<?xml version="1.0" encoding="UTF-8" standalone="no"?><!--
	U K   F E D E R A T I O N   M E T A D A T A

	Aggregate built 2026-04-08T15:00:27Z

	Aggregate valid for 21 days, until 2026-04-29T15:00:27Z
-->
<EntitiesDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:elab="http://eduserv.org.uk/labels" xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:shibmeta="urn:mace:shibboleth:metadata:1.0" xmlns:ukfedlabel="http://ukfederation.org.uk/2006/11/label" xmlns:wayf="http://sdss.ac.uk/2006/06/WAYF" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" ID="uk20100825T175806Z" Name="http://ukfederation.org.uk" validUntil="2010-09-08T17:58:06Z" xsi:schemaLocation="urn:oasis:names:tc:SAML:2.0:metadata sstc-saml-schema-metadata-2.0.xsd   urn:mace:shibboleth:metadata:1.0 shibboleth-metadata-1.0.xsd   http://www.w3.org/2001/04/xmlenc# xenc-schema.xsd   http://www.w3.org/2000/09/xmldsig# xmldsig-core-schema.xsd">
  <EntityDescriptor ID="uk004447" entityID="https://riversidecronton.cirqahosting.com/shibboleth">
    <ContactPerson contactType="support">
      <EmailAddress>mailto:support@isoxford.com</EmailAddress>
      <GivenName>The Heritage Support Desk </GivenName>
    </ContactPerson>
    <ContactPerson contactType="support">
      <EmailAddress>mailto:lee@isoxford.com</EmailAddress>
      <GivenName>Lee</GivenName>
      <SurName>Orchard</SurName>
    </ContactPerson>
    <ContactPerson contactType="technical">
      <EmailAddress>mailto:support@isoxford.com</EmailAddress>
      <GivenName>The Heritage Support Desk </GivenName>
    </ContactPerson>
    <ContactPerson contactType="technical">
      <EmailAddress>mailto:david@isoxford.com</EmailAddress>
      <GivenName>David</GivenName>
      <SurName>Salvesen</SurName>
    </ContactPerson>
    <Extensions>
      <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512" />
      <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384" />
      <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" />
      <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224" />
      <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1" />
      <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1" />
      <mdrpi:RegistrationInfo registrationAuthority="http://ukfederation.org.uk" registrationInstant="2025-07-10T10:10:33Z">
        <mdrpi:RegistrationPolicy xml:lang="en">http://ukfederation.org.uk/doc/mdrps-20130902</mdrpi:RegistrationPolicy>
      </mdrpi:RegistrationInfo>
    </Extensions>
    <Organization>
      <OrganizationDisplayName xml:lang="en">IS Oxford Ltd</OrganizationDisplayName>
      <OrganizationName xml:lang="en">IS Oxford Ltd</OrganizationName>
      <OrganizationURL xml:lang="en">https://cirqa.co.uk/</OrganizationURL>
    </Organization>
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
      <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://riversidecronton.cirqahosting.com/Shibboleth.sso/Artifact/SOAP" index="1" />
