<EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" ID="_3dad8d82-a26d-4fa4-8cc5-365bc5a3b985" entityID="http://idad.jpmorganchase.com/adfs/services/trust">
<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
<ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<ds:Reference URI="#_3dad8d82-a26d-4fa4-8cc5-365bc5a3b985">
<ds:Transforms>
<ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
</ds:Transforms>
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<ds:DigestValue>q9rFcCy9gAQOjkmxtE51vBzvHOenNg/CNBeum4/MtW4=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>CT6XG3MnakPU/p9m/bklJHIckS+Tp90E0QcHQ87XlkZZQKxHxsvB5bpYAcKJwVczvTTNxWXqm3Jujczw01RZqHRPFrSSGq+h1exHrt6idk8pVLRWVSzlhX70JQ/SpFxQiR5aVWYlzNxITtUXeyXLkoZ/bOi+2HCld8xsl9ZXzfq33oadjsrop6iptTv2CAomFU+2nVtfX1a9WauNcB9st45n/RYK32pjPdKh0JVEvpjcc4BkPNcjCSl7VrzZNgG3W95Z1l9j62jHXvbI0f1nX7ezKRrc4GaN91thXmnIuXJ/W2HMunPXoblgJoxLh2dF38bHbrM5ykW28zZSJg57CQ==</ds:SignatureValue>
<KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
<X509Data>
<X509Certificate>MIIDPjCCAiagAwIBAgIQIobBuvMfjZJJs5M30rFd5TANBgkqhkiG9w0BAQsFADAyMTAwLgYDVQQDDCdBREZTIFNpZ25pbmcgLSBpZGFkZzIuanBtb3JnYW5jaGFzZS5jb20wHhcNMjUwNzAzMTI0NTExWhcNMjcwNzAzMTI0NTExWjAyMTAwLgYDVQQDDCdBREZTIFNpZ25pbmcgLSBpZGFkZzIuanBtb3JnYW5jaGFzZS5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDCKvI63/RdJRulTi2Jm1QVRzkFZds8Gxx9wXpJAE0vckMF6l5CPKraoIFKjztwk0UM/078OfXGY2KGWbv5tsDP2vV0+VgPgUgrRScP0Hu3hMahwIC2QhalxrUqZM54htRsrU+6jXDJpjXXKUUZNnvvMqOzXWgSZ/ssHkhqURc/IXtEiAFsj3L3KviJ4q4pvRa5eZ2RWfoP3K0+PKFeo0w1n6Xc14ChO8oM1ZVw6GGHfs/qs/49f+7gyll6iJLl5Zy0vhaZCr5qSLZaq8U7zzZZhrFnVT67VNMMkGbs3MdOOVs+b6PtfBlVfQqrwhXLzzVr4MqX2GgmhDptiuR+4HCFAgMBAAGjUDBOMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFNYtVU0cPtvMyGCo+9vvxJsly3BYMA0GCSqGSIb3DQEBCwUAA4IBAQBbqLu7H7eUJA1cdGBTiRktlFh5KtcrjHEk6eayHgtcwpH0vS4DVGGpAqpp0KAzWqfQmcuZOe3382jczXODYqhISZuIIcG07PUvZRmiDbUqAHwC8oxwfwQzsUkfyJmd3wHDDSFrIkbih+Gg+SFl/wOdHLrSvdMl7qn7ev1If/hUHauCHFejig0I3S0bTNGarYCXKlYanKUBelWz6o8MyMk2kDbEjubgbmsCRs2Zr8mTst/cE7U97nwWPoqFKM01xcs+OFuk6Ysy07SVQ46V2OEbm9ZGOtYvsuqyI4bNGBi2VDmvtXQkHAvADElqSdsJ/MpooI10/481QnKbLI7IWlCq</X509Certificate>
</X509Data>
</KeyInfo>
</ds:Signature>
<RoleDescriptor xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:fed="http://docs.oasis-open.org/wsfed/federation/200706" xsi:type="fed:ApplicationServiceType" protocolSupportEnumeration="http://docs.oasis-open.org/ws-sx/ws-trust/200512 http://schemas.xmlsoap.org/ws/2005/02/trust http://docs.oasis-open.org/wsfed/federation/200706" ServiceDisplayName="JPMorgan Chase & Co. Federation Services">
<KeyDescriptor use="encryption">
<KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
<X509Data></X509Data>
<X509Certificate>MIIDRDCCAiygAwIBAgIQGsKwHcVMYIdPQqb6PKFNqDANBgkqhkiG9w0BAQsFADA1MTMwMQYDVQQDDCpBREZTIEVuY3J5cHRpb24gLSBpZGFkZzIuanBtb3JnYW5jaGFzZS5jb20wHhcNMjUwNzAzMTI0NTExWhcNMjcwNzAzMTI0NTExWjA1MTMwMQYDVQQDDCpBREZTIEVuY3J5cHRpb24gLSBpZGFkZzIuanBtb3JnYW5jaGFzZS5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCcSrwvUkKJ06dGNBWRy1WlrD4oQtPm0TlTkJlJdhmlTNtGZzUZFVwFIOfQrV1Ry1qFvbI58hDsOcjgIYQ+SM+KGZg3nq3hgVLBcOWkl3kmN8AMexNGAkif3scRqOS8jnenOWkFSor3d2abQE+3Sf80QhW23HIZanvMpQgDeX4tMg+Rz33JgUtXIWg805xoZmmKgAFaiql7nnjmvJ/EOJDaKkFVsgG3yjx3T0n88c7nTgS36vgUkWgfrZjbrydW//Jw5fO1sItt1yx/r8a0ZDRYcOZz42Y1nP6X0WwKPXhJa1I8VeiTyn+383rpFgglHifiOBRBIPPgLP79i54aKpHVAgMBAAGjUDBOMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFPZEyUfpQRp8vHfoqY3eTvWTskXSMA0GCSqGSIb3DQEBCwUAA4IBAQBRTqldOdDTmNDCGYG39zdmE3Viq92dId49Zblfq43ZmDRlh4B4JYSxWD3TQvQoaiKePMc/kj5D2mXqvEuw/4uWnv0XhYm156Wb+vQNUFzFApnRkMw5bTbJ3a7ZE/499duD2v/6XmgOXjLUb4o5lCssbC9wO2A8tR+0qgQlDbk6ZWoSe4UCI20vpoUNoGk5C2oWHSjv4HQjL4uxxGJfnSAkMVFkMJEs22AB7IwHGsteM3ayhKz9reCu4CIspsixt5CZgoALJWJcguXpZBYiH7vZXxfbps4+rXuDUbiw2Cud/W2hpqhcXKUYUENIRSgEgjF/uQ/n+XdWNlu0Ff5OtO8e</X509Certificate>
</X509Data>
</KeyInfo>
</KeyDescriptor>
<fed:ClaimTypesRequested>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress" Optional="true">
<auth:DisplayName>E-Mail Address</auth:DisplayName>
<auth:Description>The e-mail address of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname" Optional="true">
<auth:DisplayName>Given Name</auth:DisplayName>
<auth:Description>The given name of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name" Optional="true">
<auth:DisplayName>Name</auth:DisplayName>
<auth:Description>The unique name of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn" Optional="true">
<auth:DisplayName>UPN</auth:DisplayName>
<auth:Description>The user principal name (UPN) of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/claims/CommonName" Optional="true">
<auth:DisplayName>Common Name</auth:DisplayName>
<auth:Description>The common name of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/claims/EmailAddress" Optional="true">
<auth:DisplayName>AD FS 1.x E-Mail Address</auth:DisplayName>
<auth:Description>The e-mail address of the user when interoperating with AD FS 1.1 or AD FS 1.0</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/claims/Group" Optional="true">
<auth:DisplayName>Group</auth:DisplayName>
<auth:Description>A group that the user is a member of</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/claims/UPN" Optional="true">
<auth:DisplayName>AD FS 1.x UPN</auth:DisplayName>
<auth:Description>The UPN of the user when interoperating with AD FS 1.1 or AD FS 1.0</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/role" Optional="true">
<auth:DisplayName>Role</auth:DisplayName>
<auth:Description>A role that the user has</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname" Optional="true">
<auth:DisplayName>Surname</auth:DisplayName>
<auth:Description>The surname of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/privatepersonalidentifier" Optional="true">
<auth:DisplayName>PPID</auth:DisplayName>
<auth:Description>The private identifier of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier" Optional="true">
<auth:DisplayName>Name ID</auth:DisplayName>
<auth:Description>The SAML name identifier of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant" Optional="true">
<auth:DisplayName>Authentication time stamp</auth:DisplayName>
<auth:Description>Used to display the time and date that the user was authenticated</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod" Optional="true">
<auth:DisplayName>Authentication method</auth:DisplayName>
<auth:Description>The method used to authenticate the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/denyonlysid" Optional="true">
<auth:DisplayName>Deny only group SID</auth:DisplayName>
<auth:Description>The deny-only group SID of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarysid" Optional="true">
<auth:DisplayName>Deny only primary SID</auth:DisplayName>
