<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" entityID="https://idp-cro.slu.cz/idp/shibboleth">

  <Extensions xmlns="urn:oasis:names:tc:SAML:2.0:metadata">
        <eduidmd:RepublishRequest xmlns:eduidmd="http://eduid.cz/schema/metadata/1.0">
             <eduidmd:RepublishTarget>http://edugain.org/</eduidmd:RepublishTarget>
        </eduidmd:RepublishRequest>
  </Extensions>

   <!-- zakázání SAML 1.1 20250325
    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
    -->
    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">slu.cz</shibmd:Scope>
              <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">Silesian University in Opava</mdui:DisplayName>
                <mdui:DisplayName xml:lang="cs">Slezská univerzita v Opavě</mdui:DisplayName>
                <mdui:Description xml:lang="en">Identity Provider for employees and students of the Silesian University in Opava</mdui:Description>
                <mdui:Description xml:lang="cs">Identity Provider pro zaměstnance a studenty Slezské univerzity v Opavě</mdui:Description>
                <mdui:InformationURL xml:lang="en">http://www.slu.cz/slu/en</mdui:InformationURL>
                <mdui:InformationURL xml:lang="cs">http://www.slu.cz/slu/cz/</mdui:InformationURL>
                <!-- <mdui:Logo height="100" width="100">https://uit.opf.slu.cz/_media/slu-znacka-hlavni.png</mdui:Logo>-->
                <mdui:Logo height="200" width="200">https://uit.opf.slu.cz/_media/slu-znacka-hlavni-200.png</mdui:Logo>
                <mdui:Logo height="400" width="400">https://uit.opf.slu.cz/_media/slu-znacka-hlavni-400.png</mdui:Logo>
              </mdui:UIInfo>

