<?xml version="1.0" encoding="UTF-8"?>
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" entityID="https://idp.suro.cz/idp/shibboleth">

    <Extensions>
        <!-- eduGAIN -->
        <eduidmd:RepublishRequest xmlns:eduidmd="http://eduid.cz/schema/metadata/1.0">
            <eduidmd:RepublishTarget>http://edugain.org/</eduidmd:RepublishTarget>
        </eduidmd:RepublishRequest>
    </Extensions>

    <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">

        <Extensions>
            <shibmd:Scope regexp="false">suro.cz</shibmd:Scope>
            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="en">National Radiation Protection Institute</mdui:DisplayName>
                <mdui:DisplayName xml:lang="cs">Státní ústav radiační ochrany, v.v.i.</mdui:DisplayName>
                <mdui:Description xml:lang="en">Identity Provider for SURO employees.</mdui:Description>
                <mdui:Description xml:lang="cs">Identity Provider pro zaměstnance SÚRO.</mdui:Description>
                <mdui:InformationURL xml:lang="en">https://www.suro.cz/en/</mdui:InformationURL>
                <mdui:InformationURL xml:lang="cs">https://www.suro.cz/cz/</mdui:InformationURL>
                <mdui:Logo height="55" width="120">https://www.suro.cz/system/files/2025-03/logoColor.png</mdui:Logo>
            </mdui:UIInfo>
        </Extensions>

        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDGDCCAgCgAwIBAgIVAPcKNHRf7pgj1vaewBDBi1rGPzsHMA0GCSqGSIb3DQEB
CwUAMBYxFDASBgNVBAMMC2lkcC5zdXJvLmN6MB4XDTE4MDkxNDE5MjQxOVoXDTM4
MDkxNDE5MjQxOVowFjEUMBIGA1UEAwwLaWRwLnN1cm8uY3owggEiMA0GCSqGSIb3
DQEBAQUAA4IBDwAwggEKAoIBAQCC95cRncroEg8VOppKxSps2XKW8sGEGp+Q0O/t
TbdloJJwqYGIAD/VeZIFY+BZYn7iBzqt1IqP1uaDM1nmx64RhrlgRUKsKzRIMyC6
QtwXUZC17akixYGFT9PQNMzgNfwT9mxoCetd1CmoLWA3AjRhTjX6ADKhRjkYfus6
PETb1WxCu3ONjvFcksFneJDwZa8AtsdhxLnrDbDA8jEfmwfohzTyk2EtTTNAFeE2
okohL4GwaKEiB8DL+Bm9OVwbmDcChqbGP7VIwrgDRiEBByNTjdBO3DIyidDwZFUP
SrJ4BYgTh/zP/KH5EdsgbsfDqCWMzkvl0EuzEXXMGKTvjy/bAgMBAAGjXTBbMB0G
A1UdDgQWBBSUWgTRdlqDRPaihppRY7b4+8FAizA6BgNVHREEMzAxggtpZHAuc3Vy
by5jeoYiaHR0cHM6Ly9pZHAuc3Vyby5jei9pZHAvc2hpYmJvbGV0aDANBgkqhkiG
9w0BAQsFAAOCAQEAYvGj6hMN19KHfziOOCFWmbUX7Z/8Z8qJqmtBgkLYK8o5Mydc
e+hl535fx/lRY9zKGEXs1cnKqZMMBW2+RXGavqCLpjNpvEuPVGV8hOd99DfaHL0s
MGdhq38Zg40x9b9yjC19HiaIYyXtdIWZK7wD1IbC0OItlvk224xXzct5opNz1whM
776tOa2VV0pGG/EJOP24e3orIUT0umTqxZVRzZA9t1Vj+QBjUvvMVtA91/1ZwHIB
crvO22d1pK9LXjgbLy+C1TTblYIWekpXstCGcQ17kmWXceQtnFRiy5jVekk3oJIW
KWKgl/pUrawfG+w/UbLGJeDZZVppn1N46W4uTA==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDGDCCAgCgAwIBAgIVALVMAA59foP6CQQA6nxD/QnqXo3GMA0GCSqGSIb3DQEB
CwUAMBYxFDASBgNVBAMMC2lkcC5zdXJvLmN6MB4XDTE4MDkxNDE5MjQxOFoXDTM4
MDkxNDE5MjQxOFowFjEUMBIGA1UEAwwLaWRwLnN1cm8uY3owggEiMA0GCSqGSIb3
DQEBAQUAA4IBDwAwggEKAoIBAQDWtK6l2n0T1jDNV60WcmQaKFWjblqJRvLwpaSr
hoBwMaPTzIQ5APg1XVMzXJeOjVmBcRnmv5baS3uMn/83pkJDJcFqiGYmfIx0gnAq
bnezCNbtpbW+7ikukXtgWPc2SsZtRfReNfCDJe4TiNFe+Jtog9XKzP3+WOz+uUf5
qPsFgPy/CXzwTPTssQ+XY9xL6VcO+xTsgvveKgHOPyf8AvHhA6+Ubpn0vJCQLIg4
pxKZza3cHIbxHDJS1DWjnQZdlgMkUX1VmStg7u9A10o+Q/lm0OlwAks4Jt0tE5Lb
td0IIiOMGUg3+TLr3O2jD8ePpLmOsiB9qdD0WcSyGvbjX2ThAgMBAAGjXTBbMB0G
A1UdDgQWBBTD8i9zNRy7gH187I8KqZ5eAFbSXzA6BgNVHREEMzAxggtpZHAuc3Vy
by5jeoYiaHR0cHM6Ly9pZHAuc3Vyby5jei9pZHAvc2hpYmJvbGV0aDANBgkqhkiG
9w0BAQsFAAOCAQEAiWBdiMqeozg74dH5LlxesZwQV05OtSeucmI4JBDp09zt1iNj
Wnd5/tMxdTKv3vLUnWWIg3GRD7kNN+Wo3XJdvN8Zdp6h3B8vHExgvBSGXTA3qVZT
fwf6o5B7DwZnacytwbvS28SEwCcanTsXHfcB22k8u4pcr4fjyVg36FraJ5QuBzv1
leGX9vsaPGRKEmj+JTEX6WJ6D2EePVoDVLVyBLeKEhll/xjQ4nzNGKTuZGfDC5MW
TfbvZwkHDytPX+uZFzb3fO8+pstrfu1z21FO6Q5/Stpu/rUeZIiRjR5KVuJ1XpIg
29H1mxhm4DZj9IoDQ7AqvyTakZy5hkLqqcuPrg==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
MIIDGDCCAgCgAwIBAgIVAOsWShy5umTLXKR892OiFLuGF44yMA0GCSqGSIb3DQEB
CwUAMBYxFDASBgNVBAMMC2lkcC5zdXJvLmN6MB4XDTE4MDkxNDE5MjQxOVoXDTM4
MDkxNDE5MjQxOVowFjEUMBIGA1UEAwwLaWRwLnN1cm8uY3owggEiMA0GCSqGSIb3
DQEBAQUAA4IBDwAwggEKAoIBAQCKBt18ytZ3jUbaqag0IkdgQ2jLl+nhKykKxqCY
lGIkDPuBVVuPSxpi/pYJUfuTN6JALUdbCi3f2/J8n1SquBlcsnh3WwhI43TRjC8K
gdwNho2t+TJwJ+Mv/+ORFwJZITc/a8MB/2eL4uBHAxr+TXbLn2+xlvb4+b0k7Ja+
ulXW3dwFxmsAdIP17wAc18sdqwapi12YF2696jQBRaEYS/vlr8hky31QQLqFh1eF
9+dj+S5Cr+Z0TMmOqPHBXJuwCuo+VsRKlrFzdRnF0Y141V+Rbua9mNogb2mBL+0A
bsOzElLWOTCy4jdSxgerd/8amYm+vERNF32b08aa4K2NeacdAgMBAAGjXTBbMB0G
A1UdDgQWBBRcyt5jdz/hJs6end9OM3bJksoTgjA6BgNVHREEMzAxggtpZHAuc3Vy
by5jeoYiaHR0cHM6Ly9pZHAuc3Vyby5jei9pZHAvc2hpYmJvbGV0aDANBgkqhkiG
9w0BAQsFAAOCAQEAXGXcLVY2hzHObUQhabUqm5IXiEA6qGWMokUB6qZmshUnMOkC
CZI4vMESveV/mEUuhDHOh1a/is1x29n143YPBguVwpddCJ3rCTHeyXVa6DZOQthK
7kq3jb66bHUMbZ4PS7ociSDoB8lYf1tK7487ryrCl7XoYHO0TbgAWeyAHIz7iEzy
ND/0wuV2tjx0/lUlT2u26P2N9B2KmmeKAZOQf7O7PDghh8f9mxsGFNKZgl+pnaFR
ywUTKZmKewQFxYCojWUrgdoiNbTa1sAQPuPM9u7qsco6TwrpNxVokhB3+DYDAbhE
DbmSWlH+bYpRg2X1oJsTHaCdhfWDG/FUkiIM/g==
                        </ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>

