<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<saml2:Assertion ID="_2b9a9cef-acd9-4402-9a41-721ff779b9e5" IssueInstant="2014-08-26T10:57:38.489Z" Version="2.0" 
    xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:xs="http://www.w3.org/2001/XMLSchema">
    <saml2:Issuer Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">urn:elga:ets</saml2:Issuer>
    <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:SignedInfo>
            <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
            <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
            <ds:Reference URI="#_2b9a9cef-acd9-4402-9a41-721ff779b9e5">
                <ds:Transforms>
                    <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
                    <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#">
                        <ec:InclusiveNamespaces PrefixList="xs" xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#"/>
                    </ds:Transform>
                </ds:Transforms>
                <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256"/>
                <ds:DigestValue>8TrtoETN9Mt4SakWMCEUbe/7vaQ=</ds:DigestValue>
            </ds:Reference>
        </ds:SignedInfo>
        <ds:SignatureValue>baRyjKxc8LO2ueMLibuDlL7lai67aN2xM5opNpF6V6Uqz/EupNYkF7oDzDj3dHcnN4DYrg
            31pTBvCK+tBJzjLrng9Q8J62kXEkR1HoEgG1y0uMUYp82yd3PTyaFPWhcLkbnw9a8uTOCUqH6QN8A0HQV9S
            4kaZGwA24uACdH5DKeQjTMG2d81cMc1+TFrh72X9K4EyKznpcbNd3cgGkUtiqInig2pFxxYiXCxFATrshwkGx5AJbFc
            v/nS+ys5oPOdLCoU60n1AU0ODAp3ljQJtx2yWKmxGJ8RSKETF24c6EQYbUGRIKRmt3MJ0GfO1W5k
            F80/DxWVGS7Y5hm9ulbFeg==</ds:SignatureValue>
        <ds:KeyInfo>
            <ds:X509Data>
                <ds:X509Certificate>
                    MIIEQTCCAymgAwIBAgIBAzANBgkqhkiG9w0BAQUFADCBrDELMAkGA1UEBhMCQVQxEDAOBgNVBAgT
                    B0F1c3RyaWExDzANBgNVBAcTBlZpZW5uYTEaMBgGA1UEChMRVGlhbmkgU3Bpcml0IEdtYkgxGTAX
                    BgNVBAsTEERlbW8gRW52aXJvbm1lbnQxEDAOBgNVBAMTB1Rlc3QgQ0ExMTAvBgkqhkiG9w0BCQEW
                    Im1hc3NpbWlsaWFuby5tYXNpQHRpYW5pLXNwaXJpdC5jb20wIBcNMTEwNzI3MDgyMTUyWhgPMjE5
                    MDEyMzEwODIxNTJaMIGbMQswCQYDVQQGEwJBVDEQMA4GA1UECBMHQXVzdHJpYTEaMBgGA1UEChMR
                    VGlhbmkgU3Bpcml0IEdtYkgxGTAXBgNVBAsTEERlbW8gRW52aXJvbm1lbnQxEDAOBgNVBAMTB3Nl
                    cnZlcjExMTAvBgkqhkiG9w0BCQEWIm1hc3NpbWlsaWFuby5tYXNpQHRpYW5pLXNwaXJpdC5jb20w
                    ggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDcEpmyaFK8aKKrvaFZL6IGttOwI3ImGCUi
                    wINIc+fcuVWRyT7Deb8tymnwVBfHVD/8Mh5ufwiS9YU774Ta2aB8H/Gwr5QIndu4eG9+adDEV3+D
                    i6e3HhiA/8RP8CXCMGY4LOAjaNwUh/EEsn1S2oa+Dsiff5Ba8wmddc6pyYiwmhDfwEF0YBXDjvB8
                    iexcLcOLvo/pl2hP87g/ptDXy0VUWWPzX9qxc6YtqhkS7EtmhzMW5deWvmRiPzJ2NVfCuvpcsK2T
                    ii+MgCYbLXCLYkCg+5ZpV7esrqb5hWOf2tKUsDlu/sjck2lflsWTE1woKr0tbp7IxLzvGKx9hERB
                    0hzJAgMBAAGjezB5MAkGA1UdEwQCMAAwLAYJYIZIAYb4QgENBB8WHU9wZW5TU0wgR2VuZXJhdGVk
                    IENlcnRpZmljYXRlMB0GA1UdDgQWBBQU7M3dSaInYi+0MCDYpbACOCjvBzAfBgNVHSMEGDAWgBRk
                    wihuUTlGpNDxrnZFbW84FXj72jANBgkqhkiG9w0BAQUFAAOCAQEAjEqNtOb2Hk6BpBDRXk9vd+0v
                    vJSOWvdZnL3I2Kr30oN6nQOMud68FPI1JC1QwLni05ZVDTyMYOk/HRPK2jSByFmLZECaE6Q5Z1BT
                    D9vR/AqtmTOvub922uS5gTpVEWijSW1o9j+LFzGC4k8l4xWidPtKa3o1aXSGcWSw0i1BKgxM3pMz
                    SvKieZ2KQaHgZSb7bfk4uR4kAaida5hv6kveiDKRRG+8AeBvBD5lofaqUaUN9q/YIOucc8gHQBzG
                    rmkObvyykzyPz5wddLmouqrZZqfufPTNh4whyABbXCPXsptDZZss8DlKS37rFVUKLHEhcfd1J+IO
                    ioaTnaPhgY/dXg==</ds:X509Certificate>
            </ds:X509Data>
        </ds:KeyInfo>
    </ds:Signature>
    <saml2:Subject>
        <!--the responding facade is the subject (eMed facade)-->
        <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:unspecified">initGW</saml2:NameID>
        <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:sender-vouches">
            <saml2:SubjectConfirmationData/>
        </saml2:SubjectConfirmation>
    </saml2:Subject>
    <saml2:Conditions NotBefore="2014-08-26T10:57:38.489Z" NotOnOrAfter="2014-08-26T11:02:38.489Z">
        <!--the audience is restricted to the responding facade (eMed facade)-->
        <saml2:AudienceRestriction>
            <saml2:Audience>http://zgf1:8081/ACSFacade/XDS/eMed</saml2:Audience>
        </saml2:AudienceRestriction>
    </saml2:Conditions>
    <saml2:AuthnStatement AuthnInstant="2014-08-26T10:57:38.489Z">
        <saml2:AuthnContext>
            <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PreviousSession</saml2:AuthnContextClassRef>