        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDFDCCAfygAwIBAgIVAL3gk4kllTneZBd1cQdt7j2XjlTWMA0GCSqGSIb3DQEB
CwUAMBUxEzARBgNVBAMMCmlkcC5zbHUuY3owHhcNMTcwOTE0MDY1NTAzWhcNMzcw
OTE0MDY1NTAzWjAVMRMwEQYDVQQDDAppZHAuc2x1LmN6MIIBIjANBgkqhkiG9w0B
AQEFAAOCAQ8AMIIBCgKCAQEAsS/yqJzS4leiBwOrIl4Q2eL7jmTD7X70ocpJ04OY
EP7b5vXJtOkWgNx8Qgblq5qXYtm7eBlGLqz3Be3R9PL1IoAlNMdmvyvbr4ig5OTA
SagNJOUy+gYpEfFYTD5JiQycjlfpx1fqRK/H9lQx1xdq88XPIVhdyKzArqaJu6e3
XCsq726AvvhWk2yU3Q5lycQy2wQVFDE/eVHcKa3XyHe5//pBUoJB6nSro/6YyvTc
2IEtD0zBEJiTp5h+o4RcFsBsvtf/EYXO++tRQjxX28n0DuYV/PC5TeL9mh1MXylg
t6M8G0CedYH47PGeP0Vxr4/m5itpKmasnBWIRLQzqToa5QIDAQABo1swWTAdBgNV
HQ4EFgQUDjfws6M/dtlMxHIoCECZenSY03YwOAYDVR0RBDEwL4IKaWRwLnNsdS5j
eoYhaHR0cHM6Ly9pZHAuc2x1LmN6L2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEB
CwUAA4IBAQAMFpwfIDrAkpg4yW5HgOdtaj9ErHwxGc/n5PaLlfehUEcvaMn3KXWN
L+wmi5cla9usMTdo1U0fAwaHAutIr2OHj64MPih4KHvUnQtGo2QyRIM7k6vXGMtt
9lJyQbqinWvr9p2FLYQGLcchgx785rQ3IQAh5Fr2P1omXiGkx4ZkgihpoWTZ+iyf
B82omo3lqFNrlAhbykDAXIfk5F2NfsEJUCOIItwkoTogcJavE2PpauZzNjDPaaJL
e+PuGJB6sExlLVlYJAMUpd0pxRdWkW0hipsI9ACaxQLly6YYxoIpeLCOkmaSwxR5
xRESqgro3MgLDhzQESgQQ0a2twd2rutJ
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDEzCCAfugAwIBAgIUSJLyuUvpTxU+Vblhr3WRfkE/Fk0wDQYJKoZIhvcNAQEL
BQAwFTETMBEGA1UEAwwKaWRwLnNsdS5jejAeFw0xNzA5MTQwNjU1MDJaFw0zNzA5
MTQwNjU1MDJaMBUxEzARBgNVBAMMCmlkcC5zbHUuY3owggEiMA0GCSqGSIb3DQEB
AQUAA4IBDwAwggEKAoIBAQCpWnFy91UEu8SGMu3VwdG9pgQunF9HP3c/MWADJ9ln
f5amPeh1hRhJoi7mqOsDL/HAb4W1Vsz6XIUbRowRggX9MHEEpTk1ciQ8JrkIW9ZE
x8p70cO/DrZac/A01rosBLvEXQyuRWMIqo0NhsFD+JkvS/oR/Km0R9D/JtTAJyg1
A0swMUH8pAvs6kUr37I8utnnUZrA9g0ncCdXk+ONNbm1COMbGJGao/sGC68t/IsH
rnT2aJpK0G1WjtUK1Jyie6boeRmxoYCv57gHxrQ8xymmlg2qWzZxXZbsU0tO/Sh8
fOkCvVScbVfMb9ToVy6kSmINjBtXw8800e2bhMudxjg5AgMBAAGjWzBZMB0GA1Ud
DgQWBBSfhRIKbB+Ypx88Y+wvQgQQ+Kv8azA4BgNVHREEMTAvggppZHAuc2x1LmN6
hiFodHRwczovL2lkcC5zbHUuY3ovaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQEL
BQADggEBAJ0B+DYofui6aYq2aLuGG9KrraGc56OeH93VnWqRB3kWiSkIObYCA1C3
QkoLQEWPpqfYodLstUBlggCa/Kxoxe8h+S1H/t4aqzFJxiECUP98px9YOrl5uhJB
JToPCQKxwzqD/7ymS5nPRiH9Kx9w3dGwah3UUVyXsQKfVHwkZ3rCr0oXDaplK2rS
u3QphVplXRSxZpLY/FR1CBx9clL8tUIPwq3TwvEICrMq9OwSDSjFlSPnWV71AR3e
teGPEzBdZg7ALFTxZQHYehOz+kJ5UIev9mJrUm9pHUZNKASI8TjN6jItPaL135Rf
qtwdm8DlFnyRZJ3nqy2PlgzN508yEvk=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDEzCCAfugAwIBAgIUNkBRBa5hNN9y0tGmIcjnJM+zwGYwDQYJKoZIhvcNAQEL
BQAwFTETMBEGA1UEAwwKaWRwLnNsdS5jejAeFw0xNzA5MTQwNjU1MDJaFw0zNzA5
MTQwNjU1MDJaMBUxEzARBgNVBAMMCmlkcC5zbHUuY3owggEiMA0GCSqGSIb3DQEB
AQUAA4IBDwAwggEKAoIBAQCH3HZR+/s1MtztRDBvDV3NKNtPBoOzl1/N7i8kKOJz
IS/iz8j2MoEeg/hPiHnR1wiT2awvX6NjGXiftm45yL4dvINaOsutJd50kF3ORvoA
EzdNYxN57A2xXOqeJ/NF9V/LmJycSwaH5Uov82GBcUyyJp7pyALnURiVtnrr7KSA
A3vYhCS1HZEB+hENLcAIjENx6NvT+lHq4uB3xMXpATzQzqPSkVmR3go6ttWwcAlt
/hvv55xeEvHY87dzSB7yIyBc+sFKfUDKDZMZ+X+N02JRQn7YcZ9PHEkvhry4xXIc
3s+fEtLa+PcpmMPAvrfDNVwogYdWUpFENk8DA/McyIENAgMBAAGjWzBZMB0GA1Ud
DgQWBBRnrwihdgBjVHIfk4DqJBgYzleJHDA4BgNVHREEMTAvggppZHAuc2x1LmN6
hiFodHRwczovL2lkcC5zbHUuY3ovaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQEL
BQADggEBACX0aNF289pgx5yzRMoQ8+gnStiv+DaZXK5MSld9ueCT4GXRQoYaIBur
p5nHnnSqE8mV9Px2Y2WWriROl+Ez23GMsdKe5hJ4hnGKXgTXOfBsg1saNiy7hwlc
53Q77UG/c2lX+HJre1Fe6EtkKsYValz8FBd8Ol4ZRfqqFPDz7LE6s/iOsU4l6NmQ
ZHmIUo1tMkq8tI2+YbFOQvt1NaQC9AebMkSpCCDxbd2oE6BPKgusAG5txaduRsYd
q2orTQn5Ui96royjiZ1ea31UvjtVyvEC/cTgn/m3SXKAhb6PVDshZJw/N10Jgyf/
cLDQpWR2pyhtxC/jL0f5CuQPpvI9Tzw=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <!-- zakázání SAML 1.1 20250325
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp-cro.slu.cz:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
        -->
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp-cro.slu.cz:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>

