<!--
 This is example metadata only. Do *NOT* supply it as is without review,
and do *NOT* provide it in real time to your partners.
This metadata is not dynamic - it will not change as your configuration changes.
On Demand Metadata Generation available from the metadatagen plugin.
-->
<md:EntityDescriptor entityID="https://idp.hertie-school.org/idp/shibboleth" xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
    <md:Extensions>
      <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
        <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
          <saml:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xs="http://www.w3.org/2001/XMLSchema" xsi:type="xs:string">https://refeds.org/sirtfi</saml:AttributeValue>
        </saml:Attribute>
        <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category-support" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
          <saml:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xs="http://www.w3.org/2001/XMLSchema" xsi:type="xs:string">http://refeds.org/category/research-and-scholarship</saml:AttributeValue>
        </saml:Attribute>
        <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
          <saml:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xs="http://www.w3.org/2001/XMLSchema" xsi:type="xs:string">http://www.geant.net/uri/dataprotection-code-of-conduct/v1</saml:AttributeValue>
        </saml:Attribute>
      </mdattr:EntityAttributes>
    </md:Extensions>
    <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
        <md:Extensions>
            <shibmd:Scope regexp="false">hertie-school.org</shibmd:Scope>
            <mdui:UIInfo>
                <mdui:DisplayName xml:lang="de">Hertie School - School of Governance</mdui:DisplayName>
                <mdui:DisplayName xml:lang="en">Hertie School - School of Governance</mdui:DisplayName>
                <mdui:Description xml:lang="de">Hertie School - School of Governance</mdui:Description>
                <mdui:Description xml:lang="en">Hertie School - School of Governance</mdui:Description>
		<mdui:InformationURL xml:lang="de">https://www.hertie-school.org/de/</mdui:InformationURL>
        	<mdui:InformationURL xml:lang="en">https://www.hertie-school.org/en/</mdui:InformationURL>
        	<mdui:PrivacyStatementURL xml:lang="de">https://www.hertie-school.org/de/navigations/footer-service/privacy-policy</mdui:PrivacyStatementURL>