        </saml2:AuthnContext>
    </saml2:AuthnStatement>
    <saml2:AttributeStatement>
        <!--the subject includes the original XSPA Subject of the HCP Assertion coming from the local identity assertion -->
        <saml2:Attribute FriendlyName="XSPA Subject" Name="urn:oasis:names:tc:xacml:1.0:subject:subject-id" 
            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
            <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">
                Massi Doctor</saml2:AttributeValue>
        </saml2:Attribute>
        <!--role of the GDA coming from the GDA Index -->
        <saml2:Attribute FriendlyName="ELGA Rolle" Name="urn:oasis:names:tc:xacml:2.0:subject:role" 
            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
            <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:anyType">
                <Role code="702" codeSystem="1.2.40.0.34.5.3" codeSystemName="ELGA Rollen" displayName="Krankenanstalt" 
                    xmlns="urn:hl7-org:v3"/>
            </saml2:AttributeValue>
        </saml2:Attribute>
        <!--permissions for the GDA mapped from the role -->
        <saml2:Attribute FriendlyName="Permissions" Name="urn:elga:bes:permission" 
            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
            <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">
                urn:elga:bes:2013:permission:eBefunde</saml2:AttributeValue>
            <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">
                urn:elga:bes:2013:permission:eMedikation</saml2:AttributeValue>
        </saml2:Attribute>
        <!--ID of the GDA from the GDA Index (GDAIndex.ID:GDAIndex.IssuingAuthority) -->
        <saml2:Attribute FriendlyName="XSPA Organization ID (GDA-I)" Name="urn:oasis:names:tc:xspa:1.0:subject:organization-id" 
            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
            <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:anyURI">
                K434</saml2:AttributeValue>
        </saml2:Attribute>
        <!--the LPID of the responding community (will be the bPK-GH for eMed) -->
        <saml2:Attribute FriendlyName="XSPA PatientID (LPID)" Name="urn:oasis:names:tc:xacml:1.0:resource:resource-id" 
            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
            <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">
                GH:BPKLVLJUTSBVIYEV9+NIOC2QCI2EMQ=^^^&amp;1.2.40.0.10.2.1.1.149&amp;ISO</saml2:AttributeValue>
        </saml2:Attribute>
        <saml2:Attribute FriendlyName="Purpose Of Use" Name="urn:oasis:names:tc:xspa:1.0:subject:purposeofuse" 
            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
            <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">
                EMED_ID</saml2:AttributeValue>
        </saml2:Attribute>
        <!--bPK-GH of the patient -->
        <saml2:Attribute FriendlyName="Area specific personal identifier" Name="urn:elga:bes:2013:bPK-GH" 
            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
            <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:anyURI">
                GH:BPKLVLJUTSBVIYEV9+NIOC2QCI2EMQ=^^^&amp;1.2.40.0.10.2.1.1.149&amp;ISO</saml2:AttributeValue>
        </saml2:Attribute>
        <!--community ID of the initiating community -->
        <saml2:Attribute FriendlyName="XCA Home Community ID" Name="urn:ihe:iti:xca:2010:homeCommunityId" 
            NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
            <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:anyURI">
                Community.0.1</saml2:AttributeValue>
        </saml2:Attribute>
    </saml2:AttributeStatement>
    <!--policy statement including the individual or default response policy -->
    <xacml-saml:XACMLPolicyStatementType 
        xmlns:xacml-saml="urn:oasis:names:tc:xacml:2.0:profile:saml2.0:v2:schema:assertion">
        <PolicySet PolicyCombiningAlgId="urn:oasis:names:tc:xacml:1.0:policy-combining-algorithm:deny-overrides" 
            PolicySetId="polpermit" xmlns="urn:oasis:names:tc:xacml:2.0:policy:schema:os" 
            xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
            xsi:schemaLocation="urn:oasis:names:tc:xacml:2.0:policy:schema:os 
            http://docs.oasis-open.org/xacml/access_control-xacml-2.0-policy-schema-os.xsd">
            <Description>default opt-in policy</Description>
            <Target/>
            <PolicyIdReference>urn:elga:bes:2013:1.2.3.3.1.103.1</PolicyIdReference>
        </PolicySet>
    </xacml-saml:XACMLPolicyStatementType>
</saml2:Assertion>
