<?xml version="1.0" encoding="UTF-8"?>
<!--
     This is example metadata only. Do *NOT* supply it as is without review,
     and do *NOT* provide it in real time to your partners.

     This metadata is not dynamic - it will not change as your configuration changes.
-->
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" 
	entityID="https://idp.diak.fi/idp/shibboleth">

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">

        <Extensions>
            <shibmd:Scope regexp="false">diak.fi</shibmd:Scope>
<!--
    Fill in the details for your IdP here 

            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">A Name for the IdP at login.diak.fi</mdui:DisplayName>
                <mdui:Description xml:lang="en">Enter a description of your IdP at login.diak.fi</mdui:Description>
                <mdui:Logo height="80" width="80">https://login.diak.fi/Path/To/Logo.png</mdui:Logo>
            </mdui:UIInfo>
-->
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDHzCCAgegAwIBAgIUIRDbEBpRH76m4PpG/auEWQkij98wDQYJKoZIhvcNAQEL
BQAwGDEWMBQGA1UEAwwNbG9naW4uZGlhay5maTAeFw0xODAxMjYxMzA2NTVaFw0z
ODAxMjYxMzA2NTVaMBgxFjAUBgNVBAMMDWxvZ2luLmRpYWsuZmkwggEiMA0GCSqG
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQCqHVCHByKB9o4A1xIim92v3qNS+TubPzbq
+v7ig6FDIWj5IrwL9wciVZXDRi0+5Fv2U+Es7RlT8jVAjEmTfCmMLn+iOJdCqqJA
KDlGhAA6X5miTOcW2ZpFREbuMiH1ng//+qc+MYleysz8BWTq6do8D48v3rCigxGE
50LA2lRmdhPKtFM7/zK+pYsJEw//fEDgaIOvzsuB1wDKhPuqU4RZMSLiRnBpnNC1
GThU1ZrjNY4OpykVkWKXNG5P8Vycj1yypYhBbNcmPkEpqQ7KOBMlerE98qfBjW14
CM5qlVLIUNX1VEoM560apbzJiY6gADJfaePy/lhXjjABLNyaCwQjAgMBAAGjYTBf
MB0GA1UdDgQWBBRI8jdBOb1VQGYxuBFmJYOwlrgUQTA+BgNVHREENzA1gg1sb2dp
bi5kaWFrLmZphiRodHRwczovL2xvZ2luLmRpYWsuZmkvaWRwL3NoaWJib2xldGgw
DQYJKoZIhvcNAQELBQADggEBAFytaPXBqp+G8IfIxNgOrX+CTdavdUYy3lFHl+Cq
dH5+l1fZegawt/NfYFlImbQIenS1QBY54RYTYno0xnOqzY0jwBuZvOgktf0K9Ket
a2kQqF/gJFRTevqVTarSfVL7ooDU81P9N5q1wyqsOqkK/RCLkT43fwj7YEwn4kWg
d8TqaRUFJjEJQd9g95tt+VVR/j5W3nLPHD1iMO4dd1slsLxDvzLQecLWjr+KXCBi
8K7nwqEr7MWEGLoiUu+x+g3PClbmeSSrMw9BkMXmNzDvXKnJN0uvzFt1JQBZLEbg
5nOmhlo+7m8RKNqsL2XNqd7HMb7ON333EAoxeMRFcQKtut8=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDIDCCAgigAwIBAgIVAM2u0euQpVUXCy2RK6zv/W/ZKbiPMA0GCSqGSIb3DQEB
CwUAMBgxFjAUBgNVBAMMDWxvZ2luLmRpYWsuZmkwHhcNMTgwMTI2MTMwNjU0WhcN
