﻿<?xml version="1.0" encoding="utf-8"?>
<saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:xs="http://www.w3.org/2001/XMLSchema" ID="_0c5b2937-572e-41ee-ba66-63f24379e6cb" IssueInstant="2015-03-19T13:07:34.368Z" Version="2.0">
  <saml2:Issuer Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">urn:elga:ets</saml2:Issuer>
  <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
    <ds:SignedInfo>
      <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
      <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" />
      <ds:Reference URI="#_0c5b2937-572e-41ee-ba66-63f24379e6cb">
        <ds:Transforms>
          <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" />
          <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#">
            <ec:InclusiveNamespaces xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="xs" />
          </ds:Transform>
        </ds:Transforms>
        <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
        <ds:DigestValue>Kqbn8qM1frAFQquyb8PRXuW4XP8=</ds:DigestValue>
      </ds:Reference>
    </ds:SignedInfo>
    <ds:SignatureValue>h7pIHRlKtaxqMNhmOHufsUdwLMSkyBuw5yC+ybJ5kWESN9u51B+dFYCqFp0HXod0orgHGyuKJu4FaurBtINWr7qQvJRIqwSA8pfI4IqsaxbhGJvrrUWW/V9+UnhW30UOiMn1xwAkS4S9FL6+9IDmCMq0zPnmRMgBjGFzWqEw7FGnW9wUbahTDW78Z6/4bx1G9B6/cxguXcLCQo/EMhThLdU5/B9ztwF0pPfX+F3fFl7cMAEtQYklLxxISvvB0Gv1YE4RHVngyf6RFAXn67HRN/Uxm6xIw2XXY2QLrbqYpAXhJaqVGrKv2NT47GaYIjy7MkuglrlfmvaGvuAfS5fPjA==</ds:SignatureValue>
    <ds:KeyInfo>
      <ds:X509Data>
        <ds:X509Certificate>MIIEQTCCAymgAwIBAgIBAzANBgkqhkiG9w0BAQUFADCBrDELMAkGA1UEBhMCQVQxEDAOBgNVBAgT
B0F1c3RyaWExDzANBgNVBAcTBlZpZW5uYTEaMBgGA1UEChMRVGlhbmkgU3Bpcml0IEdtYkgxGTAX
BgNVBAsTEERlbW8gRW52aXJvbm1lbnQxEDAOBgNVBAMTB1Rlc3QgQ0ExMTAvBgkqhkiG9w0BCQEW
Im1hc3NpbWlsaWFuby5tYXNpQHRpYW5pLXNwaXJpdC5jb20wIBcNMTEwNzI3MDgyMTUyWhgPMjE5
MDEyMzEwODIxNTJaMIGbMQswCQYDVQQGEwJBVDEQMA4GA1UECBMHQXVzdHJpYTEaMBgGA1UEChMR
VGlhbmkgU3Bpcml0IEdtYkgxGTAXBgNVBAsTEERlbW8gRW52aXJvbm1lbnQxEDAOBgNVBAMTB3Nl
cnZlcjExMTAvBgkqhkiG9w0BCQEWIm1hc3NpbWlsaWFuby5tYXNpQHRpYW5pLXNwaXJpdC5jb20w
ggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDcEpmyaFK8aKKrvaFZL6IGttOwI3ImGCUi
wINIc+fcuVWRyT7Deb8tymnwVBfHVD/8Mh5ufwiS9YU774Ta2aB8H/Gwr5QIndu4eG9+adDEV3+D
i6e3HhiA/8RP8CXCMGY4LOAjaNwUh/EEsn1S2oa+Dsiff5Ba8wmddc6pyYiwmhDfwEF0YBXDjvB8
iexcLcOLvo/pl2hP87g/ptDXy0VUWWPzX9qxc6YtqhkS7EtmhzMW5deWvmRiPzJ2NVfCuvpcsK2T
ii+MgCYbLXCLYkCg+5ZpV7esrqb5hWOf2tKUsDlu/sjck2lflsWTE1woKr0tbp7IxLzvGKx9hERB
0hzJAgMBAAGjezB5MAkGA1UdEwQCMAAwLAYJYIZIAYb4QgENBB8WHU9wZW5TU0wgR2VuZXJhdGVk
IENlcnRpZmljYXRlMB0GA1UdDgQWBBQU7M3dSaInYi+0MCDYpbACOCjvBzAfBgNVHSMEGDAWgBRk
wihuUTlGpNDxrnZFbW84FXj72jANBgkqhkiG9w0BAQUFAAOCAQEAjEqNtOb2Hk6BpBDRXk9vd+0v
vJSOWvdZnL3I2Kr30oN6nQOMud68FPI1JC1QwLni05ZVDTyMYOk/HRPK2jSByFmLZECaE6Q5Z1BT
D9vR/AqtmTOvub922uS5gTpVEWijSW1o9j+LFzGC4k8l4xWidPtKa3o1aXSGcWSw0i1BKgxM3pMz
SvKieZ2KQaHgZSb7bfk4uR4kAaida5hv6kveiDKRRG+8AeBvBD5lofaqUaUN9q/YIOucc8gHQBzG
rmkObvyykzyPz5wddLmouqrZZqfufPTNh4whyABbXCPXsptDZZss8DlKS37rFVUKLHEhcfd1J+IO
ioaTnaPhgY/dXg==</ds:X509Certificate>
      </ds:X509Data>
    </ds:KeyInfo>
  </ds:Signature>
  <saml2:Subject>
    <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:unspecified">initGW</saml2:NameID>
    <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:sender-vouches">
      <saml2:SubjectConfirmationData />
    </saml2:SubjectConfirmation>
  </saml2:Subject>
  <saml2:Conditions NotBefore="2015-03-19T13:07:34.367Z" NotOnOrAfter="2015-03-19T13:12:34.367Z">
    <saml2:AudienceRestriction>
      <saml2:Audience>http://zgf1:8081/ACSFacade/XCA/eBefunde/respGW</saml2:Audience>
    </saml2:AudienceRestriction>
  </saml2:Conditions>
  <saml2:AuthnStatement AuthnInstant="2015-03-19T13:07:34.367Z">
    <saml2:AuthnContext>
      <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PreviousSession</saml2:AuthnContextClassRef>
    </saml2:AuthnContext>
  </saml2:AuthnStatement>
  <saml2:AttributeStatement>
    <saml2:Attribute FriendlyName="ACTING-PERSON-BPK-GH" Name="urn:elga:bes:2013:acting:bPK-GH" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