        	<mdui:PrivacyStatementURL xml:lang="en">https://www.hertie-school.org/en/privacy-policy</mdui:PrivacyStatementURL>
                <mdui:Logo xml:lang="en" width="80" height="80">https://idp.hertie-school.org/azure_square_logo_150x150.png</mdui:Logo>
            </mdui:UIInfo>
        </md:Extensions>
        <md:KeyDescriptor use="signing">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
MIIEETCCAnmgAwIBAgIUHvS9E+JdYmhmp42YCmAEg6mzgxAwDQYJKoZIhvcNAQEL
BQAwIDEeMBwGA1UEAxMVaWRwLmhlcnRpZS1zY2hvb2wub3JnMB4XDTI0MDcwNTE1
MDkxNloXDTI3MDkxODE1MDkxNlowIDEeMBwGA1UEAxMVaWRwLmhlcnRpZS1zY2hv
b2wub3JnMIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEAuckjMRkIggE3
vRgddkvC4Eqch8HNRHi+GPVan0Qt2XdepaEMjCSluahCB1HuYFnOpjWFIZ21OSdn
+VCYAyD0+0mNHepy3cOeqEsvM0ExCgzkr2XwLxLfza7bwIwiSKhdKgcMcOFfh4Ax
Nypo+cwT1kdMiZ9S7gKLl5W3+u3buQRgxdOefK3L3RChu0ddu/9yKcmsvy6htzjV
wnVc8Asfyciz1J/fKOg6cAY5LiCeAXWGRAs3eyonoAmI3b6gOLloGAKtQLf+uK2U
x/cy7/ocaPnmkVbIWMnSle+3YZyNx1ZEO1fezb763Tz9R08i5gc5Z/R8XRt3EQkT
wql8HbxnZ3gl9k1H5ot/4Jp1ODRSUggXMT44FkdFkgzEYPKtcWc/VNLaXQNqbVy1
uzJxuzB98tBnW11Winqs+aekKiuC+h+ZKwErcAZHOdI10xigfJGJPB1CYNN+lMK9
+QMhPzrQLzPmR6rhLa+Svy+SFffzVfFxvdMuVGV6TJtyWecaAsfjAgMBAAGjQzBB
MCAGA1UdEQQZMBeCFWlkcC5oZXJ0aWUtc2Nob29sLm9yZzAdBgNVHQ4EFgQUPS+F
bzz9U7+pjDqUQTRMeNWiXH0wDQYJKoZIhvcNAQELBQADggGBAEXj69pThIEzoJO1
tYhyyJATlpciZevGBKPoSCx9ZnosnEVjWHeBzj7uV2FTL8LtmIMeLt4vz6UVjpEr
vp2o7QtTkdeYHTkJ3fhB+Zoktrok8nx7SNE6MM/We5NQhZ70NUTfjX+ccekP/a2A
kuZQyd7/3w7BqorSTBfosPz8Mhbl0Kl4B1hm1JBeQ2QxeUaIsW7r2meBn3ByKWzN
F5Oa1GCS8v1sVU74Nq1QUh3uTM9bLUNfqI5veh/o209Hb4DE9G36lCIStwLIk2SS
dnge33iCeTlqWg6rnDfn4xwT/O0qBHMsx3agaaNAnuKvI8qXJm4H4cXgETaAGYMQ
mdymay1hopi11pT0XrApDIzDkbZdYUQANnEd4DL+PTR0Y7uPFqyGcnd+2Vb/QTtO
Q+kXwUdJ6Y8ktRZsPKUV35omhZR1idcfo7zOa1xxnx0AnpEzooMJdcgH0ek9u91I
VmUpRME+DQOCONLrzX7q8XwYadCB/EA50C8cHzm2k+XFfqNHlw==
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </md:KeyDescriptor>
        <md:KeyDescriptor use="signing">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
MIIEETCCAnmgAwIBAgIUHvS9E+JdYmhmp42YCmAEg6mzgxAwDQYJKoZIhvcNAQEL
BQAwIDEeMBwGA1UEAxMVaWRwLmhlcnRpZS1zY2hvb2wub3JnMB4XDTI0MDcwNTE1
MDkxNloXDTI3MDkxODE1MDkxNlowIDEeMBwGA1UEAxMVaWRwLmhlcnRpZS1zY2hv
b2wub3JnMIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEAuckjMRkIggE3
vRgddkvC4Eqch8HNRHi+GPVan0Qt2XdepaEMjCSluahCB1HuYFnOpjWFIZ21OSdn
+VCYAyD0+0mNHepy3cOeqEsvM0ExCgzkr2XwLxLfza7bwIwiSKhdKgcMcOFfh4Ax
Nypo+cwT1kdMiZ9S7gKLl5W3+u3buQRgxdOefK3L3RChu0ddu/9yKcmsvy6htzjV