MzgwMTI2MTMwNjU0WjAYMRYwFAYDVQQDDA1sb2dpbi5kaWFrLmZpMIIBIjANBgkq
hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAm3ksGzKt9l6d/3XBEzxtC8LIMaHBkBPS
ODz+7N91FEqNmhWXWb+4QLCMDUG3Lv1bMDnKGlTOAHnyXNijkvHGmenLRGNrUzS2
6oe0pPy0tcJ8aeL+xYXxnDo/Uw85PDRNZ8yttpnHMthCdjevI1BwPlBDTn7tulv7
VEUHqiP1SNhv6VTOU6TOZcaKqB3Fjtvw9FtL12ZbJ+ZCaOsMMQYKukyyzxH6Dz0P
DMHImWB8zqPd8rqWhzSEg8mpPbe9CIcPLOc/GjZJrTQ/RsjFqsCXKK8G5PO4Irfk
/ZbnVQLY1rrOKz0PNcTkcyGQrv+LPvEhwpAT7A5e5wOT79m02JD80wIDAQABo2Ew
XzAdBgNVHQ4EFgQUgeN3QPpaosBM0vKod7+3DCBY7l4wPgYDVR0RBDcwNYINbG9n
aW4uZGlhay5maYYkaHR0cHM6Ly9sb2dpbi5kaWFrLmZpL2lkcC9zaGliYm9sZXRo
MA0GCSqGSIb3DQEBCwUAA4IBAQBduZpR5z/unH7DRJd+Igf0K1/3k3I+opZzyO6N
nC6P14eMsa889e+Dbz565zZqseceo7p9pC2NLjyttskxGWC34YE069QfrTl2z8ez
oJdlflgFvb1mKNAEcYl48byfy8BP8e9E+bS//xlBvQovdgAeiSCq+6y/xSYb4OVU
5kmdWMr1c9qc209RrY2tsU623fywe0AWkPSSh9jzRbUxVB2bblHQGyX34IoPskar
CpSkToBF+5sxc0+DTE4SMRKLFVOMuRUgyd69RHunpmjo55xDRyEy9wcIby/B0N40
0dxy+Pd1MZ1wbfQNdM78PZNxa1EZcfvtKcL9n7H1IXYo+/l6
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDHzCCAgegAwIBAgIUFEG1Az3J5bg83VBhw4UNqRVuSucwDQYJKoZIhvcNAQEL
BQAwGDEWMBQGA1UEAwwNbG9naW4uZGlhay5maTAeFw0xODAxMjYxMzA2NTVaFw0z
ODAxMjYxMzA2NTVaMBgxFjAUBgNVBAMMDWxvZ2luLmRpYWsuZmkwggEiMA0GCSqG
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQCBZTp7V9SlHHRYyFh8vU8iKpWLo1dkcB2c
m2qUjUnnxG0+Ifro6UziWnOU4hWG3sVioPDHeD1Zvd2l8nfrL5GD3bSUe64aBPNT
tHHA2EHMdaxuD6iZ2xJK82+34e9ZZnAPJK5bQRFE6tGqKjq1pUUvqIJdP7IDKd8t
O/Em2nB79+oew1jCxprgv2grutSn4ylqqNs9Cpbw3yjHi5zpDZkf66OgkPdHqZfu
f8CaaEva9owu/fvIR6oRNMluklOIaUHpd+OZZYcuHzUQnztcsLqr8insJ4GLyv92
3L/ciPL32TAxZCiETeIeuuUlY2vGm+WDkRAiWb+r7uJi4DcS+InPAgMBAAGjYTBf
MB0GA1UdDgQWBBRT5F6MRCHIMgNmoI4o2zWmoj2pSzA+BgNVHREENzA1gg1sb2dp
bi5kaWFrLmZphiRodHRwczovL2xvZ2luLmRpYWsuZmkvaWRwL3NoaWJib2xldGgw
DQYJKoZIhvcNAQELBQADggEBADV8pM2vFjWWOvxh+cBdnwSfb/CN9nk7H9XWqdFC
TFJ5xNkw3/Z7N2ShHwDlRgZ5vVBRDqh6s3UPl0Sok8oBoT+U6ebUKDOWupdMFXsg
ZtsxVWN+uS8FPn4HayrGtkgGHqv4F/drW2aGdwMAQqgOI5P92rJ6vYnGQS5s+P7/
/2MD8WhZObmuHtoVVnQUvgWfYiG+4d/qJ9cKLeumPymeaFbLc4mTLyXjin//6Cu3
cDSqeKZ0wtYJndmvQSZDT79QqzcWMT9zxTLe0uhBab3Jtin3mA3nKe+gW1LQUDQ/
N3fVUpsf16XfhjtBR5kVL2KvM7x3dHL+2kv9POWN+p40tRs=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://login.diak.fi:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://login.diak.fi:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>

