<ns0:EntityDescriptor xmlns:ns0="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ns1="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:ns2="http://www.w3.org/2000/09/xmldsig#" entityID="https://ignite.kenet.or.ke/iam/sso/metadata/"><ns0:Extensions><ns1:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#ripemd160" /><ns1:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1" /><ns1:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224" /><ns1:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" /><ns1:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384" /><ns1:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512" /><ns1:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1" /><ns1:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256" /><ns1:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1" /><ns1:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224" /><ns1:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256" /><ns1:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384" /><ns1:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512" /><ns1:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-ripemd160" /><ns1:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1" /><ns1:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha224" /><ns1:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" /><ns1:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384" /><ns1:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512" /></ns0:Extensions><ns0:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" AuthnRequestsSigned="true" WantAssertionsSigned="true"><ns0:KeyDescriptor use="signing"><ns2:KeyInfo><ns2:X509Data><ns2:X509Certificate>MIIECTCCAvGgAwIBAgIUbL6hypbUNj9KWmWP1UYPr2sF7BEwDQYJKoZIhvcNAQELBQAwgZMxCzAJBgNVBAYTAktFMRAwDgYDVQQIDAdOYWlyb2JpMRAwDgYDVQQHDAdOYWlyb2JpMQ4wDAYDVQQKDAVLRU5FVDENMAsGA1UECwwETlJFTjEbMBkGA1UEAwwSaWduaXRlLmtlbmV0Lm9yLmtlMSQwIgYJKoZIhvcNAQkBFhVld2FueW9ueWlAa2VuZXQub3Iua2UwHhcNMjUwNzIxMTMzMDU0WhcNMzUwNzE5MTMzMDU0WjCBkzELMAkGA1UEBhMCS0UxEDAOBgNVBAgMB05haXJvYmkxEDAOBgNVBAcMB05haXJvYmkxDjAMBgNVBAoMBUtFTkVUMQ0wCwYDVQQLDAROUkVOMRswGQYDVQQDDBJpZ25pdGUua2VuZXQub3Iua2UxJDAiBgkqhkiG9w0BCQEWFWV3YW55b255aUBrZW5ldC5vci5rZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANdLKM7kk9zSGLHzu+JiDyo1oP0Iy3P3D8WUcX+uhS6WQrkaagPuNiEHsWYDux/WEakqlTwY3cD/kpuDWa3gEl4LHz97sN8PbZrKDVSbk/I9sbZxnGIlWZvMyisvEvZ4dZofu8wJnu2VcSiXPKQZpUqcx96phfXFt1u1e/1Sol7jSDrDShA5O88R4MTUSfEHjA7nb1gruTowdtpf1zb8x/9FJqAfxP+VJykR1EADJXTPGMEZspBO5XxF6IhIUNUqsJHyO7qVuuFw3H6FWUmKUR6yN7hstRBe5J1hSQBQ1d7fyGJBTMDjvXC4EfASG1v3hFSrn8eiMSK98OLsTadS/XMCAwEAAaNTMFEwHQYDVR0OBBYEFIe8ZyVgGiQtm7EA+db4FX8mG2TvMB8GA1UdIwQYMBaAFIe8ZyVgGiQtm7EA+db4FX8mG2TvMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAFPTKKeoclTl3tKm3KYNoM6Lf0YiXdE4VgvCTDbBfZeiRyLpSYFndURXkU0KBQHpeJCnleNlnt12mluOklC/m/dc/Uw4pas/GM6WM01iJe90n6H5z+CAz8xaLJIR98JZycL/vFuFxu2lPigEJLYHZgiFycyGXTy+Semyiez/vEzhmepnaRX0h4VLxqh0JWCcnXAQmuZC01bpHOGBjuIhHwkdt+ezQVeZuJ6kBCDfWaUy+M2koUezQCpg8QJezLwHl2fGWc7P8FUe9MDOOT3u9qTRFzNTV2fCKeEslzlz6xWfRASFvDBb0RoNaX0w7xtIdE7zvh05Vi6IBXkZe0hr8s8=</ns2:X509Certificate></ns2:X509Data></ns2:KeyInfo></ns0:KeyDescriptor><ns0:KeyDescriptor