      <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://riversidecronton.cirqahosting.com/Shibboleth.sso/SAML2/POST" index="1" />
      <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://riversidecronton.cirqahosting.com/Shibboleth.sso/SAML2/POST-SimpleSign" index="2" />
      <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://riversidecronton.cirqahosting.com/Shibboleth.sso/SAML2/Artifact" index="3" />
      <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://riversidecronton.cirqahosting.com/Shibboleth.sso/SAML2/ECP" index="4" />
      <Extensions>
        <init:RequestInitiator Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://riversidecronton.cirqahosting.com/Shibboleth.sso/Login" />
        <mdui:UIInfo>
          <mdui:Description xml:lang="en">Riverside College Halton - Heritage Online</mdui:Description>
          <mdui:DisplayName xml:lang="en">Riverside College Halton - Heritage Online</mdui:DisplayName>
          <mdui:Logo height="75" width="120">https://riversidecronton.cirqahosting.com/Heritage/Images/logo.png</mdui:Logo>
        </mdui:UIInfo>
      </Extensions>
      <KeyDescriptor use="signing">
        <ds:KeyInfo>
          <ds:X509Data>
            <ds:X509Certificate>
  						MIIEKTCCApGgAwIBAgIUCSJgRmNwPGFc0edivFaTkmtPSaswDQYJKoZIhvcNAQEL
  						BQAwKDEmMCQGA1UEAxMdaGFsdG9uLmlzb3hmb3JkLWhvc3RpbmcubG9jYWwwHhcN
  						MjUwNTI5MDkxMDE4WhcNMzUwNTI3MDkxMDE4WjAoMSYwJAYDVQQDEx1oYWx0b24u
  						aXNveGZvcmQtaG9zdGluZy5sb2NhbDCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCC
  						AYoCggGBAN/nsjIcJIsyHT4KBIx7sZSuEbjkwdd2ZkrPC0nrHLFDvTkqNJThwV51
  						Zi415GuBu1ARukUvjozlSChf2/yO0ZFpp51dEgRxDFr2i9yk+oOPar+hHV9Wjnfc
  						oLWnBIhmpTVk/jIr0CLVSz/28v0xZwQvkt6Z4PwHy9zhjiNC5BwKqVf1MBiBMI/b
  						1f1rsiK3RY7yKKhAlgaCeRo4eWrYHWJ/EerH9Opdy9rDp7pxE7KSMWM+QvHBsVfJ
  						0y76dheQqGEVJIpe4ArAxubeLpWl2A302JmrqsRVi+OlrMvFSpz3fHAXFoBqQAdT
  						iuW7QgLQLjPb43Cw5Dtapb8/aLP3NRAP00qewaOCd7Cwksd+WUsgb3Bt96rsoOuk
  						cNQiQ04wANRCR9CfrUot3iHkOIaRIMASHvk1lwLQFQH/cG0EZhUleEarawUvSRsF
  						X3LJDpOYpf62y/V/5e6HsCIugwpxn8ElAavYRqQXoD8yBy3edLFdQZyxsfebV3/T
  						RCncojxNUwIDAQABo0swSTAoBgNVHREEITAfgh1oYWx0b24uaXNveGZvcmQtaG9z
  						dGluZy5sb2NhbDAdBgNVHQ4EFgQUTETqryZREhzxAor+JnqemzreH5kwDQYJKoZI
  						hvcNAQELBQADggGBAI/dtgjfDzlr+7COs6kt1nbscbpB8S/OYeOFF0A710ZOM8kl
  						w1/Tt04uTICEGewByHOukvHrKbMw41kSehzhbZlmIfzxXpqqRkg3yp60EBdl1j3F
  						0snZ1X+++AzJI+c+lXTQkBwO4dMVwys5JEd6FLXNlyW3mLUsM8lJMnTwfOz288ZK
  						+XF71LeCdhgdD41v6QCZMMf76m714ADVhfT6RG82pwq5G4rMYuO9OqQYa9e8HD6G
  						Yr9fFM27EYGlFBxudo/WuvBYL4+VMMs8jO3lApRGUNIfnXLfLr45lQV4aFsXu17n
  						uiDGJCgkfcKP4hNGNUZKvaEHa0Rx6DfAJcRjC7wwt56wVWvzS+yc6pkOeIAUXXrV
  						D1sGFQGu0ybUJab2X8Ut0Tg531Df7tpIQa8DlEz937bsU1KxHESIjBIqx74RnX7/
  						5YISdzjurRouSFSDn8Ggjz8GBmdk82Fh3j4NIzBblCPHUsqNZXS0OFb/aIzCoG+0
  						+ireeOkCR0aKzfopMQ==
  					</ds:X509Certificate>
          </ds:X509Data>
        </ds:KeyInfo>
      </KeyDescriptor>
      <KeyDescriptor use="encryption">