        <!--
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp-cro.slu.cz/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp-cro.slu.cz/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp-cro.slu.cz/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp-cro.slu.cz:8443/idp/profile/SAML2/SOAP/SLO"/>
        -->

	<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
	<NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</NameIDFormat>
	<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
	<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>

	<!-- zakázání SAML 1.1 20250325
        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp-cro.slu.cz/idp/profile/Shibboleth/SSO"/>
        -->
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp-cro.slu.cz/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp-cro.slu.cz/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp-cro.slu.cz/idp/profile/SAML2/Redirect/SSO"/>

    </IDPSSODescriptor>


<!-- zakázání SAML 1.1 20250325
    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">slu.cz</shibmd:Scope>
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDFDCCAfygAwIBAgIVAL3gk4kllTneZBd1cQdt7j2XjlTWMA0GCSqGSIb3DQEB
CwUAMBUxEzARBgNVBAMMCmlkcC5zbHUuY3owHhcNMTcwOTE0MDY1NTAzWhcNMzcw
OTE0MDY1NTAzWjAVMRMwEQYDVQQDDAppZHAuc2x1LmN6MIIBIjANBgkqhkiG9w0B
AQEFAAOCAQ8AMIIBCgKCAQEAsS/yqJzS4leiBwOrIl4Q2eL7jmTD7X70ocpJ04OY
EP7b5vXJtOkWgNx8Qgblq5qXYtm7eBlGLqz3Be3R9PL1IoAlNMdmvyvbr4ig5OTA
SagNJOUy+gYpEfFYTD5JiQycjlfpx1fqRK/H9lQx1xdq88XPIVhdyKzArqaJu6e3
XCsq726AvvhWk2yU3Q5lycQy2wQVFDE/eVHcKa3XyHe5//pBUoJB6nSro/6YyvTc
2IEtD0zBEJiTp5h+o4RcFsBsvtf/EYXO++tRQjxX28n0DuYV/PC5TeL9mh1MXylg
t6M8G0CedYH47PGeP0Vxr4/m5itpKmasnBWIRLQzqToa5QIDAQABo1swWTAdBgNV
HQ4EFgQUDjfws6M/dtlMxHIoCECZenSY03YwOAYDVR0RBDEwL4IKaWRwLnNsdS5j
eoYhaHR0cHM6Ly9pZHAuc2x1LmN6L2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEB
CwUAA4IBAQAMFpwfIDrAkpg4yW5HgOdtaj9ErHwxGc/n5PaLlfehUEcvaMn3KXWN
L+wmi5cla9usMTdo1U0fAwaHAutIr2OHj64MPih4KHvUnQtGo2QyRIM7k6vXGMtt
9lJyQbqinWvr9p2FLYQGLcchgx785rQ3IQAh5Fr2P1omXiGkx4ZkgihpoWTZ+iyf
B82omo3lqFNrlAhbykDAXIfk5F2NfsEJUCOIItwkoTogcJavE2PpauZzNjDPaaJL
e+PuGJB6sExlLVlYJAMUpd0pxRdWkW0hipsI9ACaxQLly6YYxoIpeLCOkmaSwxR5
xRESqgro3MgLDhzQESgQQ0a2twd2rutJ
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDEzCCAfugAwIBAgIUSJLyuUvpTxU+Vblhr3WRfkE/Fk0wDQYJKoZIhvcNAQEL
BQAwFTETMBEGA1UEAwwKaWRwLnNsdS5jejAeFw0xNzA5MTQwNjU1MDJaFw0zNzA5
MTQwNjU1MDJaMBUxEzARBgNVBAMMCmlkcC5zbHUuY3owggEiMA0GCSqGSIb3DQEB
AQUAA4IBDwAwggEKAoIBAQCpWnFy91UEu8SGMu3VwdG9pgQunF9HP3c/MWADJ9ln
f5amPeh1hRhJoi7mqOsDL/HAb4W1Vsz6XIUbRowRggX9MHEEpTk1ciQ8JrkIW9ZE
x8p70cO/DrZac/A01rosBLvEXQyuRWMIqo0NhsFD+JkvS/oR/Km0R9D/JtTAJyg1
A0swMUH8pAvs6kUr37I8utnnUZrA9g0ncCdXk+ONNbm1COMbGJGao/sGC68t/IsH
rnT2aJpK0G1WjtUK1Jyie6boeRmxoYCv57gHxrQ8xymmlg2qWzZxXZbsU0tO/Sh8
fOkCvVScbVfMb9ToVy6kSmINjBtXw8800e2bhMudxjg5AgMBAAGjWzBZMB0GA1Ud
DgQWBBSfhRIKbB+Ypx88Y+wvQgQQ+Kv8azA4BgNVHREEMTAvggppZHAuc2x1LmN6