        <!--
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://login.diak.fi/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://login.diak.fi/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://login.diak.fi/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://login.diak.fi:8443/idp/profile/SAML2/SOAP/SLO"/>
        -->

        <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://login.diak.fi/idp/profile/Shibboleth/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://login.diak.fi/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://login.diak.fi/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://login.diak.fi/idp/profile/SAML2/Redirect/SSO"/>

    </IDPSSODescriptor>


    <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">diak.fi</shibmd:Scope>
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDHzCCAgegAwIBAgIUIRDbEBpRH76m4PpG/auEWQkij98wDQYJKoZIhvcNAQEL
BQAwGDEWMBQGA1UEAwwNbG9naW4uZGlhay5maTAeFw0xODAxMjYxMzA2NTVaFw0z
ODAxMjYxMzA2NTVaMBgxFjAUBgNVBAMMDWxvZ2luLmRpYWsuZmkwggEiMA0GCSqG
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQCqHVCHByKB9o4A1xIim92v3qNS+TubPzbq
+v7ig6FDIWj5IrwL9wciVZXDRi0+5Fv2U+Es7RlT8jVAjEmTfCmMLn+iOJdCqqJA
KDlGhAA6X5miTOcW2ZpFREbuMiH1ng//+qc+MYleysz8BWTq6do8D48v3rCigxGE
50LA2lRmdhPKtFM7/zK+pYsJEw//fEDgaIOvzsuB1wDKhPuqU4RZMSLiRnBpnNC1
GThU1ZrjNY4OpykVkWKXNG5P8Vycj1yypYhBbNcmPkEpqQ7KOBMlerE98qfBjW14
CM5qlVLIUNX1VEoM560apbzJiY6gADJfaePy/lhXjjABLNyaCwQjAgMBAAGjYTBf
MB0GA1UdDgQWBBRI8jdBOb1VQGYxuBFmJYOwlrgUQTA+BgNVHREENzA1gg1sb2dp
bi5kaWFrLmZphiRodHRwczovL2xvZ2luLmRpYWsuZmkvaWRwL3NoaWJib2xldGgw
DQYJKoZIhvcNAQELBQADggEBAFytaPXBqp+G8IfIxNgOrX+CTdavdUYy3lFHl+Cq
dH5+l1fZegawt/NfYFlImbQIenS1QBY54RYTYno0xnOqzY0jwBuZvOgktf0K9Ket
a2kQqF/gJFRTevqVTarSfVL7ooDU81P9N5q1wyqsOqkK/RCLkT43fwj7YEwn4kWg
d8TqaRUFJjEJQd9g95tt+VVR/j5W3nLPHD1iMO4dd1slsLxDvzLQecLWjr+KXCBi
8K7nwqEr7MWEGLoiUu+x+g3PClbmeSSrMw9BkMXmNzDvXKnJN0uvzFt1JQBZLEbg
5nOmhlo+7m8RKNqsL2XNqd7HMb7ON333EAoxeMRFcQKtut8=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDIDCCAgigAwIBAgIVAM2u0euQpVUXCy2RK6zv/W/ZKbiPMA0GCSqGSIb3DQEB
CwUAMBgxFjAUBgNVBAMMDWxvZ2luLmRpYWsuZmkwHhcNMTgwMTI2MTMwNjU0WhcN
MzgwMTI2MTMwNjU0WjAYMRYwFAYDVQQDDA1sb2dpbi5kaWFrLmZpMIIBIjANBgkq
hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAm3ksGzKt9l6d/3XBEzxtC8LIMaHBkBPS
