<?xml version="1.0" encoding="UTF-8" standalone="no"?><!--
	U K   F E D E R A T I O N   M E T A D A T A

	Aggregate built 2026-04-08T15:00:27Z

	Aggregate valid for 21 days, until 2026-04-29T15:00:27Z
-->
<EntitiesDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:elab="http://eduserv.org.uk/labels" xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" xmlns:ukfedlabel="http://ukfederation.org.uk/2006/11/label" xmlns:wayf="http://sdss.ac.uk/2006/06/WAYF" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" ID="uk20100825T175806Z" Name="http://ukfederation.org.uk" validUntil="2010-09-08T17:58:06Z" xsi:schemaLocation="urn:oasis:names:tc:SAML:2.0:metadata sstc-saml-schema-metadata-2.0.xsd   urn:mace:shibboleth:metadata:1.0 shibboleth-metadata-1.0.xsd   http://www.w3.org/2001/04/xmlenc# xenc-schema.xsd   http://www.w3.org/2000/09/xmldsig# xmldsig-core-schema.xsd">
  <EntityDescriptor ID="uk002718" entityID="https://fed.nusextra.co.uk/shibboleth">
    <ContactPerson contactType="support">
      <EmailAddress>mailto:enquiries@nusextra.co.uk</EmailAddress>
      <GivenName>Enquiries</GivenName>
    </ContactPerson>
    <ContactPerson contactType="technical">
      <EmailAddress>mailto:enquiries@nusextra.co.uk</EmailAddress>
      <GivenName>Enquiries</GivenName>
    </ContactPerson>
    <Extensions>
      <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512" />
      <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384" />
      <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" />
      <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224" />
      <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1" />
      <mdrpi:RegistrationInfo registrationAuthority="http://ukfederation.org.uk" registrationInstant="2015-05-14T10:18:20Z">
        <mdrpi:RegistrationPolicy xml:lang="en">http://ukfederation.org.uk/doc/mdrps-20130902</mdrpi:RegistrationPolicy>
      </mdrpi:RegistrationInfo>
    </Extensions>
    <Organization>
      <OrganizationDisplayName xml:lang="en">NUS Services Limited</OrganizationDisplayName>
      <OrganizationName xml:lang="en">NUS Services Limited</OrganizationName>
      <OrganizationURL xml:lang="en">http://www.nus.org.uk/</OrganizationURL>
    </Organization>
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol">
      <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://fed.nusextra.co.uk/Shibboleth.sso/Artifact/SOAP" index="1" />
      <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://fed.nusextra.co.uk/Shibboleth.sso/SAML2/POST" index="1" />
      <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://fed.nusextra.co.uk/Shibboleth.sso/SAML2/POST-SimpleSign" index="2" />
      <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://fed.nusextra.co.uk/Shibboleth.sso/SAML2/Artifact" index="3" />
      <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://fed.nusextra.co.uk/Shibboleth.sso/SAML2/ECP" index="4" />
      <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://fed.nusextra.co.uk/Shibboleth.sso/SAML/POST" index="5" />
      <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://fed.nusextra.co.uk/Shibboleth.sso/SAML/Artifact" index="6" />
      <Extensions>
        <init:RequestInitiator Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://fed.nusextra.co.uk/Shibboleth.sso/Login" />
        <mdui:UIInfo>
          <mdui:Description xml:lang="en">To be eligible for the NUS extra student discount card, you need to be over 16 years of age, and in full or part time education</mdui:Description>
          <mdui:DisplayName xml:lang="en">NUS extra Student Discount card</mdui:DisplayName>
          <mdui:Logo height="61" width="143">https://cards.nusextra.co.uk/media/images/nhs-rb-extra-logo-blue.png</mdui:Logo>
        </mdui:UIInfo>
      </Extensions>
      <KeyDescriptor>
        <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm" />
        <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm" />
        <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm" />
        <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc" />
        <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc" />
        <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc" />
        <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc" />
        <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep" />
        <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p" />
        <ds:KeyInfo>
          <ds:X509Data>
            <ds:X509Certificate>
  						MIIC6zCCAdOgAwIBAgIJAJgeZ2sQotvlMA0GCSqGSIb3DQEBBQUAMBcxFTATBgNV
  						BAMTDG51c2V4dHJhd2ViMzAeFw0xNDA3MjIxMTI1MTJaFw0yNDA3MTkxMTI1MTJa
  						MBcxFTATBgNVBAMTDG51c2V4dHJhd2ViMzCCASIwDQYJKoZIhvcNAQEBBQADggEP
  						ADCCAQoCggEBAKsOIQgV+O4ecSpfdT4Xo4wosGJAPFe5Rq7NMw+qdvsNShKwaZAb
  						kPIGk1GsQMsg732uHiWvWGjGV254NV4gSBWMZ/qe4itSegoFCZCYEyJ8BNy8Itoa
  						bRLoiqj5K1H98I//nSC9Og7xFENAqSES0aeh6Ye23W64ljo02iJiwnbDqerpv6Ju
  						B61vGT7U7ftQoJr31b+uz2Ia43mG+py/GJAE9T7QEtMhwB4z+D/LuM4hVDR0dYrf
  						TCfwi3TholspuWPXy67deJebRUMoAX0aUEqjFQzTDBicND7xVMkFXiQBdzApfmwA
  						6E8aV798URhz6BNUSnBpx93zbLmsI/jQsy0CAwEAAaM6MDgwFwYDVR0RBBAwDoIM
  						bnVzZXh0cmF3ZWIzMB0GA1UdDgQWBBRpBgrh5ihM16MMSNdIVA9LKq3gUDANBgkq
  						hkiG9w0BAQUFAAOCAQEAjVHxwsL4OW9jcgmCu7z7AecgF4pbCiA5wwGIXTvbqM2Q
  						cIFzgeqUjlxK+1XKEcH8vKItpqC5qFYXy4/Xe8Btl0RrTWI50sY5ZktGmqeuzHB1
  						xRgKkAgGmo49wm7z+ZpJdZBPnx3Ho9mw1OAuN60oZoy6yCD6qFAOblABIMKBVi1f
  						rjdUIVWJX8EboD0TrdwH22QWSnmdWe6WLcs0do27ul5AfkVPaf7qpoWa8viGtCCL
  						PyALH2n1WIsOiM+UnXC5JKaR6QMpRTFJkkV4aONwk9eQN0GcSHo89jQmUaU7w/wZ
  						xud/pMpwowhvQB7YgVq2uJQzBeJDKgnv9Kr6HfE0qw==
  					</ds:X509Certificate>
          </ds:X509Data>
        </ds:KeyInfo>
      </KeyDescriptor>
      <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://fed.nusextra.co.uk/Shibboleth.sso/SLO/SOAP" />
      <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://fed.nusextra.co.uk/Shibboleth.sso/SLO/Redirect" />
      <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://fed.nusextra.co.uk/Shibboleth.sso/SLO/POST" />
      <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://fed.nusextra.co.uk/Shibboleth.sso/SLO/Artifact" />
    </SPSSODescriptor>
  </EntityDescriptor>
</EntitiesDescriptor>