<auth:Description>The deny-only primary SID of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarygroupsid" Optional="true">
<auth:DisplayName>Deny only primary group SID</auth:DisplayName>
<auth:Description>The deny-only primary group SID of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid" Optional="true">
<auth:DisplayName>Group SID</auth:DisplayName>
<auth:Description>The group SID of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/primarygroupsid" Optional="true">
<auth:DisplayName>Primary group SID</auth:DisplayName>
<auth:Description>The primary group SID of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid" Optional="true">
<auth:DisplayName>Primary SID</auth:DisplayName>
<auth:Description>The primary SID of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname" Optional="true">
<auth:DisplayName>Windows account name</auth:DisplayName>
<auth:Description>The domain account name of the user in the form of domain user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/devicecontext/claims/isregistereduser" Optional="true">
<auth:DisplayName>Is Registered User</auth:DisplayName>
<auth:Description>User is registered to use this device</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/devicecontext/claims/identifier" Optional="true">
<auth:DisplayName>Device Identifier</auth:DisplayName>
<auth:Description>Identifier of the device</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/devicecontext/claims/registrationid" Optional="true">
<auth:DisplayName>Device Registration Identifier</auth:DisplayName>
<auth:Description>Identifier for Device Registration</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/devicecontext/claims/displayname" Optional="true">
<auth:DisplayName>Device Registration DisplayName</auth:DisplayName>
<auth:Description>Display name of Device Registration</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/devicecontext/claims/ostype" Optional="true">
<auth:DisplayName>Device OS type</auth:DisplayName>
<auth:Description>OS type of the device</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/devicecontext/claims/osversion" Optional="true">
<auth:DisplayName>Device OS Version</auth:DisplayName>
<auth:Description>OS version of the device</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/devicecontext/claims/ismanaged" Optional="true">
<auth:DisplayName>Is Managed Device</auth:DisplayName>
<auth:Description>Device is managed by a management service</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-forwarded-client-ip" Optional="true">
<auth:DisplayName>Forwarded Client IP</auth:DisplayName>
<auth:Description>IP address of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-client-application" Optional="true">
<auth:DisplayName>Client Application</auth:DisplayName>
<auth:Description>Type of the Client Application</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-client-user-agent" Optional="true">
<auth:DisplayName>Client User Agent</auth:DisplayName>
<auth:Description>Device type the client is using to access the application</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-client-ip" Optional="true">
<auth:DisplayName>Client IP</auth:DisplayName>
<auth:Description>IP address of the client</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-endpoint-absolute-path" Optional="true">
<auth:DisplayName>Endpoint Path</auth:DisplayName>
<auth:Description>Absolute Endpoint path which can be used to determine active versus passive clients</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-proxy" Optional="true">
<auth:DisplayName>Proxy</auth:DisplayName>
<auth:Description>DNS name of the federation server proxy that passed the request</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/requestcontext/claims/relyingpartytrustid" Optional="true">
<auth:DisplayName>Application Identifier</auth:DisplayName>
<auth:Description>Identifier for the Relying Party</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/applicationpolicy" Optional="true">
<auth:DisplayName>Application policies</auth:DisplayName>
<auth:Description>Application policies of the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/authoritykeyidentifier" Optional="true">
<auth:DisplayName>Authority Key Identifier</auth:DisplayName>
<auth:Description>The Authority Key Identifier extension of the certificate that signed an issued certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/basicconstraints" Optional="true">
<auth:DisplayName>Basic Constraint</auth:DisplayName>
<auth:Description>One of the basic constraints of the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/eku" Optional="true">
<auth:DisplayName>Enhanced Key Usage</auth:DisplayName>
<auth:Description>Describes one of the enhanced key usages of the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/field/issuer" Optional="true">
<auth:DisplayName>Issuer</auth:DisplayName>
<auth:Description>The name of the certificate authority that issued the X.509 certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/field/issuername" Optional="true">
<auth:DisplayName>Issuer Name</auth:DisplayName>
<auth:Description>The distinguished name of the certificate issuer</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/keyusage" Optional="true">
<auth:DisplayName>Key Usage</auth:DisplayName>
<auth:Description>One of the key usages of the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/field/notafter" Optional="true">
<auth:DisplayName>Not After</auth:DisplayName>
<auth:Description>Date in local time after which a certificate is no longer valid</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/field/notbefore" Optional="true">
<auth:DisplayName>Not Before</auth:DisplayName>
<auth:Description>The date in local time on which a certificate becomes valid</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/certificatepolicy" Optional="true">
<auth:DisplayName>Certificate Policies</auth:DisplayName>
<auth:Description>The policies under which the certificate has been issued</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/rsa" Optional="true">
<auth:DisplayName>Public Key</auth:DisplayName>
<auth:Description>Public Key of the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/field/rawdata" Optional="true">
<auth:DisplayName>Certificate Raw Data</auth:DisplayName>
<auth:Description>The raw data of the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/san" Optional="true">
<auth:DisplayName>Subject Alternative Name</auth:DisplayName>
<auth:Description>One of the alternative names of the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/serialnumber" Optional="true">
<auth:DisplayName>Serial Number</auth:DisplayName>
<auth:Description>The serial number of a certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/field/signaturealgorithm" Optional="true">
<auth:DisplayName>Signature Algorithm</auth:DisplayName>
