<?xml version="1.0" encoding="UTF-8"?>
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" entityID="https://idp.clce.ac.zm/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">clce.ac.zm</shibmd:Scope> 
    
        </Extensions>

        <!-- First signing certificate is BackChannel, the Second is FrontChannel--> 
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEIzCCAougAwIBAgIUcZ46gCHw+4lZPPSNOmdGfSjsScAwDQYJKoZIhvcNAQEL
BQAwGTEXMBUGA1UEAwwOaWRwLmNsY2UuYWMuem0wHhcNMjExMjE5MTgxNDE4WhcN
NDExMjE5MTgxNDE4WjAZMRcwFQYDVQQDDA5pZHAuY2xjZS5hYy56bTCCAaIwDQYJ
KoZIhvcNAQEBBQADggGPADCCAYoCggGBAKMal73zp57eA5ipxhXdJCYvWg3OXBEo
fGSeEO4ppjbX7NzozcJolXy1YEiX6u1dbmjHQ3At2hUj3sKpFmXktxBoxsxDAra0
wwaMF7bm5YWGJ6yqk951cef56PaRlsh76Kqw7L7YeB44o37ReOvvrgmVVzddWYas
IaoRFi2FTCvevnBKTG5gvFLfFZEv3zlqEtqiUw7MedY99hfx6OaJGy4AGlMCdXtM
o6mzz16RJVkuq9rdaCxSRS9JTQiJKc7c9WsjgNKd0I9kD6eviIRZm92PcjK8Xxg5
icx9yz/LkuwHNWzm3Pw7kGKoD7dqCHV69OUggcexCb/64VoC3P3u8zuft2HpNl4N
VTqq7zMkJDKHGl1z6mw/pxq/3jGGZKcTm1/OEPk4LHmifaK2lN+Xfp3+xbRE2J5r
GLdeSl/NNSI/aNr4o4SWX/XrjXFMjWge+6w59uaWoLMZDNasQWYd1wQNVY36f3o1
d1uu6lTJTQwCXxvvaemJTUEJh5ApEgTWcwIDAQABo2MwYTAdBgNVHQ4EFgQUJmI7
mi/t2Bm8ODIh6mVIlYsWPdUwQAYDVR0RBDkwN4IOaWRwLmNsY2UuYWMuem2GJWh0
dHBzOi8vaWRwLmNsY2UuYWMuem0vaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQEL
BQADggGBAD/fYdo0lNGKVmfycW6dDK7YdoQjZgbO04Jkq33rqSDk2E1UEOfUs7PU
QWPbRO4T6dvSCZ/EFASW6pVNLl7PBcZE5m6rOpEcdap7K4ORTPcAGAhAwuHD9Zox
sl/FhtKAI66rR3FoCCH2fjsWhtZsF/4TX0g9EZctrZHD1cTgkEDzyczE/YF3QZl5
pn1K1JvyIT/l5soDNwYwZ2f3ph26uyR8XB7hC1375Zplq3rg0v9BGilHrrwrBmwS
UmsPVeRQszXPYlLwJj6U+u+ZW8mT4VvbIm2Pt1pOwh4bWd56VLZkhEUhkhelxvCv
CQSneGHAGPwftcI+JBXDkWL+J2p4sPIvzyeMP3D108lJ8Q4KLajPkQEDH4OaPniC
rr+4MH1IB4lDy6Ze1MHntqgyh5jMWI9qP3Vdrxf/2oDEG/AVROMuF8TfhZ4OoUU4
3Z0iF5z+UdzDayf8vLlRg7vwGNK7uTChMRXSrTzUQkZxtHNMMUxW153/7al2MhA1
uD1hC99PNQ==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEIzCCAougAwIBAgIUPSbOuLo9ceydJ2ZqKz6BBoRWrDowDQYJKoZIhvcNAQEL
BQAwGTEXMBUGA1UEAwwOaWRwLmNsY2UuYWMuem0wHhcNMjExMjE5MTgxMzU5WhcN
NDExMjE5MTgxMzU5WjAZMRcwFQYDVQQDDA5pZHAuY2xjZS5hYy56bTCCAaIwDQYJ
KoZIhvcNAQEBBQADggGPADCCAYoCggGBAMGmLtbomUp3sLIaKBmUpU3yaoOrBApK
sSjvZxoHe0vm1WhVi8nAM0vyg23xM59bH2WZMiD3q7lzQ0khoczyWiYq/1fNsojs
BT24gor9EpjWAHxNK0euuqaTEQL6Rw+AXklGUILG/FGeKwXefYNMaIvGR7D5ZEZ/
/8i3gwy+OKw3pyLDSfiYtMAlZS74tvfIK/I1Vk8q+M3/xkiNDgvX1Niyb7BJ+nNh
zzS4AngTUR9S0KZGs8cMMVJe5jzJ+dFyKjES8G0Dh8PHqOJtP52EfmjPTsmXBeF+
J/KxclywmInI2FCNPizBhWEbwKckmqw7QZlo0zhlcM2igD8kgF0JjbnplRTUWXOD
kFldKc1Fe/bTQv/mrHoqzdG0cv0pRkKg+GTZjN+jIYPvdDwKektDbW3g4u3vxJHs
1nCItJ6mFmKB+hlC51OnAiApjb0qgy4ugOtqCMUH7rAo7Pem/hsahnz9Qfes4uyw
BKer+OeBDN8Sg61ZsMYh1LapFkloVuPvqwIDAQABo2MwYTAdBgNVHQ4EFgQUY6i4
iObX1O2tmxxIMuL8gfR9l4MwQAYDVR0RBDkwN4IOaWRwLmNsY2UuYWMuem2GJWh0
dHBzOi8vaWRwLmNsY2UuYWMuem0vaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQEL
BQADggGBAAsE9bvYj2SBTojvFWditYj/dIJy8zwLbEjzTt2G3xsRqx5hdLHVslWr
dj2ziw43RpCg1kd5NLXTZjXrAd2hp82BJWihCbFXKeF8QTwH8SP86BrBjKDMt/l0