wnVc8Asfyciz1J/fKOg6cAY5LiCeAXWGRAs3eyonoAmI3b6gOLloGAKtQLf+uK2U
x/cy7/ocaPnmkVbIWMnSle+3YZyNx1ZEO1fezb763Tz9R08i5gc5Z/R8XRt3EQkT
wql8HbxnZ3gl9k1H5ot/4Jp1ODRSUggXMT44FkdFkgzEYPKtcWc/VNLaXQNqbVy1
uzJxuzB98tBnW11Winqs+aekKiuC+h+ZKwErcAZHOdI10xigfJGJPB1CYNN+lMK9
+QMhPzrQLzPmR6rhLa+Svy+SFffzVfFxvdMuVGV6TJtyWecaAsfjAgMBAAGjQzBB
MCAGA1UdEQQZMBeCFWlkcC5oZXJ0aWUtc2Nob29sLm9yZzAdBgNVHQ4EFgQUPS+F
bzz9U7+pjDqUQTRMeNWiXH0wDQYJKoZIhvcNAQELBQADggGBAEXj69pThIEzoJO1
tYhyyJATlpciZevGBKPoSCx9ZnosnEVjWHeBzj7uV2FTL8LtmIMeLt4vz6UVjpEr
vp2o7QtTkdeYHTkJ3fhB+Zoktrok8nx7SNE6MM/We5NQhZ70NUTfjX+ccekP/a2A
kuZQyd7/3w7BqorSTBfosPz8Mhbl0Kl4B1hm1JBeQ2QxeUaIsW7r2meBn3ByKWzN
F5Oa1GCS8v1sVU74Nq1QUh3uTM9bLUNfqI5veh/o209Hb4DE9G36lCIStwLIk2SS
dnge33iCeTlqWg6rnDfn4xwT/O0qBHMsx3agaaNAnuKvI8qXJm4H4cXgETaAGYMQ
mdymay1hopi11pT0XrApDIzDkbZdYUQANnEd4DL+PTR0Y7uPFqyGcnd+2Vb/QTtO
Q+kXwUdJ6Y8ktRZsPKUV35omhZR1idcfo7zOa1xxnx0AnpEzooMJdcgH0ek9u91I
VmUpRME+DQOCONLrzX7q8XwYadCB/EA50C8cHzm2k+XFfqNHlw==
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </md:KeyDescriptor>
        <md:KeyDescriptor use="encryption">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
MIIEETCCAnmgAwIBAgIUHvS9E+JdYmhmp42YCmAEg6mzgxAwDQYJKoZIhvcNAQEL
BQAwIDEeMBwGA1UEAxMVaWRwLmhlcnRpZS1zY2hvb2wub3JnMB4XDTI0MDcwNTE1
MDkxNloXDTI3MDkxODE1MDkxNlowIDEeMBwGA1UEAxMVaWRwLmhlcnRpZS1zY2hv
b2wub3JnMIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEAuckjMRkIggE3
vRgddkvC4Eqch8HNRHi+GPVan0Qt2XdepaEMjCSluahCB1HuYFnOpjWFIZ21OSdn
+VCYAyD0+0mNHepy3cOeqEsvM0ExCgzkr2XwLxLfza7bwIwiSKhdKgcMcOFfh4Ax
Nypo+cwT1kdMiZ9S7gKLl5W3+u3buQRgxdOefK3L3RChu0ddu/9yKcmsvy6htzjV
wnVc8Asfyciz1J/fKOg6cAY5LiCeAXWGRAs3eyonoAmI3b6gOLloGAKtQLf+uK2U
x/cy7/ocaPnmkVbIWMnSle+3YZyNx1ZEO1fezb763Tz9R08i5gc5Z/R8XRt3EQkT
wql8HbxnZ3gl9k1H5ot/4Jp1ODRSUggXMT44FkdFkgzEYPKtcWc/VNLaXQNqbVy1
uzJxuzB98tBnW11Winqs+aekKiuC+h+ZKwErcAZHOdI10xigfJGJPB1CYNN+lMK9
+QMhPzrQLzPmR6rhLa+Svy+SFffzVfFxvdMuVGV6TJtyWecaAsfjAgMBAAGjQzBB
MCAGA1UdEQQZMBeCFWlkcC5oZXJ0aWUtc2Nob29sLm9yZzAdBgNVHQ4EFgQUPS+F
bzz9U7+pjDqUQTRMeNWiXH0wDQYJKoZIhvcNAQELBQADggGBAEXj69pThIEzoJO1
tYhyyJATlpciZevGBKPoSCx9ZnosnEVjWHeBzj7uV2FTL8LtmIMeLt4vz6UVjpEr
vp2o7QtTkdeYHTkJ3fhB+Zoktrok8nx7SNE6MM/We5NQhZ70NUTfjX+ccekP/a2A
kuZQyd7/3w7BqorSTBfosPz8Mhbl0Kl4B1hm1JBeQ2QxeUaIsW7r2meBn3ByKWzN
F5Oa1GCS8v1sVU74Nq1QUh3uTM9bLUNfqI5veh/o209Hb4DE9G36lCIStwLIk2SS
dnge33iCeTlqWg6rnDfn4xwT/O0qBHMsx3agaaNAnuKvI8qXJm4H4cXgETaAGYMQ
mdymay1hopi11pT0XrApDIzDkbZdYUQANnEd4DL+PTR0Y7uPFqyGcnd+2Vb/QTtO