ODz+7N91FEqNmhWXWb+4QLCMDUG3Lv1bMDnKGlTOAHnyXNijkvHGmenLRGNrUzS2
6oe0pPy0tcJ8aeL+xYXxnDo/Uw85PDRNZ8yttpnHMthCdjevI1BwPlBDTn7tulv7
VEUHqiP1SNhv6VTOU6TOZcaKqB3Fjtvw9FtL12ZbJ+ZCaOsMMQYKukyyzxH6Dz0P
DMHImWB8zqPd8rqWhzSEg8mpPbe9CIcPLOc/GjZJrTQ/RsjFqsCXKK8G5PO4Irfk
/ZbnVQLY1rrOKz0PNcTkcyGQrv+LPvEhwpAT7A5e5wOT79m02JD80wIDAQABo2Ew
XzAdBgNVHQ4EFgQUgeN3QPpaosBM0vKod7+3DCBY7l4wPgYDVR0RBDcwNYINbG9n
aW4uZGlhay5maYYkaHR0cHM6Ly9sb2dpbi5kaWFrLmZpL2lkcC9zaGliYm9sZXRo
MA0GCSqGSIb3DQEBCwUAA4IBAQBduZpR5z/unH7DRJd+Igf0K1/3k3I+opZzyO6N
nC6P14eMsa889e+Dbz565zZqseceo7p9pC2NLjyttskxGWC34YE069QfrTl2z8ez
oJdlflgFvb1mKNAEcYl48byfy8BP8e9E+bS//xlBvQovdgAeiSCq+6y/xSYb4OVU
5kmdWMr1c9qc209RrY2tsU623fywe0AWkPSSh9jzRbUxVB2bblHQGyX34IoPskar
CpSkToBF+5sxc0+DTE4SMRKLFVOMuRUgyd69RHunpmjo55xDRyEy9wcIby/B0N40
0dxy+Pd1MZ1wbfQNdM78PZNxa1EZcfvtKcL9n7H1IXYo+/l6
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDHzCCAgegAwIBAgIUFEG1Az3J5bg83VBhw4UNqRVuSucwDQYJKoZIhvcNAQEL
BQAwGDEWMBQGA1UEAwwNbG9naW4uZGlhay5maTAeFw0xODAxMjYxMzA2NTVaFw0z
ODAxMjYxMzA2NTVaMBgxFjAUBgNVBAMMDWxvZ2luLmRpYWsuZmkwggEiMA0GCSqG
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQCBZTp7V9SlHHRYyFh8vU8iKpWLo1dkcB2c
m2qUjUnnxG0+Ifro6UziWnOU4hWG3sVioPDHeD1Zvd2l8nfrL5GD3bSUe64aBPNT
tHHA2EHMdaxuD6iZ2xJK82+34e9ZZnAPJK5bQRFE6tGqKjq1pUUvqIJdP7IDKd8t
O/Em2nB79+oew1jCxprgv2grutSn4ylqqNs9Cpbw3yjHi5zpDZkf66OgkPdHqZfu
f8CaaEva9owu/fvIR6oRNMluklOIaUHpd+OZZYcuHzUQnztcsLqr8insJ4GLyv92
3L/ciPL32TAxZCiETeIeuuUlY2vGm+WDkRAiWb+r7uJi4DcS+InPAgMBAAGjYTBf
MB0GA1UdDgQWBBRT5F6MRCHIMgNmoI4o2zWmoj2pSzA+BgNVHREENzA1gg1sb2dp
bi5kaWFrLmZphiRodHRwczovL2xvZ2luLmRpYWsuZmkvaWRwL3NoaWJib2xldGgw
DQYJKoZIhvcNAQELBQADggEBADV8pM2vFjWWOvxh+cBdnwSfb/CN9nk7H9XWqdFC
TFJ5xNkw3/Z7N2ShHwDlRgZ5vVBRDqh6s3UPl0Sok8oBoT+U6ebUKDOWupdMFXsg
ZtsxVWN+uS8FPn4HayrGtkgGHqv4F/drW2aGdwMAQqgOI5P92rJ6vYnGQS5s+P7/
/2MD8WhZObmuHtoVVnQUvgWfYiG+4d/qJ9cKLeumPymeaFbLc4mTLyXjin//6Cu3
cDSqeKZ0wtYJndmvQSZDT79QqzcWMT9zxTLe0uhBab3Jtin3mA3nKe+gW1LQUDQ/
N3fVUpsf16XfhjtBR5kVL2KvM7x3dHL+2kv9POWN+p40tRs=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://login.diak.fi:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
        <!-- <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://login.diak.fi:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> -->
        <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->