<auth:Description>The algorithm used to create the signature of a certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/field/subject" Optional="true">
<auth:DisplayName>Subject</auth:DisplayName>
<auth:Description>The subject from the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/subjectkeyidentifier" Optional="true">
<auth:DisplayName>Subject Key Identifier</auth:DisplayName>
<auth:Description>Describes the subject key identifier of the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/field/subjectname" Optional="true">
<auth:DisplayName>Subject Name</auth:DisplayName>
<auth:Description>The subject distinguished name from a certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/certificatetemplateinformation" Optional="true">
<auth:DisplayName>V2 Template Name</auth:DisplayName>
<auth:Description>The name of the version 2 certificate template used when issuing or renewing a certificate. The extension is Microsoft specific.</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/certificatetemplatename" Optional="true">
<auth:DisplayName>V1 Template Name</auth:DisplayName>
<auth:Description>The name of the version 1 certificate template used when issuing or renewing a certificate. The extension is Microsoft specific.</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/thumbprint" Optional="true">
<auth:DisplayName>Thumbprint</auth:DisplayName>
<auth:Description>Thumbprint of the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/field/x509version" Optional="true">
<auth:DisplayName>X.509 Version</auth:DisplayName>
<auth:Description>The X.509 format version of a certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2012/01/insidecorporatenetwork" Optional="true">
<auth:DisplayName>Inside Corporate Network</auth:DisplayName>
<auth:Description>Used to indicate if a request originated inside corporate network</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2012/01/passwordexpirationtime" Optional="true">
<auth:DisplayName>Password Expiration Time</auth:DisplayName>
<auth:Description>Used to display the time when the password expires</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2012/01/passwordexpirationdays" Optional="true">
<auth:DisplayName>Password Expiration Days</auth:DisplayName>
<auth:Description>Used to display the number of days to password expiry</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2012/01/passwordchangeurl" Optional="true">
<auth:DisplayName>Update Password URL</auth:DisplayName>
<auth:Description>Used to display the web address of update password service</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/claims/authnmethodsreferences" Optional="true">
<auth:DisplayName>Authentication Methods References</auth:DisplayName>
<auth:Description>Used to indicate all authentication methods used to authenticate the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/requestcontext/claims/client-request-id" Optional="true">
<auth:DisplayName>Client Request ID</auth:DisplayName>
<auth:Description>Identifier for a user session</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2013/11/alternateloginid" Optional="true">
<auth:DisplayName>Alternate Login ID</auth:DisplayName>
<auth:Description>Alternate login ID of the user</auth:Description>
</auth:ClaimType>
</fed:ClaimTypesRequested>
<fed:TargetScopes>
<EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
<Address>https://idadg2.jpmorganchase.com/adfs/services/trust/2005/issuedtokenmixedasymmetricbasic256</Address>
</EndpointReference>
<EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
<Address>https://idadg2.jpmorganchase.com/adfs/services/trust/2005/issuedtokenmixedsymmetricbasic256</Address>
</EndpointReference>
<EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
<Address>https://idadg2.jpmorganchase.com/adfs/services/trust/13/issuedtokenmixedasymmetricbasic256</Address>
</EndpointReference>
<EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
<Address>https://idadg2.jpmorganchase.com/adfs/services/trust/13/issuedtokenmixedasymmetricbasic256sha256</Address>
</EndpointReference>
<EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
<Address>https://idadg2.jpmorganchase.com/adfs/services/trust/13/issuedtokenmixedsymmetricbasic256</Address>
</EndpointReference>
<EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
<Address>https://idadg2.jpmorganchase.com/adfs/ls/</Address>
</EndpointReference>
<EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
<Address>http://idad.jpmorganchase.com/adfs/services/trust</Address>
</EndpointReference>
</fed:TargetScopes>
<fed:ApplicationServiceEndpoint>
<EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
<Address>https://idadg2.jpmorganchase.com/adfs/services/trust/2005/issuedtokenmixedasymmetricbasic256</Address>
</EndpointReference>
</fed:ApplicationServiceEndpoint>
<fed:PassiveRequestorEndpoint>
<EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
<Address>https://idadg2.jpmorganchase.com/adfs/ls/</Address>
</EndpointReference>
</fed:PassiveRequestorEndpoint>
</RoleDescriptor>
<RoleDescriptor xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:fed="http://docs.oasis-open.org/wsfed/federation/200706" xsi:type="fed:SecurityTokenServiceType" protocolSupportEnumeration="http://docs.oasis-open.org/ws-sx/ws-trust/200512 http://schemas.xmlsoap.org/ws/2005/02/trust http://docs.oasis-open.org/wsfed/federation/200706" ServiceDisplayName="JPMorgan Chase & Co. Federation Services">
<KeyDescriptor use="signing">
<KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
<X509Data>
<X509Certificate>MIIDPjCCAiagAwIBAgIQTaHJ7I2WPY9DDxQXyv8pbDANBgkqhkiG9w0BAQsFADAyMTAwLgYDVQQDDCdBREZTIFNpZ25pbmcgLSBpZGFkZzIuanBtb3JnYW5jaGFzZS5jb20wHhcNMjUwNjE5MTI0NTA4WhcNMjcwNjE5MTI0NTA4WjAyMTAwLgYDVQQDDCdBREZTIFNpZ25pbmcgLSBpZGFkZzIuanBtb3JnYW5jaGFzZS5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDZFH7sPdjjpPXmE+3lCrRFjso5IMXWopFyZ4JUtnl4+S877xyMMXOLxX/gfXAIzR+V/NVZpdsXHY15PAexFD6ar8oTJXfDke1H4M35V8fJ7QBWl7I/svPSqgZsFBU1FsM4Gu0gJpH42cmxrfOS0sII9ExRSzfbWHUyV+j7YPXaydbLxl9d94gpazlXfE++pFaM5a6BYruf8KQKXjjK/onxwgxdFpkx9PcDTw3cjHIPPN4Ooka5h8V+Zo6COLhq+q0O6D+DYRmXbYGzwm/Uf1lBvjXviDN3koRylmjK45Af98lRD9YCmKqbWinbgMg9vp+hr72ccxyZr0JRbIuTWh6xAgMBAAGjUDBOMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFL64+BoAtH+jlTSRJ5HErT6rggb4MA0GCSqGSIb3DQEBCwUAA4IBAQBw3Ye2y8DLDJ/bp6wgTkllmq/jbHqSRqWWPdLAb1pB1SMANn5aDgrRzYuOr6qcaeWhCgBA1eZI5fkcx6tsrNjHefeZvM3Mr2ubsdXBRdbsGDK4436ZuHi5EebpVJDhQM9KdvAs03kJjuqXAt+srU4m9l5osNgDpFKTYShQ4DQ1i7Zet6etPZHpcM7mw1v/nzG3Z59/Vo7d0+Qs2Ctijo+4Tl11iBhUOXj89LsgSF3gA43VunMBINj3OohMTGeVBxBuRxrohd9dAwrNjYWTo8UGkNoDkx7BkDtk6iIacdr3XvI2Q5UYfj9A+TR0qCjwVqFHW7suCT/S4jkiQRgJx4tS</X509Certificate>
</X509Data>
</KeyInfo>
</KeyDescriptor>
<KeyDescriptor use="signing">
<KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