        </KeyDescriptor>

        <!--
	<ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.suro.cz:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
        <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.suro.cz:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>
	-->

        <!--
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.suro.cz/idp/profile/SAML2/Redirect/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.suro.cz/idp/profile/SAML2/POST/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.suro.cz/idp/profile/SAML2/POST-SimpleSign/SLO"/>
        <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.suro.cz:8443/idp/profile/SAML2/SOAP/SLO"/>
        -->

        <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>

        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.suro.cz/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.suro.cz/idp/profile/SAML2/POST-SimpleSign/SSO"/>
        <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.suro.cz/idp/profile/SAML2/Redirect/SSO"/>

    </IDPSSODescriptor>

    <Organization>
        <OrganizationName xml:lang="en">National Radiation Protection Institute</OrganizationName>
        <OrganizationName xml:lang="cs">Státní ústav radiační ochrany, v.v.i.</OrganizationName>
        <OrganizationDisplayName xml:lang="en">National Radiation Protection Institute</OrganizationDisplayName>
        <OrganizationDisplayName xml:lang="cs">Státní ústav radiační ochrany, v.v.i.</OrganizationDisplayName>
        <OrganizationURL xml:lang="en">https://www.suro.cz/en/</OrganizationURL>
        <OrganizationURL xml:lang="cs">https://www.suro.cz/cz/</OrganizationURL>
    </Organization>

    <ContactPerson contactType="technical">
        <GivenName>Vít</GivenName>
        <SurName>Labský</SurName>
        <EmailAddress>mailto:vit.labsky@suro.cz</EmailAddress>
    </ContactPerson>

</EntityDescriptor>
