<env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope">
    <env:Header xmlns:addressing="http://www.w3.org/2005/08/addressing">
        <addressing:Action env:mustUnderstand="1">http://docs.oasis-open.org/ws-sx/ws-trust/200512/RSTR/IssueFinal</addressing:Action>
        <addressing:MessageID>uuid:9B3E3D0F-4302-418F-A079-BCEBCEE27EA1</addressing:MessageID>
        <addressing:RelatesTo>pineIT_msgID:faab5c20-a8f2-428a-a350-64f3537ba5f0</addressing:RelatesTo>
    </env:Header>
    <env:Body>
        <wst:RequestSecurityTokenResponseCollection xmlns:wst="http://docs.oasis-open.org/ws-sx/ws-trust/200512">
            <wst:RequestSecurityTokenResponse>
                <wst:TokenType>urn:elga:bes:2019:Context:assertion</wst:TokenType>
                <wst:RequestedSecurityToken>
                    <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:xsd="http://www.w3.org/2001/XMLSchema" ID="_41cb609d-c096-4528-b031-18fc0ab72b8d" IssueInstant="2020-11-06T08:42:04.060Z" Version="2.0">
                        <saml2:Issuer Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">urn:elga:ets</saml2:Issuer>
                        <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                            <ds:SignedInfo>
                                <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
                                <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
                                <ds:Reference URI="#_41cb609d-c096-4528-b031-18fc0ab72b8d">
                                    <ds:Transforms>
                                        <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
                                        <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#">
                                            <ec:InclusiveNamespaces xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="xsd"/>
                                        </ds:Transform>
                                    </ds:Transforms>
                                    <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
                                    <ds:DigestValue>O3Km89JiGGby4xpTL1dgZuRWPrHsqpW3nYMuaBxmwT8=</ds:DigestValue>
                                </ds:Reference>
                            </ds:SignedInfo>
                            <ds:SignatureValue>LolBVBswEbrjDKnJV89mPAIkSglUgpE7/R4k6UUHsH9bik7/nXuJQeSJY381wnVwi5/kr0HAnoXBk9Q7Z0I6QmFfI4VZmGcJwMb7LKHd9rqxlFT3G9Tg2vcD0NsxtBL39t62s7hOx90zyVfrff29Hkzk8W3fLBVUoBqMsCgNHyBa3UPXy+4UJ7fIykCSPz4k3ewvx+hL9L2gcIE289lRQtEs/10B7VbbMO+lOWPwMYP6aaZ3kc2K9Ce+yRvjT1QFsJK8G4KfVCnQ/P2nFrXTa6Kw/ygqKtdLEVC1ae1bdbr/rUAgIZaL4/NuEdPis47Z7M4m66wiSCBoch9SYOfEeQ==</ds:SignatureValue>
                            <ds:KeyInfo>
                                <ds:X509Data>
                                    <ds:X509Certificate>MIIEMzCCAxugAwIBAgIIXazOdf5ItY4wDQYJKoZIhvcNAQELBQAwFjEUMBIGA1UEAwwLRUxHQS1JTlRDQTEwHhcNMjAwNTEwMTE1MzExWhcNMjIwNTEwMTE1MzExWjBCMRwwGgYDVQQDDBNhY3MuZWxnYS1zcGlyaXQuaW50MRUwEwYDVQQKDAxUaWFuaS1TcGlyaXQxCzAJBgNVBAYTAkFUMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA5RYjoSxZdKoAOo4Q+4zojVrBr3t55E25L4u9VLgxm7evS6lhI1zFa03elnVCVPZsEbz8zEuqBjDLpU4fYvDdyw6u8U5Sw9q9jtiUt9JBkgGO9lxppRRfARqbbJKvLlzpQa0IARYeh4sBj5fNc2ohUjifOATPkhW/QzTiCnMDZh9U3tYeLUORX/b3Lgm8wZ5/oy6MUtPnXefTRMVmFtP5YAevhsQqpqAyMcqmodtRDiNDa5mHReVH/ftKGGWeX6MeO7b6RTy0Znji/TH7Y7GIjqwh4ISRgxJ/B9ZzCUApoFD2MceGCvZzIYQ2St8WAA0UsxDFA5EuPS7G18LHvcRLyQIDAQABo4IBVzCCAVMwDAYDVR0TAQH/BAIwADAfBgNVHSMEGDAWgBRpnVuezwNOHziBG5P0dFmd5NVI5zBTBggrBgEFBQcBAQRHMEUwQwYIKwYBBQUHMAGGN2h0dHA6Ly9iZXMudGlhbmktc3Bpcml0LmNvbS9lamJjYS9wdWJsaWN3ZWIvc3RhdHVzL29jc3AwgYEGA1UdEQR6MHiCF2Fjcy5lbGdhLWRldi1zcGlyaXQuaW50ghVhY3Mua29sbGFiLXNwaXJpdC5pbnSCFmFjcy5rb2xsYWIxLXNwaXJpdC5pbnSCFmFjcy5rb2xsYWIyLXNwaXJpdC5pbnSCFmFjcy5rb2xsYWIzLXNwaXJpdC5pbnQwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMB0GA1UdDgQWBBQS4G6YdEJcRn3+26BTwmyhrrh5EjALBgNVHQ8EBAMCBeAwDQYJKoZIhvcNAQELBQADggEBADr7WLGpG1nCcSNfA/zdlSQvuUVuzLgT3DDdZ1Yjj/tZkG6hAO+rIwRAroz4sNbNxzrksDghhvhZe2GsboJaiJlu81uxH/Y7mi3fh3CTYkTjW4dxS1i9D9uXXLTKuuP1S4XBVuK/FF47Y5MXxAY6IGc/Hoy/cxHxRAWpGskPIkx2weQ0g/UkmWwG41QafEuwyZcaGIxI7ZJkvt7Zw96U01AlnkQodq4dG0tsG+YRuHb+4iRCOjo1gQPucVS6ss+bbRBJ+ikO8fT9cV6yXAKoBi8yfw4HBGDTSbJdWs7F0bRKV1IJDR6xadByG9skpSOhuEe4VXuqNAkvdxxExLxN5/Q=</ds:X509Certificate>
                                </ds:X509Data>
                            </ds:KeyInfo>
                        </ds:Signature>
                        <saml2:Subject>