    </AttributeAuthorityDescriptor>
	
	<!-- EntraId mfa:ta varten-->
<SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">



        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDHzCCAgegAwIBAgIUIRDbEBpRH76m4PpG/auEWQkij98wDQYJKoZIhvcNAQEL
BQAwGDEWMBQGA1UEAwwNbG9naW4uZGlhay5maTAeFw0xODAxMjYxMzA2NTVaFw0z
ODAxMjYxMzA2NTVaMBgxFjAUBgNVBAMMDWxvZ2luLmRpYWsuZmkwggEiMA0GCSqG
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQCqHVCHByKB9o4A1xIim92v3qNS+TubPzbq
+v7ig6FDIWj5IrwL9wciVZXDRi0+5Fv2U+Es7RlT8jVAjEmTfCmMLn+iOJdCqqJA
KDlGhAA6X5miTOcW2ZpFREbuMiH1ng//+qc+MYleysz8BWTq6do8D48v3rCigxGE
50LA2lRmdhPKtFM7/zK+pYsJEw//fEDgaIOvzsuB1wDKhPuqU4RZMSLiRnBpnNC1
GThU1ZrjNY4OpykVkWKXNG5P8Vycj1yypYhBbNcmPkEpqQ7KOBMlerE98qfBjW14
CM5qlVLIUNX1VEoM560apbzJiY6gADJfaePy/lhXjjABLNyaCwQjAgMBAAGjYTBf
MB0GA1UdDgQWBBRI8jdBOb1VQGYxuBFmJYOwlrgUQTA+BgNVHREENzA1gg1sb2dp
bi5kaWFrLmZphiRodHRwczovL2xvZ2luLmRpYWsuZmkvaWRwL3NoaWJib2xldGgw
DQYJKoZIhvcNAQELBQADggEBAFytaPXBqp+G8IfIxNgOrX+CTdavdUYy3lFHl+Cq
dH5+l1fZegawt/NfYFlImbQIenS1QBY54RYTYno0xnOqzY0jwBuZvOgktf0K9Ket
a2kQqF/gJFRTevqVTarSfVL7ooDU81P9N5q1wyqsOqkK/RCLkT43fwj7YEwn4kWg
d8TqaRUFJjEJQd9g95tt+VVR/j5W3nLPHD1iMO4dd1slsLxDvzLQecLWjr+KXCBi
8K7nwqEr7MWEGLoiUu+x+g3PClbmeSSrMw9BkMXmNzDvXKnJN0uvzFt1JQBZLEbg
5nOmhlo+7m8RKNqsL2XNqd7HMb7ON333EAoxeMRFcQKtut8=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDIDCCAgigAwIBAgIVAM2u0euQpVUXCy2RK6zv/W/ZKbiPMA0GCSqGSIb3DQEB
CwUAMBgxFjAUBgNVBAMMDWxvZ2luLmRpYWsuZmkwHhcNMTgwMTI2MTMwNjU0WhcN
MzgwMTI2MTMwNjU0WjAYMRYwFAYDVQQDDA1sb2dpbi5kaWFrLmZpMIIBIjANBgkq
hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAm3ksGzKt9l6d/3XBEzxtC8LIMaHBkBPS
ODz+7N91FEqNmhWXWb+4QLCMDUG3Lv1bMDnKGlTOAHnyXNijkvHGmenLRGNrUzS2
6oe0pPy0tcJ8aeL+xYXxnDo/Uw85PDRNZ8yttpnHMthCdjevI1BwPlBDTn7tulv7
VEUHqiP1SNhv6VTOU6TOZcaKqB3Fjtvw9FtL12ZbJ+ZCaOsMMQYKukyyzxH6Dz0P
DMHImWB8zqPd8rqWhzSEg8mpPbe9CIcPLOc/GjZJrTQ/RsjFqsCXKK8G5PO4Irfk