BpS/XqNAFoBS5oVot0lWFSmDJ2A3hxrmlLiT2bYy69msAV/9E2f8cNnOlmAYaZzb
tb4vjyD+a5YQrEduvnOCWsdQzn91OmfHOu2SFDTDgM7bYdljO/a4P2kFDAJLKga/
sAnj5FJuIGHateLekGtyeVRInyTOTO8my956MqXz61xmKHovay/6m6aPX5uc0frs
qwG8S0isKStij4SfMfMn9EPfPUZhu8Em4Py+Dyx31YoMDtM2AIz/kDreaI+/h5Yz
CadRKfSZHumzy5IcfGjPSOhdiHWjoCCs89IB9i+hIJ1AFBZpoG4oY7gcsTljvCf1
bYtxRiW0rZ9p0G3qpxTHJVRwq1yRQvl2sedoWJRqIq5fKOop49GSHmcFZ1lQuTa+
lfaIXkrqDA==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIEJDCCAoygAwIBAgIVAOwWNXTrDh6PE+mEGyY5Drd/7DaTMA0GCSqGSIb3DQEB
CwUAMBkxFzAVBgNVBAMMDmlkcC5jbGNlLmFjLnptMB4XDTIxMTIxOTE4MTQwMFoX
DTQxMTIxOTE4MTQwMFowGTEXMBUGA1UEAwwOaWRwLmNsY2UuYWMuem0wggGiMA0G
CSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQCTuA7EdeBDjoZq2eYVsV2mcMjYm1B4
OMW1Vtez0j5U7/NJdtUfF6BIevok3OVonCAWVKDcRkfEPJdZG/1J4D7t3qulWsml
RRw93C6a+pTpdlLVETaHknkadx8bfL8q3STPGRMTgQEKAN7KLlku6axrHUrVCFgj
vbH2CMTt/gA9zx4Dntl2emMV14McD1FEaEoriS3wgjMrayU2j3STP57O6CQ2Odbh
j1xwT99HALW9yeYnYmwkKGv45bdaUH11baQSG3mqtqvQ6K1F2qE62j8lfpYK70Ue
3eCK95cG9wjMu0MX94C0LPhnfpYBqhHktpSbpPIuKNmDilmBRT3l+/cVW48Kz+R8
HVABPguZNLV0chnuKvVBEpllA7vdebinwLRcdjQahqimxMkr2iYD6pQWYwPMwr8q
wpxrO0Dic1URDgpg4OjZyWX0XMv4R6kZkYG3sucSvpRpDOA0NwvhbjtfbGhgCqYe
cnZeY0SbACU1DyOvrrLPSoib5X9qOGwXpekCAwEAAaNjMGEwHQYDVR0OBBYEFJcR
E2lKDiGB93odBKDIWEGBIAmnMEAGA1UdEQQ5MDeCDmlkcC5jbGNlLmFjLnpthiVo
dHRwczovL2lkcC5jbGNlLmFjLnptL2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEB
CwUAA4IBgQAgcYZivDpY/s4xbjYszXsLwLw4ON/32kHHutfN3Q714lRCMmGQa9a7
yE6IH5n8Di5iykaWWlHm61IA6Be/P5Yky3ZlKAHlUTa/sle95QAs53ZNurx1Squ8
cK29/90sMZQzPtZwKTll9lrrUlRY4tsNcnqyxD7XXVJziUPE7o7YLB+LG6y1sRf6
FESuwnEufLFLOBjL5Nf82T73X26vNGPNmjvar1vNdx2C0ebOzX22gkPBdjzd9lS9
afknLPJrYzzJ9WFvOmRKVfzC21pRLXmMbKUFkMXDTT5FUQylXdNm2qxYbcXhjZzy
adjfIv0gU5H+PfG3W7WTenuNDbFCPdKCt4tBBPwqEB2Ji86hbxwSPN4OoQvkZLW+
TXJnVYZrSSeIQ2KkUJ3vnm3NPZLghxE3AOAEMkRuFUnNSkDubr4ohsNmI7k5y3VC
EUfXE4kV9yZWCzvPcGlXCkzTLJ/+UMMhONFtiSTHWGT7t4kUJRXDsNOcvFjolXDk
Ho0dpr3UdfY=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.clce.ac.zm/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>
        

        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.clce.ac.zm/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.clce.ac.zm/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.clce.ac.zm/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.clce.ac.zm/idp/profile/SAML2/SOAP/SLO"/> 

	<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
	<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>

        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://idp.clce.ac.zm/idp/profile/SAML2/Redirect/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" req-attr:supportsRequestedAttributes="true" Location="https://idp.clce.ac.zm/idp/profile/SAML2/POST-SimpleSign/SSO"/>
         <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://idp.clce.ac.zm/idp/profile/SAML2/POST/SSO"/>

    </IDPSSODescriptor>

</EntityDescriptor>