        <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm" />
        <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm" />
        <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm" />
        <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc" />
        <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc" />
        <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc" />
        <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc" />
        <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep" />
        <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p" />
        <ds:KeyInfo>
          <ds:X509Data>
            <ds:X509Certificate>
  						MIIEKTCCApGgAwIBAgIUFWYUCkV9LYHDk6PYQP4N68QUlKYwDQYJKoZIhvcNAQEL
  						BQAwKDEmMCQGA1UEAxMdaGFsdG9uLmlzb3hmb3JkLWhvc3RpbmcubG9jYWwwHhcN
  						MjUwNTI5MDkxMDE2WhcNMzUwNTI3MDkxMDE2WjAoMSYwJAYDVQQDEx1oYWx0b24u
  						aXNveGZvcmQtaG9zdGluZy5sb2NhbDCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCC
  						AYoCggGBANQJiwznEg4jzz431akxPdHOzkQpKUBokTx2E121dI6uOnhD5ofGXBgW
  						9ntXmuxAf6Cli+pjJkjf5lhv8WBCFJL2m7+XmxRjtH20SB4vffsJWy3IX0qCJttY
  						r1Anh+WKPSEojl7oMcAhR2WwIb072+7yyOZLAlSrv/nuBvXMN8LbI45lEgRcDb2Y
  						mUYzbf01l6czNteOthmwWiRmPXc9g+4MuxSf7whGKaVkchFdE6vO+XWI4rKy6/Nj
  						3kMsNzIhYcyQ2yjKgNjIQkAokPeUAxPyQ7XyWNnHxdLk9mRfVcUrGrM7Tjw0f/Nu
  						jTeapmFX/Iy8kdFYNK0Fi2qLG8kHt6f0G+RpB5co5XEusF0/sX/k8VOdX5A94kfw
  						amARFI5r8HxJCgQ1s4wqBJUbhLv87Vk0JfgConBebwy/z9Occ89SvrKxkuu0H7nX
  						I29rhJ7xfn6LN9j4jc/Z8fzUbrCfnKhBTgLMFO1uIWKBUqD0vxKA8bCF8SEAlemE
  						VvS46X2LTwIDAQABo0swSTAoBgNVHREEITAfgh1oYWx0b24uaXNveGZvcmQtaG9z
  						dGluZy5sb2NhbDAdBgNVHQ4EFgQU1NpCy1TVRkszUQmxHEA6LA2fQ6UwDQYJKoZI
  						hvcNAQELBQADggGBAHDZItk+iIaaXKrz7G4Z1RsQKNbNfOVkDj2AvvLj1n4AZikW
  						Pz41XiSEbQBkaE0dAqEZbsTOyc83K2rR0H6C4Br0UrXBZfbxR238nV5/oBNYL/gF
  						SS0VZs4IrdTktkql8TQrt7KM4leiu34xk+M+Olud8Zje82yhAsy1jIoyMKheH7j4
  						x4BAlzB3eutfSWhFdmSYBZIvZw6NIpa72d60L81e4R4NfiTtnTwkx+0UW6h2MqC8
  						9iaTRL5Nj7qV8fyqGB0sJpZmjxEO/kYltNf+lE6jNX8F5/W5wBUDnMW/ra4PI5DS
  						BmxxS+HAF58X44y7bx7YExByReXKpn2GanxPXN/KQuvhSU8D/Ukz4sDp0kd6iYkU
  						RjoWl6ZIGMjgXUoOsfKjeNKEHWvhmc0rsJHf/6XqvK5ZCF5iDjkHplsLFFSiqhJV
  						DxtSZIozj6vckoU2UW9VbTPVjtpT298skbZHFuZtSvQF4FWBTEr1Bv6GWEj7vQdA
  						cBLgAQHxRUJ+zCof1A==
  					</ds:X509Certificate>
          </ds:X509Data>
        </ds:KeyInfo>
      </KeyDescriptor>
      <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://riversidecronton.cirqahosting.com/Shibboleth.sso/SLO/SOAP" />
      <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://riversidecronton.cirqahosting.com/Shibboleth.sso/SLO/Redirect" />
      <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://riversidecronton.cirqahosting.com/Shibboleth.sso/SLO/POST" />
      <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://riversidecronton.cirqahosting.com/Shibboleth.sso/SLO/Artifact" />
    </SPSSODescriptor>
  </EntityDescriptor>
</EntitiesDescriptor>
