<?xml version="1.0" encoding="utf-8"?>
<samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" ID="identifier_1" InResponseTo="identifier_1" Version="2.0" IssueInstant="2004-12-05T09:22:05Z" Destination="https://sp.example.com/SAML2/SSO/POST">
<saml:Issuer>https://idp.example.org/SAML2</saml:Issuer>
<samlp:Status>
<samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
</samlp:Status>
<saml:Assertion xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" ID="identifier_2" Version="2.0" IssueInstant="2004-12-05T09:22:05Z">
<saml:Issuer>https://idp.example.org/SAML2</saml:Issuer>
<!-- a POSTed assertion MUST be signed -->
<saml:Subject>
<saml:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient">
3f7b3dcf-1674-4ecd-92c8-1544f346baf8
</saml:NameID>
<saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
<saml:SubjectConfirmationData InResponseTo="identifier_1" Recipient="https://sp.example.com/SAML2/SSO/POST" NotOnOrAfter="2004-12-05T09:27:05Z"/>
</saml:SubjectConfirmation>
</saml:Subject>
<saml:Conditions NotBefore="2004-12-05T09:17:05Z" NotOnOrAfter="2004-12-05T09:27:05Z">
<saml:AudienceRestriction>
<saml:Audience>https://sp.example.com/SAML2</saml:Audience>
</saml:AudienceRestriction>
</saml:Conditions>
<saml:AuthnStatement AuthnInstant="2004-12-05T09:22:00Z" SessionIndex="identifier_3">
<saml:AuthnContext>
<saml:AuthnContextClassRef>
urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport
</saml:AuthnContextClassRef>
</saml:AuthnContext>
</saml:AuthnStatement>
<dsig:Signature>
<dsig:SignedInfo xmlns:xenc="http://www.w3.org/2001/04/xmlenc#">
<dsig:CanonicalizationMethod Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n-20010315#WithComments"/>
<dsig:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
<dsig:Reference URI="#identifier_2">
<dsig:Transforms>
<dsig:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<dsig:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
</dsig:Transforms>
<dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
<dsig:DigestValue>WHNwnt7MBsBUujGCiQUCQKV60Y0=</dsig:DigestValue>
</dsig:Reference>
</dsig:SignedInfo>
<dsig:SignatureValue>PnEOz3n0wQnNEXIZUvwHyprg6Xs4qobuAkFsMWqd+2KzK7xqlbr+evydmeT35hfXSbtNzLlU7Mq3
ALnWzpY+rmnCt09mGKIbFfvs9Uf2AI0+vZWv3qdJ3/RxfcIAazX1FTk3aQbWBBNKPweYGVdsgSff
/U1eToPxWPM4iAzCCU0DG7TLOCstXUbqldvaYmn/aQ6MGKa0RrpGAOqyMEPz0M+yk2YCQB1JWNa9
wjiPcGTBxH7B4+84zFBRgPC7tMCX8HoTDUjm32QPN38tcimL5UY7emBXe580O0+WpNrnykS7lKZJ
IfRqydSPrQrwSxV61tX4ip2mUli4RxG/+h5LSA==
</dsig:SignatureValue>
<dsig:KeyInfo><dsig:X509Data><dsig:X509Certificate>
MIIFuDCCA6CgAwIBAgICEAIwDQYJKoZIhvcNAQELBQAwezELMAkGA1UEBhMCQ0Ex