<X509Data>
<X509Certificate>MIIDPjCCAiagAwIBAgIQIobBuvMfjZJJs5M30rFd5TANBgkqhkiG9w0BAQsFADAyMTAwLgYDVQQDDCdBREZTIFNpZ25pbmcgLSBpZGFkZzIuanBtb3JnYW5jaGFzZS5jb20wHhcNMjUwNzAzMTI0NTExWhcNMjcwNzAzMTI0NTExWjAyMTAwLgYDVQQDDCdBREZTIFNpZ25pbmcgLSBpZGFkZzIuanBtb3JnYW5jaGFzZS5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDCKvI63/RdJRulTi2Jm1QVRzkFZds8Gxx9wXpJAE0vckMF6l5CPKraoIFKjztwk0UM/078OfXGY2KGWbv5tsDP2vV0+VgPgUgrRScP0Hu3hMahwIC2QhalxrUqZM54htRsrU+6jXDJpjXXKUUZNnvvMqOzXWgSZ/ssHkhqURc/IXtEiAFsj3L3KviJ4q4pvRa5eZ2RWfoP3K0+PKFeo0w1n6Xc14ChO8oM1ZVw6GGHfs/qs/49f+7gyll6iJLl5Zy0vhaZCr5qSLZaq8U7zzZZhrFnVT67VNMMkGbs3MdOOVs+b6PtfBlVfQqrwhXLzzVr4MqX2GgmhDptiuR+4HCFAgMBAAGjUDBOMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFNYtVU0cPtvMyGCo+9vvxJsly3BYMA0GCSqGSIb3DQEBCwUAA4IBAQBbqLu7H7eUJA1cdGBTiRktlFh5KtcrjHEk6eayHgtcwpH0vS4DVGGpAqpp0KAzWqfQmcuZOe3382jczXODYqhISZuIIcG07PUvZRmiDbUqAHwC8oxwfwQzsUkfyJmd3wHDDSFrIkbih+Gg+SFl/wOdHLrSvdMl7qn7ev1If/hUHauCHFejig0I3S0bTNGarYCXKlYanKUBelWz6o8MyMk2kDbEjubgbmsCRs2Zr8mTst/cE7U97nwWPoqFKM01xcs+OFuk6Ysy07SVQ46V2OEbm9ZGOtYvsuqyI4bNGBi2VDmvtXQkHAvADElqSdsJ/MpooI10/481QnKbLI7IWlCq</X509Certificate>
</X509Data>
</KeyInfo>
</KeyDescriptor>
<fed:TokenTypesOffered>
<fed:TokenType Uri="urn:oasis:names:tc:SAML:2.0:assertion"/>
<fed:TokenType Uri="urn:oasis:names:tc:SAML:1.0:assertion"/>
</fed:TokenTypesOffered>
<fed:ClaimTypesOffered>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress" Optional="true">
<auth:DisplayName>E-Mail Address</auth:DisplayName>
<auth:Description>The e-mail address of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname" Optional="true">
<auth:DisplayName>Given Name</auth:DisplayName>
<auth:Description>The given name of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name" Optional="true">
<auth:DisplayName>Name</auth:DisplayName>
<auth:Description>The unique name of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn" Optional="true">
<auth:DisplayName>UPN</auth:DisplayName>
<auth:Description>The user principal name (UPN) of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/claims/CommonName" Optional="true">
<auth:DisplayName>Common Name</auth:DisplayName>
<auth:Description>The common name of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/claims/EmailAddress" Optional="true">
<auth:DisplayName>AD FS 1.x E-Mail Address</auth:DisplayName>
<auth:Description>The e-mail address of the user when interoperating with AD FS 1.1 or AD FS 1.0</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/claims/Group" Optional="true">
<auth:DisplayName>Group</auth:DisplayName>
<auth:Description>A group that the user is a member of</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/claims/UPN" Optional="true">
<auth:DisplayName>AD FS 1.x UPN</auth:DisplayName>
<auth:Description>The UPN of the user when interoperating with AD FS 1.1 or AD FS 1.0</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/role" Optional="true">
<auth:DisplayName>Role</auth:DisplayName>
<auth:Description>A role that the user has</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname" Optional="true">
<auth:DisplayName>Surname</auth:DisplayName>
<auth:Description>The surname of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/privatepersonalidentifier" Optional="true">
<auth:DisplayName>PPID</auth:DisplayName>
<auth:Description>The private identifier of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier" Optional="true">
<auth:DisplayName>Name ID</auth:DisplayName>
<auth:Description>The SAML name identifier of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant" Optional="true">
<auth:DisplayName>Authentication time stamp</auth:DisplayName>
<auth:Description>Used to display the time and date that the user was authenticated</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod" Optional="true">
<auth:DisplayName>Authentication method</auth:DisplayName>
<auth:Description>The method used to authenticate the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/denyonlysid" Optional="true">
<auth:DisplayName>Deny only group SID</auth:DisplayName>
<auth:Description>The deny-only group SID of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarysid" Optional="true">
<auth:DisplayName>Deny only primary SID</auth:DisplayName>
<auth:Description>The deny-only primary SID of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarygroupsid" Optional="true">
<auth:DisplayName>Deny only primary group SID</auth:DisplayName>
<auth:Description>The deny-only primary group SID of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid" Optional="true">
<auth:DisplayName>Group SID</auth:DisplayName>
<auth:Description>The group SID of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/primarygroupsid" Optional="true">
<auth:DisplayName>Primary group SID</auth:DisplayName>
<auth:Description>The primary group SID of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid" Optional="true">
<auth:DisplayName>Primary SID</auth:DisplayName>
<auth:Description>The primary SID of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname" Optional="true">
<auth:DisplayName>Windows account name</auth:DisplayName>
<auth:Description>The domain account name of the user in the form of domain user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/devicecontext/claims/isregistereduser" Optional="true">
<auth:DisplayName>Is Registered User</auth:DisplayName>
<auth:Description>User is registered to use this device</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/devicecontext/claims/identifier" Optional="true">
<auth:DisplayName>Device Identifier</auth:DisplayName>
<auth:Description>Identifier of the device</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/devicecontext/claims/registrationid" Optional="true">
<auth:DisplayName>Device Registration Identifier</auth:DisplayName>
<auth:Description>Identifier for Device Registration</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/devicecontext/claims/displayname" Optional="true">
<auth:DisplayName>Device Registration DisplayName</auth:DisplayName>
<auth:Description>Display name of Device Registration</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/devicecontext/claims/ostype" Optional="true">
<auth:DisplayName>Device OS type</auth:DisplayName>
<auth:Description>OS type of the device</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/devicecontext/claims/osversion" Optional="true">
<auth:DisplayName>Device OS Version</auth:DisplayName>
<auth:Description>OS version of the device</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/devicecontext/claims/ismanaged" Optional="true">
<auth:DisplayName>Is Managed Device</auth:DisplayName>
<auth:Description>Device is managed by a management service</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-forwarded-client-ip" Optional="true">