      <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">GH:NnO6EUHwZS8Ozag9on/ElSu8f44=^^^&amp;1.2.40.0.10.2.1.1.149&amp;ISO</saml2:AttributeValue>
    </saml2:Attribute>
    <saml2:Attribute FriendlyName="XSPA Subject (real person acting)" Name="urn:oasis:names:tc:xacml:1.0:subject:subject-id" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
      <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">ACTING_NN ACTING_VN</saml2:AttributeValue>
    </saml2:Attribute>
    <saml2:Attribute FriendlyName="ELGA Rolle" Name="urn:oasis:names:tc:xacml:2.0:subject:role" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
      <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:anyType">
        <Role xmlns="urn:hl7-org:v3" code="611" codeSystem="1.2.40.0.34.5.158" codeSystemName="ELGA Rollen" displayName="bevollmächtigter ELGA-Teilnehmer" />
      </saml2:AttributeValue>
    </saml2:Attribute>
    <saml2:Attribute FriendlyName="Permissions" Name="urn:elga:bes:permission" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
      <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">urn:elga:bes:2013:permission:eBefunde</saml2:AttributeValue>
    </saml2:Attribute>
    <saml2:Attribute FriendlyName="XSPA PatientID (LPID)" Name="urn:oasis:names:tc:xacml:1.0:resource:resource-id" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
      <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">10003^^^&amp;1.2.40.0.34.99.10.1.11.1.1&amp;ISO</saml2:AttributeValue>
    </saml2:Attribute>
    <saml2:Attribute FriendlyName="Purpose Of Use" Name="urn:oasis:names:tc:xspa:1.0:subject:purposeofuse" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
      <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">MANDATE2</saml2:AttributeValue>
    </saml2:Attribute>
    <saml2:Attribute FriendlyName="Area specific personal identifier" Name="urn:elga:bes:2013:bPK-GH" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
      <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:anyURI">GH:J1fL3/IBEUR9djmQQJDXYNGF8hc=^^^&amp;1.2.40.0.10.2.1.1.149&amp;ISO</saml2:AttributeValue>
    </saml2:Attribute>
    <saml2:Attribute FriendlyName="XCA Home Community ID" Name="urn:ihe:iti:xca:2010:homeCommunityId" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
      <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:anyURI">Community.0.2</saml2:AttributeValue>
    </saml2:Attribute>
    <saml2:Attribute FriendlyName="XCA Responding Home Community ID" Name="urn:elga:bes:2013:rsp-community" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
      <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:anyURI">Community.0.1</saml2:AttributeValue>
    </saml2:Attribute>
		<saml2:Attribute FriendlyName="XSPA Organization ID" Name="urn:oasis:names:tc:xspa:1.0:subject:organization-id" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
      <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:anyURI">1.2.40.0.34.6.6</saml2:AttributeValue>
    </saml2:Attribute>
  </saml2:AttributeStatement>
  <xacml-saml:XACMLPolicyStatementType xmlns:xacml-saml="urn:oasis:names:tc:xacml:2.0:profile:saml2.0:v2:schema:assertion">
    <PolicySet xmlns="urn:oasis:names:tc:xacml:2.0:policy:schema:os" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" PolicyCombiningAlgId="urn:oasis:names:tc:xacml:1.0:policy-combining-algorithm:permit-overrides" PolicySetId="urn:elga:bes:2013:1.2.40.0.34.72.102" xsi:schemaLocation="urn:oasis:names:tc:xacml:2.0:policy:schema:os http://docs.oasis-open.org/xacml/access_control-xacml-2.0-policy-schema-os.xsd">
  <Description>Policy that permits everything</Description>
  <Target />
  <Policy PolicyId="urn:elga:bes:2013:1.2.40.0.34.72.102.1" RuleCombiningAlgId="urn:oasis:names:tc:xacml:1.0:rule-combining-algorithm:permit-overrides">
    <Description>Policy permit</Description>
    <Target />
    <Rule Effect="Permit" RuleId="urn:elga:bes:2013:1.2.40.0.34.72.102.1.1" />
  </Policy>
</PolicySet>
  </xacml-saml:XACMLPolicyStatementType>
</saml2:Assertion>