FjAUBgNVBAgMDU5ldyBCcnVuc3dpY2sxHTAbBgNVBAoMFENyeXB0LU9wZW5TU0wt
VmVyaWZ5MTUwMwYDVQQDDCxDcnlwdC1PcGVuU1NMLVZlcmlmeSBTSEEtMjU2IElu
dGVybWVkaWF0ZSBDQTAeFw0yMDA2MDMwMjM4MjJaFw0yMTA2MTMwMjM4MjJaMGcx
CzAJBgNVBAYTAkNBMRYwFAYDVQQIDA1OZXcgQnJ1bnN3aWNrMRAwDgYDVQQHDAdN
b25jdG9uMRAwDgYDVQQKDAdYTUwtU2lnMRwwGgYDVQQDDBN4bWwtc2lnLmV4YW1w
bGUuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArkqxhCTOB2Xx
FxCNWJt0bLWRQva6qOAPKiqlLfgJjG+YY2JaPtpO7WNV5oVqv9F21V/wgOkcQTZZ
QQQl/L/eXlnFpJeSpF31dupLnzrBU29qWjedNCkj+y01sprJG+c++2d2jV8Qccp5
5SklALtXYZ3K5OfILy4dFEqUyW0/Bk7Y/PdrAacAazumdNW2nw/ajbiXbUfm55Qe
bQd/61emGettQBT9EUPOxMQrrtxHHxwyvrtsa9KyRPCamYEamOA0Al2Eya5dPWzE
bndbVpRx1jz8Ec6ANk8wJHTkggJOUXWem7HL4x8v9hEQeaHEy5CwxKzodDpV2bA/
Adr+NCYhsQIDAQABo4IBWDCCAVQwCQYDVR0TBAIwADARBglghkgBhvhCAQEEBAMC
BkAwMwYJYIZIAYb4QgENBCYWJE9wZW5TU0wgR2VuZXJhdGVkIFNlcnZlciBDZXJ0
aWZpY2F0ZTAdBgNVHQ4EFgQUDYY0sUvDD+ttN7MKzQzVgg25D94wgboGA1UdIwSB
sjCBr4AUzVMiKnV2P0l/W5nowtx2oIRM0S2hgZKkgY8wgYwxCzAJBgNVBAYTAkNB
MRYwFAYDVQQIDA1OZXcgQnJ1bnN3aWNrMRAwDgYDVQQHDAdNb25jdG9uMR0wGwYD
VQQKDBRDcnlwdC1PcGVuU1NMLVZlcmlmeTE0MDIGA1UEAwwrQ3J5cHQtT3BlblNT
TC1WZXJpZnkgU0hBLTI1NiBSb290IEF1dGhvcml0eYICEAAwDgYDVR0PAQH/BAQD
AgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMBMA0GCSqGSIb3DQEBCwUAA4ICAQA/unU2
cUwoXZ1S4U/vY++ZIRDuzO3MB6o1zE4SrDExAHkxbKvtkbEAe8RnaCKjNpPcJUls
8qTWnB91DmyvBAI4V2l81bu8X2+HoBwK8YMn9+/mPVHBWfhhFuNZmDfAn7r2fA5o
rPZda9aw1IkH2KU4dl0lVAQdCDiDP3pow9+LQw/CRouqSsDwD4AepRVfgL0oaR/c
GoJJ94A4vEq2KMk3s8fke/wY5vSPyTEZfOdjkeMeHyl94MP3ntftArVmTN9I9Ge2
jcr4+c19buluYUDm0uS0LmIU+EqrtVKe81Vfo1Yw3gfZaMu6QPh0x3t11g9IDjVP
SG+Hv2YDtv6kvq0n/wR2rugIS/4MkKCIX7s4iphZ1gn6VD1ioG73YIidTCLlhwN6
hQi47lefGJ0tHMBrTqdUlJzwrYI7dAA+k/gHmautaAwgxGOsOrh0jR0i6IduPveE
2RDYQ1o07Bs9it0nJKOwZJxu7lYCrCCkumEyJsRrtutFfVNs0NJ6oYHPUwBtMp5x
guwuWkGWaDjeWZqPWSM5dB9RGCabiSC6/wiV6euKx99pBXKxEm5hjwIbAw3FZDJv
rtSTf7mzMXCplGYhk7pW+b0faYo9yR3Bt41klT3ynReHNfxfdT+Md2SPUn6zoEPE
zCtB4QhckJIeDQmaChU08zKMPU2d080HsjLYyw==
</dsig:X509Certificate></dsig:X509Data></dsig:KeyInfo>
</dsig:Signature></saml:Assertion>
<dsig:Signature>
<dsig:SignedInfo xmlns:xenc="http://www.w3.org/2001/04/xmlenc#">
<dsig:CanonicalizationMethod Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n-20010315#WithComments"/>
<dsig:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
<dsig:Reference URI="#identifier_1">
<dsig:Transforms>
<dsig:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<dsig:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
</dsig:Transforms>
<dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
<dsig:DigestValue>MMATGDLt1nwo9bLT5pgkdPTHHxY=</dsig:DigestValue>