<auth:DisplayName>Forwarded Client IP</auth:DisplayName>
<auth:Description>IP address of the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-client-application" Optional="true">
<auth:DisplayName>Client Application</auth:DisplayName>
<auth:Description>Type of the Client Application</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-client-user-agent" Optional="true">
<auth:DisplayName>Client User Agent</auth:DisplayName>
<auth:Description>Device type the client is using to access the application</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-client-ip" Optional="true">
<auth:DisplayName>Client IP</auth:DisplayName>
<auth:Description>IP address of the client</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-endpoint-absolute-path" Optional="true">
<auth:DisplayName>Endpoint Path</auth:DisplayName>
<auth:Description>Absolute Endpoint path which can be used to determine active versus passive clients</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-proxy" Optional="true">
<auth:DisplayName>Proxy</auth:DisplayName>
<auth:Description>DNS name of the federation server proxy that passed the request</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/requestcontext/claims/relyingpartytrustid" Optional="true">
<auth:DisplayName>Application Identifier</auth:DisplayName>
<auth:Description>Identifier for the Relying Party</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/applicationpolicy" Optional="true">
<auth:DisplayName>Application policies</auth:DisplayName>
<auth:Description>Application policies of the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/authoritykeyidentifier" Optional="true">
<auth:DisplayName>Authority Key Identifier</auth:DisplayName>
<auth:Description>The Authority Key Identifier extension of the certificate that signed an issued certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/basicconstraints" Optional="true">
<auth:DisplayName>Basic Constraint</auth:DisplayName>
<auth:Description>One of the basic constraints of the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/eku" Optional="true">
<auth:DisplayName>Enhanced Key Usage</auth:DisplayName>
<auth:Description>Describes one of the enhanced key usages of the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/field/issuer" Optional="true">
<auth:DisplayName>Issuer</auth:DisplayName>
<auth:Description>The name of the certificate authority that issued the X.509 certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/field/issuername" Optional="true">
<auth:DisplayName>Issuer Name</auth:DisplayName>
<auth:Description>The distinguished name of the certificate issuer</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/keyusage" Optional="true">
<auth:DisplayName>Key Usage</auth:DisplayName>
<auth:Description>One of the key usages of the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/field/notafter" Optional="true">
<auth:DisplayName>Not After</auth:DisplayName>
<auth:Description>Date in local time after which a certificate is no longer valid</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/field/notbefore" Optional="true">
<auth:DisplayName>Not Before</auth:DisplayName>
<auth:Description>The date in local time on which a certificate becomes valid</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/certificatepolicy" Optional="true">
<auth:DisplayName>Certificate Policies</auth:DisplayName>
<auth:Description>The policies under which the certificate has been issued</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/rsa" Optional="true">
<auth:DisplayName>Public Key</auth:DisplayName>
<auth:Description>Public Key of the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/field/rawdata" Optional="true">
<auth:DisplayName>Certificate Raw Data</auth:DisplayName>
<auth:Description>The raw data of the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/san" Optional="true">
<auth:DisplayName>Subject Alternative Name</auth:DisplayName>
<auth:Description>One of the alternative names of the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/serialnumber" Optional="true">
<auth:DisplayName>Serial Number</auth:DisplayName>
<auth:Description>The serial number of a certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/field/signaturealgorithm" Optional="true">
<auth:DisplayName>Signature Algorithm</auth:DisplayName>
<auth:Description>The algorithm used to create the signature of a certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/field/subject" Optional="true">
<auth:DisplayName>Subject</auth:DisplayName>
<auth:Description>The subject from the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/subjectkeyidentifier" Optional="true">
<auth:DisplayName>Subject Key Identifier</auth:DisplayName>
<auth:Description>Describes the subject key identifier of the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/field/subjectname" Optional="true">
<auth:DisplayName>Subject Name</auth:DisplayName>
<auth:Description>The subject distinguished name from a certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/certificatetemplateinformation" Optional="true">
<auth:DisplayName>V2 Template Name</auth:DisplayName>
<auth:Description>The name of the version 2 certificate template used when issuing or renewing a certificate. The extension is Microsoft specific.</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/extension/certificatetemplatename" Optional="true">
<auth:DisplayName>V1 Template Name</auth:DisplayName>
<auth:Description>The name of the version 1 certificate template used when issuing or renewing a certificate. The extension is Microsoft specific.</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/thumbprint" Optional="true">
<auth:DisplayName>Thumbprint</auth:DisplayName>
<auth:Description>Thumbprint of the certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/12/certificatecontext/field/x509version" Optional="true">
<auth:DisplayName>X.509 Version</auth:DisplayName>
<auth:Description>The X.509 format version of a certificate</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2012/01/insidecorporatenetwork" Optional="true">
<auth:DisplayName>Inside Corporate Network</auth:DisplayName>
<auth:Description>Used to indicate if a request originated inside corporate network</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2012/01/passwordexpirationtime" Optional="true">
<auth:DisplayName>Password Expiration Time</auth:DisplayName>
<auth:Description>Used to display the time when the password expires</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2012/01/passwordexpirationdays" Optional="true">
<auth:DisplayName>Password Expiration Days</auth:DisplayName>
<auth:Description>Used to display the number of days to password expiry</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2012/01/passwordchangeurl" Optional="true">
<auth:DisplayName>Update Password URL</auth:DisplayName>