Q+kXwUdJ6Y8ktRZsPKUV35omhZR1idcfo7zOa1xxnx0AnpEzooMJdcgH0ek9u91I
VmUpRME+DQOCONLrzX7q8XwYadCB/EA50C8cHzm2k+XFfqNHlw==
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </md:KeyDescriptor>
        <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.hertie-school.org/idp/profile/SAML2/SOAP/ArtifactResolution" />
        <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.hertie-school.org/idp/profile/SAML2/POST-SimpleSign/SSO" />
        <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.hertie-school.org/idp/profile/SAML2/Redirect/SSO" />
        <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.hertie-school.org/idp/profile/SAML2/POST/SSO" />
        <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
    </md:IDPSSODescriptor>

    <md:Organization>
      <md:OrganizationName xml:lang="de">Hertie School - School of Governance</md:OrganizationName>
      <md:OrganizationName xml:lang="en">Hertie School - School of Governance</md:OrganizationName>
      <md:OrganizationDisplayName xml:lang="de">Hertie School - School of Governance</md:OrganizationDisplayName>
      <md:OrganizationDisplayName xml:lang="en">Hertie School - School of Governance</md:OrganizationDisplayName>
      <md:OrganizationURL xml:lang="de">https://www.hertie-school.org/</md:OrganizationURL>
      <md:OrganizationURL xml:lang="en">https://www.hertie-school.org/</md:OrganizationURL>
    </md:Organization>
    <md:ContactPerson contactType="technical">
      <md:Company>Hertie School gGmbh</md:Company>
      <md:GivenName>IT Servicedesk</md:GivenName>
      <md:SurName>Hertie School</md:SurName>
      <md:EmailAddress>mailto:servicedesk@hertie-school.org</md:EmailAddress>
    </md:ContactPerson>
    <md:ContactPerson contactType="support">
      <md:Company>Hertie School gGmbh</md:Company>
      <md:GivenName>IT Servicedesk</md:GivenName>
      <md:SurName>Hertie School</md:SurName>
      <md:EmailAddress>mailto:servicedesk@hertie-school.org</md:EmailAddress>
    </md:ContactPerson>
    <md:ContactPerson contactType="other" xmlns:remd="http://refeds.org/metadata" remd:contactType="http://refeds.org/metadata/contactType/security">
      <md:Company>Hertie School gGmbh</md:Company>
      <md:GivenName>IT Servicedesk</md:GivenName>
      <md:SurName>Hertie School</md:SurName>
      <md:EmailAddress>mailto:servicedesk@hertie-school.org</md:EmailAddress>
    </md:ContactPerson>

    <!-- New SP block -->
    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