</dsig:Reference>
</dsig:SignedInfo>
<dsig:SignatureValue>UoeieeRUkdQzqf1ZzQqFn94Zod3HYprC/Bt0PO21CH0XjyjpPMNRklwvPieuoNZpAI5yPAweHo92
TnUhosDcujZIQeY3/+owdhJcx5dZOobi3BuFi8f1kfXCQiXyFSv+iJYGiT0B77GuhwJODhyc1tuu
SeuQYmQpmn+r6m5G2yxQ/myT2IxPTuR6+21LIX61AXIUekh7KEhJAkW+VnVbAHePO9BA/jPDhI8Z
1IzUKVuqrx9ep//8fW+QPzU8TrQwj7s2/GiBNe9DxOfhsyV3GSmKFbFaM7N5Y6WYZ0al3ho//4Pu
zBkHlnjBbo6IFMrlymkbRP5ThfF6w5POoxEwkg==
</dsig:SignatureValue>
<dsig:KeyInfo><dsig:X509Data><dsig:X509Certificate>
MIIFuDCCA6CgAwIBAgICEAIwDQYJKoZIhvcNAQELBQAwezELMAkGA1UEBhMCQ0Ex
FjAUBgNVBAgMDU5ldyBCcnVuc3dpY2sxHTAbBgNVBAoMFENyeXB0LU9wZW5TU0wt
VmVyaWZ5MTUwMwYDVQQDDCxDcnlwdC1PcGVuU1NMLVZlcmlmeSBTSEEtMjU2IElu
dGVybWVkaWF0ZSBDQTAeFw0yMDA2MDMwMjM4MjJaFw0yMTA2MTMwMjM4MjJaMGcx
CzAJBgNVBAYTAkNBMRYwFAYDVQQIDA1OZXcgQnJ1bnN3aWNrMRAwDgYDVQQHDAdN
b25jdG9uMRAwDgYDVQQKDAdYTUwtU2lnMRwwGgYDVQQDDBN4bWwtc2lnLmV4YW1w
bGUuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArkqxhCTOB2Xx
FxCNWJt0bLWRQva6qOAPKiqlLfgJjG+YY2JaPtpO7WNV5oVqv9F21V/wgOkcQTZZ
QQQl/L/eXlnFpJeSpF31dupLnzrBU29qWjedNCkj+y01sprJG+c++2d2jV8Qccp5
5SklALtXYZ3K5OfILy4dFEqUyW0/Bk7Y/PdrAacAazumdNW2nw/ajbiXbUfm55Qe
bQd/61emGettQBT9EUPOxMQrrtxHHxwyvrtsa9KyRPCamYEamOA0Al2Eya5dPWzE
bndbVpRx1jz8Ec6ANk8wJHTkggJOUXWem7HL4x8v9hEQeaHEy5CwxKzodDpV2bA/
Adr+NCYhsQIDAQABo4IBWDCCAVQwCQYDVR0TBAIwADARBglghkgBhvhCAQEEBAMC
BkAwMwYJYIZIAYb4QgENBCYWJE9wZW5TU0wgR2VuZXJhdGVkIFNlcnZlciBDZXJ0
aWZpY2F0ZTAdBgNVHQ4EFgQUDYY0sUvDD+ttN7MKzQzVgg25D94wgboGA1UdIwSB
sjCBr4AUzVMiKnV2P0l/W5nowtx2oIRM0S2hgZKkgY8wgYwxCzAJBgNVBAYTAkNB
MRYwFAYDVQQIDA1OZXcgQnJ1bnN3aWNrMRAwDgYDVQQHDAdNb25jdG9uMR0wGwYD
VQQKDBRDcnlwdC1PcGVuU1NMLVZlcmlmeTE0MDIGA1UEAwwrQ3J5cHQtT3BlblNT
TC1WZXJpZnkgU0hBLTI1NiBSb290IEF1dGhvcml0eYICEAAwDgYDVR0PAQH/BAQD
AgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMBMA0GCSqGSIb3DQEBCwUAA4ICAQA/unU2
cUwoXZ1S4U/vY++ZIRDuzO3MB6o1zE4SrDExAHkxbKvtkbEAe8RnaCKjNpPcJUls
8qTWnB91DmyvBAI4V2l81bu8X2+HoBwK8YMn9+/mPVHBWfhhFuNZmDfAn7r2fA5o
rPZda9aw1IkH2KU4dl0lVAQdCDiDP3pow9+LQw/CRouqSsDwD4AepRVfgL0oaR/c
GoJJ94A4vEq2KMk3s8fke/wY5vSPyTEZfOdjkeMeHyl94MP3ntftArVmTN9I9Ge2
jcr4+c19buluYUDm0uS0LmIU+EqrtVKe81Vfo1Yw3gfZaMu6QPh0x3t11g9IDjVP
SG+Hv2YDtv6kvq0n/wR2rugIS/4MkKCIX7s4iphZ1gn6VD1ioG73YIidTCLlhwN6
hQi47lefGJ0tHMBrTqdUlJzwrYI7dAA+k/gHmautaAwgxGOsOrh0jR0i6IduPveE
2RDYQ1o07Bs9it0nJKOwZJxu7lYCrCCkumEyJsRrtutFfVNs0NJ6oYHPUwBtMp5x
guwuWkGWaDjeWZqPWSM5dB9RGCabiSC6/wiV6euKx99pBXKxEm5hjwIbAw3FZDJv
rtSTf7mzMXCplGYhk7pW+b0faYo9yR3Bt41klT3ynReHNfxfdT+Md2SPUn6zoEPE
zCtB4QhckJIeDQmaChU08zKMPU2d080HsjLYyw==
</dsig:X509Certificate></dsig:X509Data></dsig:KeyInfo>
</dsig:Signature></samlp:Response>