<auth:Description>Used to display the web address of update password service</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/claims/authnmethodsreferences" Optional="true">
<auth:DisplayName>Authentication Methods References</auth:DisplayName>
<auth:Description>Used to indicate all authentication methods used to authenticate the user</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/2012/01/requestcontext/claims/client-request-id" Optional="true">
<auth:DisplayName>Client Request ID</auth:DisplayName>
<auth:Description>Identifier for a user session</auth:Description>
</auth:ClaimType>
<auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2013/11/alternateloginid" Optional="true">
<auth:DisplayName>Alternate Login ID</auth:DisplayName>
<auth:Description>Alternate login ID of the user</auth:Description>
</auth:ClaimType>
</fed:ClaimTypesOffered>
<fed:SecurityTokenServiceEndpoint>
<EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
<Address>https://idadg2.jpmorganchase.com/adfs/services/trust/2005/certificatemixed</Address>
<Metadata>
<Metadata xmlns="http://schemas.xmlsoap.org/ws/2004/09/mex" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:wsx="http://schemas.xmlsoap.org/ws/2004/09/mex">
<wsx:MetadataSection xmlns="" Dialect="http://schemas.xmlsoap.org/ws/2004/09/mex">
<wsx:MetadataReference>
<Address xmlns="http://www.w3.org/2005/08/addressing">https://idadg2.jpmorganchase.com/adfs/services/trust/mex</Address>
</wsx:MetadataReference>
</wsx:MetadataSection>
</Metadata>
</Metadata>
</EndpointReference>
</fed:SecurityTokenServiceEndpoint>
<fed:PassiveRequestorEndpoint>
<EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
<Address>https://idadg2.jpmorganchase.com/adfs/ls/</Address>
</EndpointReference>
</fed:PassiveRequestorEndpoint>
</RoleDescriptor>
<SPSSODescriptor WantAssertionsSigned="true" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<KeyDescriptor use="encryption">
<KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
<X509Data>
<X509Certificate>MIIDRDCCAiygAwIBAgIQGsKwHcVMYIdPQqb6PKFNqDANBgkqhkiG9w0BAQsFADA1MTMwMQYDVQQDDCpBREZTIEVuY3J5cHRpb24gLSBpZGFkZzIuanBtb3JnYW5jaGFzZS5jb20wHhcNMjUwNzAzMTI0NTExWhcNMjcwNzAzMTI0NTExWjA1MTMwMQYDVQQDDCpBREZTIEVuY3J5cHRpb24gLSBpZGFkZzIuanBtb3JnYW5jaGFzZS5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCcSrwvUkKJ06dGNBWRy1WlrD4oQtPm0TlTkJlJdhmlTNtGZzUZFVwFIOfQrV1Ry1qFvbI58hDsOcjgIYQ+SM+KGZg3nq3hgVLBcOWkl3kmN8AMexNGAkif3scRqOS8jnenOWkFSor3d2abQE+3Sf80QhW23HIZanvMpQgDeX4tMg+Rz33JgUtXIWg805xoZmmKgAFaiql7nnjmvJ/EOJDaKkFVsgG3yjx3T0n88c7nTgS36vgUkWgfrZjbrydW//Jw5fO1sItt1yx/r8a0ZDRYcOZz42Y1nP6X0WwKPXhJa1I8VeiTyn+383rpFgglHifiOBRBIPPgLP79i54aKpHVAgMBAAGjUDBOMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFPZEyUfpQRp8vHfoqY3eTvWTskXSMA0GCSqGSIb3DQEBCwUAA4IBAQBRTqldOdDTmNDCGYG39zdmE3Viq92dId49Zblfq43ZmDRlh4B4JYSxWD3TQvQoaiKePMc/kj5D2mXqvEuw/4uWnv0XhYm156Wb+vQNUFzFApnRkMw5bTbJ3a7ZE/499duD2v/6XmgOXjLUb4o5lCssbC9wO2A8tR+0qgQlDbk6ZWoSe4UCI20vpoUNoGk5C2oWHSjv4HQjL4uxxGJfnSAkMVFkMJEs22AB7IwHGsteM3ayhKz9reCu4CIspsixt5CZgoALJWJcguXpZBYiH7vZXxfbps4+rXuDUbiw2Cud/W2hpqhcXKUYUENIRSgEgjF/uQ/n+XdWNlu0Ff5OtO8e</X509Certificate>
</X509Data>
</KeyInfo>
</KeyDescriptor>
<KeyDescriptor use="signing">
<KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
<X509Data>
<X509Certificate>MIIDPjCCAiagAwIBAgIQTaHJ7I2WPY9DDxQXyv8pbDANBgkqhkiG9w0BAQsFADAyMTAwLgYDVQQDDCdBREZTIFNpZ25pbmcgLSBpZGFkZzIuanBtb3JnYW5jaGFzZS5jb20wHhcNMjUwNjE5MTI0NTA4WhcNMjcwNjE5MTI0NTA4WjAyMTAwLgYDVQQDDCdBREZTIFNpZ25pbmcgLSBpZGFkZzIuanBtb3JnYW5jaGFzZS5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDZFH7sPdjjpPXmE+3lCrRFjso5IMXWopFyZ4JUtnl4+S877xyMMXOLxX/gfXAIzR+V/NVZpdsXHY15PAexFD6ar8oTJXfDke1H4M35V8fJ7QBWl7I/svPSqgZsFBU1FsM4Gu0gJpH42cmxrfOS0sII9ExRSzfbWHUyV+j7YPXaydbLxl9d94gpazlXfE++pFaM5a6BYruf8KQKXjjK/onxwgxdFpkx9PcDTw3cjHIPPN4Ooka5h8V+Zo6COLhq+q0O6D+DYRmXbYGzwm/Uf1lBvjXviDN3koRylmjK45Af98lRD9YCmKqbWinbgMg9vp+hr72ccxyZr0JRbIuTWh6xAgMBAAGjUDBOMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFL64+BoAtH+jlTSRJ5HErT6rggb4MA0GCSqGSIb3DQEBCwUAA4IBAQBw3Ye2y8DLDJ/bp6wgTkllmq/jbHqSRqWWPdLAb1pB1SMANn5aDgrRzYuOr6qcaeWhCgBA1eZI5fkcx6tsrNjHefeZvM3Mr2ubsdXBRdbsGDK4436ZuHi5EebpVJDhQM9KdvAs03kJjuqXAt+srU4m9l5osNgDpFKTYShQ4DQ1i7Zet6etPZHpcM7mw1v/nzG3Z59/Vo7d0+Qs2Ctijo+4Tl11iBhUOXj89LsgSF3gA43VunMBINj3OohMTGeVBxBuRxrohd9dAwrNjYWTo8UGkNoDkx7BkDtk6iIacdr3XvI2Q5UYfj9A+TR0qCjwVqFHW7suCT/S4jkiQRgJx4tS</X509Certificate>
</X509Data>
</KeyInfo>
</KeyDescriptor>
<KeyDescriptor use="signing">
<KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
<X509Data>
<X509Certificate>MIIDPjCCAiagAwIBAgIQIobBuvMfjZJJs5M30rFd5TANBgkqhkiG9w0BAQsFADAyMTAwLgYDVQQDDCdBREZTIFNpZ25pbmcgLSBpZGFkZzIuanBtb3JnYW5jaGFzZS5jb20wHhcNMjUwNzAzMTI0NTExWhcNMjcwNzAzMTI0NTExWjAyMTAwLgYDVQQDDCdBREZTIFNpZ25pbmcgLSBpZGFkZzIuanBtb3JnYW5jaGFzZS5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDCKvI63/RdJRulTi2Jm1QVRzkFZds8Gxx9wXpJAE0vckMF6l5CPKraoIFKjztwk0UM/078OfXGY2KGWbv5tsDP2vV0+VgPgUgrRScP0Hu3hMahwIC2QhalxrUqZM54htRsrU+6jXDJpjXXKUUZNnvvMqOzXWgSZ/ssHkhqURc/IXtEiAFsj3L3KviJ4q4pvRa5eZ2RWfoP3K0+PKFeo0w1n6Xc14ChO8oM1ZVw6GGHfs/qs/49f+7gyll6iJLl5Zy0vhaZCr5qSLZaq8U7zzZZhrFnVT67VNMMkGbs3MdOOVs+b6PtfBlVfQqrwhXLzzVr4MqX2GgmhDptiuR+4HCFAgMBAAGjUDBOMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFNYtVU0cPtvMyGCo+9vvxJsly3BYMA0GCSqGSIb3DQEBCwUAA4IBAQBbqLu7H7eUJA1cdGBTiRktlFh5KtcrjHEk6eayHgtcwpH0vS4DVGGpAqpp0KAzWqfQmcuZOe3382jczXODYqhISZuIIcG07PUvZRmiDbUqAHwC8oxwfwQzsUkfyJmd3wHDDSFrIkbih+Gg+SFl/wOdHLrSvdMl7qn7ev1If/hUHauCHFejig0I3S0bTNGarYCXKlYanKUBelWz6o8MyMk2kDbEjubgbmsCRs2Zr8mTst/cE7U97nwWPoqFKM01xcs+OFuk6Ysy07SVQ46V2OEbm9ZGOtYvsuqyI4bNGBi2VDmvtXQkHAvADElqSdsJ/MpooI10/481QnKbLI7IWlCq</X509Certificate>
</X509Data>
</KeyInfo>
</KeyDescriptor>
<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idadg2.jpmorganchase.com/adfs/ls/"/>
<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idadg2.jpmorganchase.com/adfs/ls/"/>
<NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</NameIDFormat>
<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>
<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
<AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idadg2.jpmorganchase.com/adfs/ls/" index="0" isDefault="true"/>
<AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://idadg2.jpmorganchase.com/adfs/ls/" index="1"/>
<AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idadg2.jpmorganchase.com/adfs/ls/" index="2"/>
</SPSSODescriptor>
<IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<KeyDescriptor use="encryption">
<KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
<X509Data>