/ZbnVQLY1rrOKz0PNcTkcyGQrv+LPvEhwpAT7A5e5wOT79m02JD80wIDAQABo2Ew
XzAdBgNVHQ4EFgQUgeN3QPpaosBM0vKod7+3DCBY7l4wPgYDVR0RBDcwNYINbG9n
aW4uZGlhay5maYYkaHR0cHM6Ly9sb2dpbi5kaWFrLmZpL2lkcC9zaGliYm9sZXRo
MA0GCSqGSIb3DQEBCwUAA4IBAQBduZpR5z/unH7DRJd+Igf0K1/3k3I+opZzyO6N
nC6P14eMsa889e+Dbz565zZqseceo7p9pC2NLjyttskxGWC34YE069QfrTl2z8ez
oJdlflgFvb1mKNAEcYl48byfy8BP8e9E+bS//xlBvQovdgAeiSCq+6y/xSYb4OVU
5kmdWMr1c9qc209RrY2tsU623fywe0AWkPSSh9jzRbUxVB2bblHQGyX34IoPskar
CpSkToBF+5sxc0+DTE4SMRKLFVOMuRUgyd69RHunpmjo55xDRyEy9wcIby/B0N40
0dxy+Pd1MZ1wbfQNdM78PZNxa1EZcfvtKcL9n7H1IXYo+/l6
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDHzCCAgegAwIBAgIUFEG1Az3J5bg83VBhw4UNqRVuSucwDQYJKoZIhvcNAQEL
BQAwGDEWMBQGA1UEAwwNbG9naW4uZGlhay5maTAeFw0xODAxMjYxMzA2NTVaFw0z
ODAxMjYxMzA2NTVaMBgxFjAUBgNVBAMMDWxvZ2luLmRpYWsuZmkwggEiMA0GCSqG
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQCBZTp7V9SlHHRYyFh8vU8iKpWLo1dkcB2c
m2qUjUnnxG0+Ifro6UziWnOU4hWG3sVioPDHeD1Zvd2l8nfrL5GD3bSUe64aBPNT
tHHA2EHMdaxuD6iZ2xJK82+34e9ZZnAPJK5bQRFE6tGqKjq1pUUvqIJdP7IDKd8t
O/Em2nB79+oew1jCxprgv2grutSn4ylqqNs9Cpbw3yjHi5zpDZkf66OgkPdHqZfu
f8CaaEva9owu/fvIR6oRNMluklOIaUHpd+OZZYcuHzUQnztcsLqr8insJ4GLyv92
3L/ciPL32TAxZCiETeIeuuUlY2vGm+WDkRAiWb+r7uJi4DcS+InPAgMBAAGjYTBf
MB0GA1UdDgQWBBRT5F6MRCHIMgNmoI4o2zWmoj2pSzA+BgNVHREENzA1gg1sb2dp
bi5kaWFrLmZphiRodHRwczovL2xvZ2luLmRpYWsuZmkvaWRwL3NoaWJib2xldGgw
DQYJKoZIhvcNAQELBQADggEBADV8pM2vFjWWOvxh+cBdnwSfb/CN9nk7H9XWqdFC
TFJ5xNkw3/Z7N2ShHwDlRgZ5vVBRDqh6s3UPl0Sok8oBoT+U6ebUKDOWupdMFXsg
ZtsxVWN+uS8FPn4HayrGtkgGHqv4F/drW2aGdwMAQqgOI5P92rJ6vYnGQS5s+P7/
/2MD8WhZObmuHtoVVnQUvgWfYiG+4d/qJ9cKLeumPymeaFbLc4mTLyXjin//6Cu3
cDSqeKZ0wtYJndmvQSZDT79QqzcWMT9zxTLe0uhBab3Jtin3mA3nKe+gW1LQUDQ/
N3fVUpsf16XfhjtBR5kVL2KvM7x3dHL+2kv9POWN+p40tRs=
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

		<AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.diak.fi/idp/profile/Authn/SAML2/POST/SSO" index="0"/>

    </SPSSODescriptor>

</EntityDescriptor>
