xyrHcDFQsOHhY=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.npu.cz:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.npu.cz:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>

        <!--
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.npu.cz/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.npu.cz/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.npu.cz:8443/idp/profile/SAML2/SOAP/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.npu.cz/idp/profile/SAML2/POST/SLO"/>
        -->

        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>

        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://idp.npu.cz/idp/profile/SAML2/Redirect/SSO"/>
        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.npu.cz/idp/profile/Shibboleth/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://idp.npu.cz/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://idp.npu.cz/idp/profile/SAML2/POST/SSO"/>

    </IDPSSODescriptor>


    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">npu.cz</shibmd:Scope>
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel -->
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEQDCCAqigAwIBAgIVAMefGEEeBfbfqs3neTFGmQw86RlFMA0GCSqGSIb3DQEB
CwUAMCAxHjAcBgNVBAMMFURURURVSUQwMS5ucHVkdC5sb2NhbDAeFw0yMTAxMTkx
OTA5NTFaFw00MTAxMTkxOTA5NTFaMCAxHjAcBgNVBAMMFURURURVSUQwMS5ucHVk
dC5sb2NhbDCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAIJ3Gx5DmuoC
JvuveLPl27eoPoIC0p0/c5rwS20vYCkmnZYSXfO5Wy8XaK1e2zwPvYxBAyXsYpEq
dCTwNBsQ8sKuLOHELYp0j5Q1/PZcR0PfYnkVcqxCIPQZclXZTcjKO7RF0LwcgYbC
ZsuoEs4DoXJ9mfKdz9+7l6LFHZ9k7ejNbd4/2uicHg9qLA4n7+wOGO7iVXC9cMjg
LWjn6mnTIY+y+zxsu2pow2C9gpy6WQo+xbbpB89xr9y0E9KZwraCdhoxHMRom1wN
ncu3UGXfYjss6CkRrGCAeg0e8VtmIIupPHmy1wtKEanuzUzrnb+28lzBBWxPbuvG
pU9DRLb3+ZQyDrAZPy0vJxk9PIBih372ceGFxqOZtaMUl7N1mIp1j0GOTmy6UoCG
24rZAylpkmLZ3j2q2musNaA6NHBmD5AaPQ9et5zeQTHrbk9XD6flDG+Ng4SPad0s
1Kxg+vv42uKAOXdbYnDHJpRdx26euicPh2OvQUHj3NkqTjJol3EYPwIDAQABo3Ew
bzAdBgNVHQ4EFgQUDGmIpm8HjI1tOD6GeqbEa5qml04wTgYDVR0RBEcwRYIVRFRF
RFVJRDAxLm5wdWR0LmxvY2FshixodHRwczovL0RURURVSUQwMS5ucHVkdC5sb2Nh
bC9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAYEAOi2Nhsaia6h25ry+
Xh+HpQtiT/sLP2ggjspS1QXxcAJiu4lR9f/8W3bYd0+1pvef1oZfmznexBxtLy6s
h/5gI5voejZ7eeSuCEuKtQ8qI7KirJsstVHW0seVXSrt1sVq9P4fJRUyoakWrccn
lWPmqCLnblRuHt840zTMV1h+9ft/OGa51qZcSasr+nz+qWTAiSLzMx/FGZuGE3c+
CjK34LQajfhN6m1BYHp08iN4HZBk0E5AgbfXe6N6DL8gGPlmBvGj0iVhKxgGVxaZ