<X509Certificate>MIIDRDCCAiygAwIBAgIQGsKwHcVMYIdPQqb6PKFNqDANBgkqhkiG9w0BAQsFADA1MTMwMQYDVQQDDCpBREZTIEVuY3J5cHRpb24gLSBpZGFkZzIuanBtb3JnYW5jaGFzZS5jb20wHhcNMjUwNzAzMTI0NTExWhcNMjcwNzAzMTI0NTExWjA1MTMwMQYDVQQDDCpBREZTIEVuY3J5cHRpb24gLSBpZGFkZzIuanBtb3JnYW5jaGFzZS5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCcSrwvUkKJ06dGNBWRy1WlrD4oQtPm0TlTkJlJdhmlTNtGZzUZFVwFIOfQrV1Ry1qFvbI58hDsOcjgIYQ+SM+KGZg3nq3hgVLBcOWkl3kmN8AMexNGAkif3scRqOS8jnenOWkFSor3d2abQE+3Sf80QhW23HIZanvMpQgDeX4tMg+Rz33JgUtXIWg805xoZmmKgAFaiql7nnjmvJ/EOJDaKkFVsgG3yjx3T0n88c7nTgS36vgUkWgfrZjbrydW//Jw5fO1sItt1yx/r8a0ZDRYcOZz42Y1nP6X0WwKPXhJa1I8VeiTyn+383rpFgglHifiOBRBIPPgLP79i54aKpHVAgMBAAGjUDBOMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwHQYDVR0OBBYEFPZEyUfpQRp8vHfoqY3eTvWTskXSMA0GCSqGSIb3DQEBCwUAA4IBAQBRTqldOdDTmNDCGYG39zdmE3Viq92dId49Zblfq43ZmDRlh4B4JYSxWD3TQvQoaiKePMc/kj5D2mXqvEuw/4uWnv0XhYm156Wb+vQNUFzFApnRkMw5bTbJ3a7ZE/499duD2v/6XmgOXjLUb4o5lCssbC9wO2A8tR+0qgQlDbk6ZWoSe4UCI20vpoUNoGk5C2oWHSjv4HQjL4uxxGJfnSAkMVFkMJEs22AB7IwHGsteM3ayhKz9reCu4CIspsixt5CZgoALJWJcguXpZBYiH7vZXxfbps4+rXuDUbiw2Cud/W2hpqhcXKUYUENIRSgEgjF/uQ/n+XdWNlu0Ff5OtO8e</X509Certificate>
</X509Data>
</KeyInfo>
</KeyDescriptor>
<KeyDescriptor use="signing">
<KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
<X509Data>
<X509Certificate>MIIDVjCCAj4CCQDPCz91+8Oo2TANBgkqhkiG9w0BAQsFADBtMQswCQYDVQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTEWMBQGA1UEBwwNU2FuIEZyYW5jaXNjbzEQMA4GA1UECgwHSmFua3lDbzEfMB0GA1UEAwwWVGVzdCBJZGVudGl0eSBQcm92aWRlcjAeFw0yNTA2MjgwMzU4NDdaFw00NTA2MjMwMzU4NDdaMG0xCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRAwDgYDVQQKDAdKYW5reUNvMR8wHQYDVQQDDBZUZXN0IElkZW50aXR5IFByb3ZpZGVyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw6NsxtaC5F0oDygZO6DOjopprdl4t2YErKJS8haCrJdWvYTIQG5UHFMLfgq4APoEQbVJm6rV4Z5kjxbQvXkkLyKcMJfwkscMuR/Gquih08zKKCRmeLbqUOhwDx+Zamlvh1Ll7ffFIA3pmAAUCrN3TYdgvzOCg/wbhkEgRYhjCXEmJGdCkPEfOiTatmxZ5Uft441e0aSyyx0D/wOSOJcR1FOQliPgM3PFJKZjlhlACzu5O5l/2ntPBbmU7IfjM4Qjpln16ArXRbRyXIHPsyge/rXJo3HwOOoEdK4nARvZEGw4/xBu/o43im6rK2RmJV10hgAw/S27ocREbOWGOy/IAwIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA0YY9yxwcFY4kwvnkJu3ZG6BdbTXx4LLnyInJTU10UYEI9WjJzGHJ1pWvKO8xFqfUM8FsHlxksaW3ayCVQO9K2cqaq84qkmS0JokkhkKo6gA434a0ExY++w9eRXy3/dCmkCWYT9+4BOc1BrY69Jt9PvamUpZLFzI/oj0Eg4ORGuoJPEq2186ziexfi1MOoCequFkjBYTIyK3y3mfjUckw6iX8oX6J40ciBACqXvw/T27zVRsH4THCv5XkKLsXIsvEHNhoSVLAcBhkR31oO2txN7/txibmxWIGiBB8+if1cNd+b3ce3jfvb1Qv5JgdeJU/R3LtZLEYjqFYlpzHtuRAN</X509Certificate>
</X509Data>
</KeyInfo>
</KeyDescriptor>
<KeyDescriptor use="signing">
<KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
<X509Data>
<X509Certificate>MIIDzTCCArWgAwIBAgIUEOmLajxiCXOUIvFRR4UUCU55jnMwDQYJKoZIhvcNAQELBQAwdjELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFjAUBgNVBAcMDVNhbiBGcmFuY2lzY28xEDAOBgNVBAoMB0phbmt5Q28xKDAmBgNVBAMMH1Rlc3QgSWRlbnRpdHkgUHJvdmlkZXIgUm9sbG92ZXIwHhcNMjUwNzE0MTYwNzI0WhcNNDUwNzA5MTYwNzI0WjB2MQswCQYDVQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTEWMBQGA1UEBwwNU2FuIEZyYW5jaXNjbzEQMA4GA1UECgwHSmFua3lDbzEoMCYGA1UEAwwfVGVzdCBJZGVudGl0eSBQcm92aWRlciBSb2xsb3ZlcjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANOzyDkY5Iz3Sh14rbfCqEkBHuwJvgeqkuv9fystVCJLIK79W/+fECOXjPMpZuBR7Qm4LZ/dHl1MSMZ/1lh4Oa7R3Ui4Oq1zMDON4HkgZJKxXXHb1WtPFbg+0XeVymJd/UvAGYJ+pUETgtqvc5kzmHYTOOG7SZwz9AZYlhzFzn51Gik+UwnGwTt0iapY9z+f+wfitnfFiBzqN41LQK20UUF4+nJFcn5zyshQwbqBX2azZrVKxNG3ZNTmBNQQdxkoAuLJVO+jOe5v11PKx18fcE3QmkpFsZEr3bQkdg04/+jVSpfX00O43JvUiZSnE+bgfXQhQMZa6PNPA7LIe6Ezpr0CAwEAAaNTMFEwHQYDVR0OBBYEFKJ8rut6eb/vzbzLEE6pAsS6aD0MMB8GA1UdIwQYMBaAFKJ8rut6eb/vzbzLEE6pAsS6aD0MMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBALA7H81rYfFXTZ6HbRjSfoJXyVGqnF+lFUIxK90S/cEDcycXTT7SaYwGF3DWTmPxGXrI9WCQA4avIgVbAs7o5DrMmAcwtju4fS+eq2ThFEqneGK1EukUiDeh3joOjLBO2rR7q8RktnUiGJeZRKtgEdJ2jd9q36gBMA9uj35ACqHQqEdJHd8KP6smrcqbhR2mKqhb9PpDvhFDCKNtS83kEQuahC+1WZUt529SVR7YvPdxXYMXliR9lxeagA9noB8lgJhu81/Z5kD8WwmHuZkzfCPELVXLM3JO2EoNTtbC1o7Kjee47YWu/qJqLIbMzgq7dbdLe13QdOmj1KHEKjY7u2g=</X509Certificate>
</X509Data>
</KeyInfo>
</KeyDescriptor>
<ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idadg2.jpmorganchase.com/adfs/services/trust/artifactresolution" index="0"/>
<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idadg2.jpmorganchase.com/adfs/ls/"/>
<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idadg2.jpmorganchase.com/adfs/ls/"/>
<NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</NameIDFormat>
<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat>
<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
<SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idadg2.jpmorganchase.com/adfs/ls/"/>
<SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idadg2.jpmorganchase.com/adfs/ls/"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="E-Mail Address"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Given Name"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Name"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="UPN"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/claims/CommonName" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Common Name"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/claims/EmailAddress" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="AD FS 1.x E-Mail Address"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/claims/Group" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Group"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/claims/UPN" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="AD FS 1.x UPN"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/role" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Role"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Surname"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/privatepersonalidentifier" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="PPID"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Name ID"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Authentication time stamp"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Authentication method"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/denyonlysid" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Deny only group SID"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarysid" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Deny only primary SID"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarygroupsid" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Deny only primary group SID"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Group SID"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/primarygroupsid" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Primary group SID"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Primary SID"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Windows account name"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/01/devicecontext/claims/isregistereduser" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Is Registered