use="encryption"><ns2:KeyInfo><ns2:X509Data><ns2:X509Certificate>MIIECTCCAvGgAwIBAgIUbL6hypbUNj9KWmWP1UYPr2sF7BEwDQYJKoZIhvcNAQELBQAwgZMxCzAJBgNVBAYTAktFMRAwDgYDVQQIDAdOYWlyb2JpMRAwDgYDVQQHDAdOYWlyb2JpMQ4wDAYDVQQKDAVLRU5FVDENMAsGA1UECwwETlJFTjEbMBkGA1UEAwwSaWduaXRlLmtlbmV0Lm9yLmtlMSQwIgYJKoZIhvcNAQkBFhVld2FueW9ueWlAa2VuZXQub3Iua2UwHhcNMjUwNzIxMTMzMDU0WhcNMzUwNzE5MTMzMDU0WjCBkzELMAkGA1UEBhMCS0UxEDAOBgNVBAgMB05haXJvYmkxEDAOBgNVBAcMB05haXJvYmkxDjAMBgNVBAoMBUtFTkVUMQ0wCwYDVQQLDAROUkVOMRswGQYDVQQDDBJpZ25pdGUua2VuZXQub3Iua2UxJDAiBgkqhkiG9w0BCQEWFWV3YW55b255aUBrZW5ldC5vci5rZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANdLKM7kk9zSGLHzu+JiDyo1oP0Iy3P3D8WUcX+uhS6WQrkaagPuNiEHsWYDux/WEakqlTwY3cD/kpuDWa3gEl4LHz97sN8PbZrKDVSbk/I9sbZxnGIlWZvMyisvEvZ4dZofu8wJnu2VcSiXPKQZpUqcx96phfXFt1u1e/1Sol7jSDrDShA5O88R4MTUSfEHjA7nb1gruTowdtpf1zb8x/9FJqAfxP+VJykR1EADJXTPGMEZspBO5XxF6IhIUNUqsJHyO7qVuuFw3H6FWUmKUR6yN7hstRBe5J1hSQBQ1d7fyGJBTMDjvXC4EfASG1v3hFSrn8eiMSK98OLsTadS/XMCAwEAAaNTMFEwHQYDVR0OBBYEFIe8ZyVgGiQtm7EA+db4FX8mG2TvMB8GA1UdIwQYMBaAFIe8ZyVgGiQtm7EA+db4FX8mG2TvMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAFPTKKeoclTl3tKm3KYNoM6Lf0YiXdE4VgvCTDbBfZeiRyLpSYFndURXkU0KBQHpeJCnleNlnt12mluOklC/m/dc/Uw4pas/GM6WM01iJe90n6H5z+CAz8xaLJIR98JZycL/vFuFxu2lPigEJLYHZgiFycyGXTy+Semyiez/vEzhmepnaRX0h4VLxqh0JWCcnXAQmuZC01bpHOGBjuIhHwkdt+ezQVeZuJ6kBCDfWaUy+M2koUezQCpg8QJezLwHl2fGWc7P8FUe9MDOOT3u9qTRFzNTV2fCKeEslzlz6xWfRASFvDBb0RoNaX0w7xtIdE7zvh05Vi6IBXkZe0hr8s8=</ns2:X509Certificate></ns2:X509Data></ns2:KeyInfo></ns0:KeyDescriptor><ns0:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://ignite.kenet.or.ke/iam/sso/ls/" /><ns0:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://ignite.kenet.or.ke/iam/sso/ls/post" /><ns0:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</ns0:NameIDFormat><ns0:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://ignite.kenet.or.ke/iam/sso/acs/" index="1" /><ns0:AttributeConsumingService index="1"><ns0:ServiceName xml:lang="en">KENET ignite</ns0:ServiceName><ns0:ServiceDescription xml:lang="en">KENET ignite application for ignite related information</ns0:ServiceDescription><ns0:RequestedAttribute Name="uid" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true" /><ns0:RequestedAttribute Name="mail" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true" /><ns0:RequestedAttribute Name="displayName" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="false" /><ns0:RequestedAttribute Name="eduPersonAffiliation" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="false" /><ns0:RequestedAttribute Name="eduPersonPrimaryAffiliation" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="false" /></ns0:AttributeConsumingService></ns0:SPSSODescriptor><ns0:Organization><ns0:OrganizationName xml:lang="en">Kenya Education Network</ns0:OrganizationName><ns0:OrganizationDisplayName xml:lang="en">Kenya Education Network (KENET)</ns0:OrganizationDisplayName><ns0:OrganizationURL xml:lang="en">https://kenet.or.ke</ns0:OrganizationURL></ns0:Organization><ns0:ContactPerson contactType="technical"><ns0:Company>KENET</ns0:Company><ns0:GivenName>KENET</ns0:GivenName><ns0:SurName>Support</ns0:SurName><ns0:EmailAddress>sysadmins@kenet.or.ke</ns0:EmailAddress></ns0:ContactPerson><ns0:ContactPerson contactType="technical"><ns0:Company>KENET</ns0:Company><ns0:GivenName>Emanuel</ns0:GivenName><ns0:SurName>Wanyonyi</ns0:SurName><ns0:EmailAddress>ewanyonyi@kenet.or.ke</ns0:EmailAddress></ns0:ContactPerson></ns0:EntityDescriptor>