xrt8s3pO/kzF8ONEe6NnXyLKuKSz1DGJsybREWyopstEZSqSKXMNa7DdUKBjS7Ay
97B7RVLqDYoQKO5r0hDdmQKVr4+uWzHLQF7WyHoCwTgO32NAiSeE600MIotyS/sZ
6UVTXTPB0L7x7eMzNPDQNrI71jUaPDtZPLYlNhu6YrBMPiqDmmSBHjXkFI82kaW6
vPRHA93QubU+IWwn8Y2EXzgxPXFcjtGUITZ1YX14XsRnybaS
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEQDCCAqigAwIBAgIVAJyiWX3fvWI5sGgnkVey3EV+VdCIMA0GCSqGSIb3DQEB
CwUAMCAxHjAcBgNVBAMMFURURURVSUQwMS5ucHVkdC5sb2NhbDAeFw0yMTAxMTkx
OTA5MjhaFw00MTAxMTkxOTA5MjhaMCAxHjAcBgNVBAMMFURURURVSUQwMS5ucHVk
dC5sb2NhbDCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAJfqHtBqKJJk
a0gzOin0Uf+YRAkXSlTL0pHTwDNa/Ne5neggC4u6kN6M+0pw+N5+AYtpNOiUfxMY
UV/yXki5GuqZZ7fkpbfkSLsxW4Gp4onX4wFRTiVtNRlUAD/AzeP/GfuGc5Pt1HgK
LrTqcZ3Xa/h8ikJI2bMPLmhPoRQ1PB2C2Dy/NS8LTBLv5fvPquJz8ceRGjnXWv2A
pZlVBu18yPADk1mSBWxLy+N0e0k5+oWBG8F7qLYxDFvtBm/VtMQmt9Uz+bVmAq3D
2i4jeKrBfEwryr8pFAgaGTAGcebFPkd3NBJskR36xD2QyRZh4U3Zr+K5dKw15m7L
ENWBzB7YP1jMsUEdn4IktFtS1OJ5GdqvnMu5pmCmXYAU8AfPTrbxiz2WIfMIqnue
ReqMwa0gY/ArI5OpbiMANaykILstfqNmgs8Mg1TceMDhOfsxu74u00D2ASPxJOgg
U8RUb6HGRxljFCabIjo+DPVF5Rzbw65MEwJ7SquVkRExS86uGpRWnQIDAQABo3Ew
bzAdBgNVHQ4EFgQUEvzxrBCmQLIOiEcPttJ4jSu50iYwTgYDVR0RBEcwRYIVRFRF
RFVJRDAxLm5wdWR0LmxvY2FshixodHRwczovL0RURURVSUQwMS5ucHVkdC5sb2Nh
bC9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAYEADUTgDi06TPY3kxT5
/E8YAzRGd/2FZpKN5RAglOWUsSUxdM8bWjzRr3U5oU5vMi6OyRlmCejNQolrn8Tz
4puLNR3/pbLYRN6QDNzccU5hT6xUa1fqYUpoEWqkMqU6NyvkUV85AH+T0jT8SyMj
gbKrox9J6N28ELCZx4qmG3flJZ3/It1HwiLU8Z5Ku0Tj46SdrKrd7u9tCRXA2kx2
PnKnCbFn/mexLmJsbX+RPv5+VZRDnbbc4q4JHSzuPjvdUUpJLDY3LrhvCfZOlMgV
LoKi+jJ5fkmnU0AXk3AUpZAdHYUbOVJiC1oAdRjWhi2x3kcwo8q8SZVH0x4lFqbs
if96EyrOtSnE1vtEpPd5w0YrIm1FXPsrJly1pLCiNxj3dLdLGhpfGihZn8+C/OIh
dWEupDyGw6Vitr8FJGm3/6E1N85UcoxNL3FGGsHKyHVBC3rgW7Rjmhj1R2Eg6qMm
voVV6Kpfz6C9rCZwzjtaA+BBeD0YSFgSgpu/6DHXJonKa5Sc
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEPzCCAqegAwIBAgIUNbqwFgFDI5AppBQ23MuwQaZ+ftIwDQYJKoZIhvcNAQEL
BQAwIDEeMBwGA1UEAwwVRFRFRFVJRDAxLm5wdWR0LmxvY2FsMB4XDTIxMDExOTE5
MDkzMFoXDTQxMDExOTE5MDkzMFowIDEeMBwGA1UEAwwVRFRFRFVJRDAxLm5wdWR0
LmxvY2FsMIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEAg0uEwnz4vJD0
Yrp1oH+Ljd1a21Q18gwtpGLbzj9yXg/iswW9Qyv3jCnJUxhq/L/XONrs2d5g19zW
bUQbn3Dg21kwFbiLH4vlF+tC/C0msnS1dgRKpwbaa/F+fJmbvMIu8xeg3x016emT
dCKxXt8FhuX2UJ+j6xRb5X/7NCz6f7z9Ex/WeRHMSH6fCMFKWBNZx0mFgyCiICmF
/kLlnPzWQgffb6O+6s1YvUuz9r9REmNayvwuKVo59LAwtK/rLeqyZU8ZZaeC2xLO