User"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/01/devicecontext/claims/identifier" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Device Identifier"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/01/devicecontext/claims/registrationid" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Device Registration Identifier"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/01/devicecontext/claims/displayname" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Device Registration DisplayName"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/01/devicecontext/claims/ostype" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Device OS type"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/01/devicecontext/claims/osversion" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Device OS Version"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/01/devicecontext/claims/ismanaged" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Is Managed Device"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-forwarded-client-ip" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Forwarded Client IP"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-client-application" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Client Application"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-client-user-agent" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Client User Agent"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-client-ip" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Client IP"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-endpoint-absolute-path" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Endpoint Path"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-proxy" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Proxy"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/01/requestcontext/claims/relyingpartytrustid" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Application Identifier"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/12/certificatecontext/extension/applicationpolicy" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Application policies"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/12/certificatecontext/extension/authoritykeyidentifier" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Authority Key Identifier"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/12/certificatecontext/extension/basicconstraints" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Basic Constraint"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/12/certificatecontext/extension/eku" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Enhanced Key Usage"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/12/certificatecontext/field/issuer" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Issuer"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/12/certificatecontext/field/issuername" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Issuer Name"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/12/certificatecontext/extension/keyusage" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Key Usage"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/12/certificatecontext/field/notafter" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Not After"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/12/certificatecontext/field/notbefore" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Not Before"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/12/certificatecontext/extension/certificatepolicy" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Certificate Policies"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/rsa" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Public Key"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/12/certificatecontext/field/rawdata" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Certificate Raw Data"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/12/certificatecontext/extension/san" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Subject Alternative Name"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/serialnumber" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Serial Number"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/12/certificatecontext/field/signaturealgorithm" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Signature Algorithm"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/12/certificatecontext/field/subject" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Subject"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/12/certificatecontext/extension/subjectkeyidentifier" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Subject Key Identifier"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/12/certificatecontext/field/subjectname" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Subject Name"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/12/certificatecontext/extension/certificatetemplateinformation" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="V2 Template Name"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/12/certificatecontext/extension/certificatetemplatename" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="V1 Template Name"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/thumbprint" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Thumbprint"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/12/certificatecontext/field/x509version" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="X.509 Version"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2012/01/insidecorporatenetwork" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Inside Corporate Network"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2012/01/passwordexpirationtime" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Password Expiration Time"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2012/01/passwordexpirationdays" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Password Expiration Days"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2012/01/passwordchangeurl" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Update Password URL"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/claims/authnmethodsreferences" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Authentication Methods References"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/2012/01/requestcontext/claims/client-request-id" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Client Request ID"/>
<Attribute xmlns="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2013/11/alternateloginid" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Alternate Login ID"/>
</IDPSSODescriptor>
<ContactPerson contactType="support">
<EmailAddress/>
<TelephoneNumber/>
</ContactPerson>
</EntityDescriptor>