hiFodHRwczovL2lkcC5zbHUuY3ovaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQEL
BQADggEBAJ0B+DYofui6aYq2aLuGG9KrraGc56OeH93VnWqRB3kWiSkIObYCA1C3
QkoLQEWPpqfYodLstUBlggCa/Kxoxe8h+S1H/t4aqzFJxiECUP98px9YOrl5uhJB
JToPCQKxwzqD/7ymS5nPRiH9Kx9w3dGwah3UUVyXsQKfVHwkZ3rCr0oXDaplK2rS
u3QphVplXRSxZpLY/FR1CBx9clL8tUIPwq3TwvEICrMq9OwSDSjFlSPnWV71AR3e
teGPEzBdZg7ALFTxZQHYehOz+kJ5UIev9mJrUm9pHUZNKASI8TjN6jItPaL135Rf
qtwdm8DlFnyRZJ3nqy2PlgzN508yEvk=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDEzCCAfugAwIBAgIUNkBRBa5hNN9y0tGmIcjnJM+zwGYwDQYJKoZIhvcNAQEL
BQAwFTETMBEGA1UEAwwKaWRwLnNsdS5jejAeFw0xNzA5MTQwNjU1MDJaFw0zNzA5
MTQwNjU1MDJaMBUxEzARBgNVBAMMCmlkcC5zbHUuY3owggEiMA0GCSqGSIb3DQEB
AQUAA4IBDwAwggEKAoIBAQCH3HZR+/s1MtztRDBvDV3NKNtPBoOzl1/N7i8kKOJz
IS/iz8j2MoEeg/hPiHnR1wiT2awvX6NjGXiftm45yL4dvINaOsutJd50kF3ORvoA
EzdNYxN57A2xXOqeJ/NF9V/LmJycSwaH5Uov82GBcUyyJp7pyALnURiVtnrr7KSA
A3vYhCS1HZEB+hENLcAIjENx6NvT+lHq4uB3xMXpATzQzqPSkVmR3go6ttWwcAlt
/hvv55xeEvHY87dzSB7yIyBc+sFKfUDKDZMZ+X+N02JRQn7YcZ9PHEkvhry4xXIc
3s+fEtLa+PcpmMPAvrfDNVwogYdWUpFENk8DA/McyIENAgMBAAGjWzBZMB0GA1Ud
DgQWBBRnrwihdgBjVHIfk4DqJBgYzleJHDA4BgNVHREEMTAvggppZHAuc2x1LmN6
hiFodHRwczovL2lkcC5zbHUuY3ovaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQEL
BQADggEBACX0aNF289pgx5yzRMoQ8+gnStiv+DaZXK5MSld9ueCT4GXRQoYaIBur
p5nHnnSqE8mV9Px2Y2WWriROl+Ez23GMsdKe5hJ4hnGKXgTXOfBsg1saNiy7hwlc
53Q77UG/c2lX+HJre1Fe6EtkKsYValz8FBd8Ol4ZRfqqFPDz7LE6s/iOsU4l6NmQ
ZHmIUo1tMkq8tI2+YbFOQvt1NaQC9AebMkSpCCDxbd2oE6BPKgusAG5txaduRsYd
q2orTQn5Ui96royjiZ1ea31UvjtVyvEC/cTgn/m3SXKAhb6PVDshZJw/N10Jgyf/
cLDQpWR2pyhtxC/jL0f5CuQPpvI9Tzw=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
zakázání SAML 1.1 20250325 -->
<!-- zakázání SAML 1.1 20250325
        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp-cro.slu.cz:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
zakázání SAML 1.1 20250325 -->
        <!-- <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp-cro.slu.cz:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> -->
        <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->
<!-- zakázání SAML 1.1 20250325
    </AttributeAuthorityDescriptor>
zakázání SAML 1.1 20250325 -->    
   
    
  <Organization>
    <OrganizationName xml:lang="en">Silesian University in Opava</OrganizationName>
    <OrganizationName xml:lang="cs">Slezská univerzita v Opavě</OrganizationName>
    <OrganizationDisplayName xml:lang="en">Silesian University in Opava</OrganizationDisplayName>
    <OrganizationDisplayName xml:lang="cs">Slezská univerzita v Opavě</OrganizationDisplayName>
    <OrganizationURL xml:lang="en">http://www.slu.cz/slu/en</OrganizationURL>
    <OrganizationURL xml:lang="cs">http://www.slu.cz/</OrganizationURL>
  </Organization>

  <ContactPerson contactType="technical">
    <GivenName>Jakub</GivenName>
    <SurName>Jezisek</SurName>
    <EmailAddress>mailto:jezisek@opf.slu.cz</EmailAddress>
  </ContactPerson>


</EntityDescriptor>