neakkRiZdeptYzNPpUjLKcvxmbhe8KzuDiPqyT7PZvmTYeTCd4TBHdyXwxXWF7fg
13hqi4ekjCAFlQxyCpujLTfKSa/l9X4s3jFCPcSV2v2VBSgJNEm4WPEVkzDbvEYq
Ak3/fNTb+H4H/D0S6DltrDq4NjDNrOWtfUBM9Diw8sqviuWjssWLCiCmE4PsdDtZ
p7k98BHKIouALosi+SaMv7kzl57mXpHF/buCNk+JJNxu7LRHPRrjAgMBAAGjcTBv
MB0GA1UdDgQWBBSAASX82HyQmxAab36SucRWxclZyDBOBgNVHREERzBFghVEVEVE
VUlEMDEubnB1ZHQubG9jYWyGLGh0dHBzOi8vRFRFRFVJRDAxLm5wdWR0LmxvY2Fs
L2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBgQBqrFJg6rRmwq9wH9RK
PEtOmMe9MKYc58NwATC6UQQfSKe/qw39kGfooQsxDe+VsyeS7GEVpB5+LOasgCSD
je2fTuVy9n84d8dWB+RBwBn+qe8TVMRs4xvN71sHa3gto2SMMa/nR6+ngB+a1QZ3
aiPWcgRzOCK/x30H8lOpVW/yNfbBrYhDq0QMzZyFjCFk62GG6Kxxyq7/asweqaka
EOYXAHQ4ft8qDo65H5qu6eCyo6q6NKg+XgDZfYbLSdWaWHo6AO+S0LuCAARkgjlg
OlH66vt9Tc+RnE0aI8tA7cKIA7jbtdFpnEhvTj2TwgUwzZV6Mk5KKGdI2F48tZ8y
goIDibgNGOem1sox2uKBRuAKjTwEu9kBmBytDo+B99AYFZZktcJMcc7mPYp2EqGi
+EhcY8fNy7JH5QKq/uOWvFNd/Gu5aQNUlWo8wyTzj8o5G/A6jiygKfQ6dr28cHtA
wYjWCrbCbOnu5aXqxBTNgpZEzhQQOU0Fr8xyrHcDFQsOHhY=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.npu.cz:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
        <!-- <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.npu.cz:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> -->
        <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->

    </AttributeAuthorityDescriptor>

    <Organization>
        <OrganizationName xml:lang="en">The National Heritage Institute</OrganizationName>
        <OrganizationName xml:lang="cs">Národní památkový ústav</OrganizationName>
        <OrganizationDisplayName xml:lang="en">The National Heritage Institute</OrganizationDisplayName>
        <OrganizationDisplayName xml:lang="cs">Národní památkový ústav</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">https://www.npu.cz/en</OrganizationURL>
        <OrganizationURL xml:lang="cs">https://www.npu.cz/cs</OrganizationURL>
    </Organization>

    <ContactPerson contactType="administrative">
        <Company>The National Heritage Institute</Company>
        <GivenName>Petr</GivenName>
        <SurName>Volfík</SurName>
        <EmailAddress>mailto:volfik.petr@npu.cz</EmailAddress>
    </ContactPerson>

    <ContactPerson contactType="technical">
        <Company>The National Heritage Institute</Company>
        <GivenName>Martin</GivenName>
        <SurName>Dohnal</SurName>
        <EmailAddress>mailto:dohnal.martin@npu.cz</EmailAddress>
    </ContactPerson>

</EntityDescriptor>
