<saml2:Assertion ID="_47485ec9-4cb5-4226-b748-a3df4a88b597" IssueInstant="2014-06-08T09:44:07.538Z" Version="2.0" 
    xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
    xmlns:xs="http://www.w3.org/2001/XMLSchema">
    <saml2:Issuer Format="PUBLICHEALTH">urn:elga:ets</saml2:Issuer>
    <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:SignedInfo>
            <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
            <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
            <ds:Reference URI="#_47485ec9-4cb5-4226-b748-a3df4a88b597">
                <ds:Transforms>
                    <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
                    <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#">
                        <ec:InclusiveNamespaces PrefixList="xs" xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#"/>
                    </ds:Transform>
                </ds:Transforms>
                <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
                <ds:DigestValue>ZQbze74GdIId6vZBw4SB7pKSvow=</ds:DigestValue>
            </ds:Reference>
        </ds:SignedInfo>
        <ds:SignatureValue>0xrY4fGnzPdKVrVK1grR+1JaLVkser6bWbGH/laSOoMcg0Pa8g2S95anMfsgt6/fv5dIijKs9H+TPyay
            IHz9Iv7JhRs1c2qIj+vBI2hXuqtfgntsCFrwue6ICQ/YvVDpyxk4/aI9ebVOGIK7jmf2tk6K6pXSnGomFiXJL2KQxBeJ8UY
            rCSReyRaFKnCyQH3+Zxnjrdhdpog6u0N8+Xrl91zqNCgGyDKBoT7me8wrSz/sP+i66ArF70/70sLELG0EK4qcfNFG2JsJnV
            JSdL8DdxwlGAkYtgFzOyv9CEhYUNtsoLq5S0IEQETMn OrdddUkQN97/v/IB/To9Y5W3XS1kg== 
        </ds:SignatureValue>
        <ds:KeyInfo>
            <ds:X509Data>
           <ds:X509Certificate>MIIEQTCCAymgAwIBAgIBAzANBgkqhkiG9w0BAQUFADCBrDELMAkGA1UEBh
               MCQVQxEDAOBgNVBAgTB0F1c3RyaWExDzANBgNVBAcTBlZpZW5uYTEaMBgGA1UEChMRVGlhbmkgU3Bpc
               ml0IEdtYkgxGTAXBgNVBAsTEERlbW8gRW52aXJvbm1lbnQxEDAOBgNVBAMTB1Rlc3QgQ0ExMTAvB
               gkqhkiG9w0BCQEW Im1hc3NpbWlsaWFuby5tYXNpQHRpYW5pLXNwaXJpdC5jb20wIBcNMTEwNzI3MDgy
               MTUyWhgPMjE5MDEyMzEwODIxNTJaMIGbMQswCQYDVQQGEwJBVDEQMA4GA1UECBMHQXVzdHJpYTE
               aMBgGA1UEChMR D9vR/AqtmTOvub922uS5gTpVEWijSW1o9j+LFzGC4k8l4xWidPtKa3o1aXSGcWSw0i1BKgx
               M3pMzSvKieZ2KQaHgZSb7bfk4uR4kAaida5hv6kveiDKRRG+8AeBvBD5lofaqUaUN9q/YIOucc8gHQBzG 
               rmkObvyykzyPz5wddLmouqrZZqfufPTNh4whyABbXCPXsptDZZss8DlKS37rFVUKLHEhcfd1J+IO
               ioaTnaPhgY/dXg==</ds:X509Certificate>
            </ds:X509Data>
        </ds:KeyInfo>
    </ds:Signature>
    <saml2:Subject>
        <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:unspecified">1.2.40.0.34.3.1.4.2</saml2:NameID>
        <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
            <saml2:SubjectConfirmationData/>
        </saml2:SubjectConfirmation>
    </saml2:Subject>
    <saml2:Conditions NotBefore="2014-06-08T09:44:07.537Z" NotOnOrAfter="2014-06-08T11:44:07.537Z">
        <saml2:AudienceRestriction>
            <saml2:Audience>https://elga-online.at/ETS</saml2:Audience>
        </saml2:AudienceRestriction>
    </saml2:Conditions>
    <saml2:AuthnStatement AuthnInstant="2014-06-08T09:44:07.537Z">
        <saml2:AuthnContext>
            <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PreviousSession</saml2:AuthnContextClassRef>
        </saml2:AuthnContext>
    </saml2:AuthnStatement>
    <saml2:AttributeStatement>
        <saml2:Attribute FriendlyName="Purpose Of Use" Name="urn:oasis:names:tc:xspa:1.0:subject:purposeofuse" 
            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
            <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
                xsi:type="xs:string">WIST</saml2:AttributeValue>
        </saml2:Attribute>
        <saml2:Attribute FriendlyName="ELGA Rolle" Name="urn:oasis:names:tc:xacml:2.0:subject:role" 
            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
            <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:anyType">
                <Role code="607" codeSystem="1.2.40.0.34.5.158" codeSystemName="ELGA Rollen" displayName="ELGA-Widerspruchstelle" 
                    xmlns="urn:hl7-org:v3"/>
            </saml2:AttributeValue>
        </saml2:Attribute>
        <saml2:Attribute FriendlyName="XSPA Subject" Name="urn:oasis:names:tc:xacml:1.0:subject:subject-id" 
            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
            <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">
                WIST</saml2:AttributeValue>
        </saml2:Attribute>
        <saml2:Attribute FriendlyName="Permissions" Name="urn:elga:bes:permission" 
            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
            <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
                xsi:type="xs:string">urn:elga:bes:2013:permission:707</saml2:AttributeValue>
        </saml2:Attribute>
    </saml2:AttributeStatement>
</saml2:Assertion>