                            <saml2:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">1.2.40.0.34.99.10.1.1.1.31498^1.2.40.0.34@100Krankenanstalt Eisenstadt</saml2:NameID>
                            <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
                                <saml2:SubjectConfirmationData/>
                            </saml2:SubjectConfirmation>
                        </saml2:Subject>
                        <saml2:Conditions NotBefore="2020-11-06T08:42:04.060Z" NotOnOrAfter="2020-11-06T12:42:04.060Z">
                            <saml2:ProxyRestriction Count="1"/>
                            <saml2:AudienceRestriction>
                                <saml2:Audience>https://elga-online.at/ETS</saml2:Audience>
                                <saml2:Audience>https://elga-online.at/KBS</saml2:Audience>
                                <saml2:Audience>https://elga-online.at/ZPI</saml2:Audience>
                            </saml2:AudienceRestriction>
                        </saml2:Conditions>
                        <saml2:AuthnStatement AuthnInstant="2020-11-06T08:42:04.060Z">
                            <saml2:AuthnContext>
                                <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PreviousSession</saml2:AuthnContextClassRef>
                            </saml2:AuthnContext>
                        </saml2:AuthnStatement>
                        <saml2:AttributeStatement>
                            <saml2:Attribute FriendlyName="BeS Purpose Of Use" Name="urn:oasis:names:tc:xspa:1.0:subject:purposeofuse" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
                                <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">E-HEALTH-CONTEXT^103</saml2:AttributeValue>
                            </saml2:Attribute>
                            <saml2:Attribute FriendlyName="AC Purpose" Name="urn:oasis:names:tc:xacml:2.0:action:purpose" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
                                <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">PUBLICHEALTH</saml2:AttributeValue>
                            </saml2:Attribute>
                            <saml2:Attribute FriendlyName="ELGA Rolle" Name="urn:oasis:names:tc:xacml:2.0:subject:role" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
                                <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:anyType">
                                    <Role xmlns="urn:hl7-org:v3" code="702" codeSystem="1.2.40.0.34.5.3" codeSystemName="ELGA GDA Aggregatrollen" displayName="Krankenanstalt"/>
                                </saml2:AttributeValue>
                            </saml2:Attribute>
                            <saml2:Attribute FriendlyName="XSPA Subject" Name="urn:oasis:names:tc:xacml:1.0:subject:subject-id" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
                                <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">pineIT</saml2:AttributeValue>
                            </saml2:Attribute>
                            <saml2:Attribute FriendlyName="Local Organisation ID" Name="urn:elga:bes:2013:local-organisation-id" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
                                <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:anyURI">urn:oid:1.2.40.0.34.99.10.1.1.1.31498</saml2:AttributeValue>
                            </saml2:Attribute>
                            <saml2:Attribute FriendlyName="XSPA Organization ID" Name="urn:oasis:names:tc:xspa:1.0:subject:organization-id" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
                                <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:anyURI">urn:oid:1.2.40.0.34.99.10.1.1.1.31498</saml2:AttributeValue>
                            </saml2:Attribute>
                            <saml2:Attribute FriendlyName="Permissions" Name="urn:elga:bes:permission" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
                                <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">urn:elga:bes:2019:permission:e-Impfpass:read:contact</saml2:AttributeValue>
                                <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">urn:elga:bes:2019:permission:e-Impfpass:write:contact</saml2:AttributeValue>
                            </saml2:Attribute>
                        </saml2:AttributeStatement>
                    </saml2:Assertion>
                </wst:RequestedSecurityToken>
            </wst:RequestSecurityTokenResponse>
        </wst:RequestSecurityTokenResponseCollection>
    </env:Body>
</env:Envelope>