MIIEETCCAnmgAwIBAgIUHvS9E+JdYmhmp42YCmAEg6mzgxAwDQYJKoZIhvcNAQEL
BQAwIDEeMBwGA1UEAxMVaWRwLmhlcnRpZS1zY2hvb2wub3JnMB4XDTI0MDcwNTE1
MDkxNloXDTI3MDkxODE1MDkxNlowIDEeMBwGA1UEAxMVaWRwLmhlcnRpZS1zY2hv
b2wub3JnMIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEAuckjMRkIggE3
vRgddkvC4Eqch8HNRHi+GPVan0Qt2XdepaEMjCSluahCB1HuYFnOpjWFIZ21OSdn
+VCYAyD0+0mNHepy3cOeqEsvM0ExCgzkr2XwLxLfza7bwIwiSKhdKgcMcOFfh4Ax
Nypo+cwT1kdMiZ9S7gKLl5W3+u3buQRgxdOefK3L3RChu0ddu/9yKcmsvy6htzjV
wnVc8Asfyciz1J/fKOg6cAY5LiCeAXWGRAs3eyonoAmI3b6gOLloGAKtQLf+uK2U
x/cy7/ocaPnmkVbIWMnSle+3YZyNx1ZEO1fezb763Tz9R08i5gc5Z/R8XRt3EQkT
wql8HbxnZ3gl9k1H5ot/4Jp1ODRSUggXMT44FkdFkgzEYPKtcWc/VNLaXQNqbVy1
uzJxuzB98tBnW11Winqs+aekKiuC+h+ZKwErcAZHOdI10xigfJGJPB1CYNN+lMK9
+QMhPzrQLzPmR6rhLa+Svy+SFffzVfFxvdMuVGV6TJtyWecaAsfjAgMBAAGjQzBB
MCAGA1UdEQQZMBeCFWlkcC5oZXJ0aWUtc2Nob29sLm9yZzAdBgNVHQ4EFgQUPS+F
bzz9U7+pjDqUQTRMeNWiXH0wDQYJKoZIhvcNAQELBQADggGBAEXj69pThIEzoJO1
tYhyyJATlpciZevGBKPoSCx9ZnosnEVjWHeBzj7uV2FTL8LtmIMeLt4vz6UVjpEr
vp2o7QtTkdeYHTkJ3fhB+Zoktrok8nx7SNE6MM/We5NQhZ70NUTfjX+ccekP/a2A
kuZQyd7/3w7BqorSTBfosPz8Mhbl0Kl4B1hm1JBeQ2QxeUaIsW7r2meBn3ByKWzN
F5Oa1GCS8v1sVU74Nq1QUh3uTM9bLUNfqI5veh/o209Hb4DE9G36lCIStwLIk2SS
dnge33iCeTlqWg6rnDfn4xwT/O0qBHMsx3agaaNAnuKvI8qXJm4H4cXgETaAGYMQ
mdymay1hopi11pT0XrApDIzDkbZdYUQANnEd4DL+PTR0Y7uPFqyGcnd+2Vb/QTtO
Q+kXwUdJ6Y8ktRZsPKUV35omhZR1idcfo7zOa1xxnx0AnpEzooMJdcgH0ek9u91I
VmUpRME+DQOCONLrzX7q8XwYadCB/EA50C8cHzm2k+XFfqNHlw==
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>
MIIEETCCAnmgAwIBAgIUHvS9E+JdYmhmp42YCmAEg6mzgxAwDQYJKoZIhvcNAQEL
BQAwIDEeMBwGA1UEAxMVaWRwLmhlcnRpZS1zY2hvb2wub3JnMB4XDTI0MDcwNTE1
MDkxNloXDTI3MDkxODE1MDkxNlowIDEeMBwGA1UEAxMVaWRwLmhlcnRpZS1zY2hv
b2wub3JnMIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEAuckjMRkIggE3
vRgddkvC4Eqch8HNRHi+GPVan0Qt2XdepaEMjCSluahCB1HuYFnOpjWFIZ21OSdn
+VCYAyD0+0mNHepy3cOeqEsvM0ExCgzkr2XwLxLfza7bwIwiSKhdKgcMcOFfh4Ax
Nypo+cwT1kdMiZ9S7gKLl5W3+u3buQRgxdOefK3L3RChu0ddu/9yKcmsvy6htzjV
wnVc8Asfyciz1J/fKOg6cAY5LiCeAXWGRAs3eyonoAmI3b6gOLloGAKtQLf+uK2U
x/cy7/ocaPnmkVbIWMnSle+3YZyNx1ZEO1fezb763Tz9R08i5gc5Z/R8XRt3EQkT
wql8HbxnZ3gl9k1H5ot/4Jp1ODRSUggXMT44FkdFkgzEYPKtcWc/VNLaXQNqbVy1
uzJxuzB98tBnW11Winqs+aekKiuC+h+ZKwErcAZHOdI10xigfJGJPB1CYNN+lMK9
+QMhPzrQLzPmR6rhLa+Svy+SFffzVfFxvdMuVGV6TJtyWecaAsfjAgMBAAGjQzBB
MCAGA1UdEQQZMBeCFWlkcC5oZXJ0aWUtc2Nob29sLm9yZzAdBgNVHQ4EFgQUPS+F
bzz9U7+pjDqUQTRMeNWiXH0wDQYJKoZIhvcNAQELBQADggGBAEXj69pThIEzoJO1
tYhyyJATlpciZevGBKPoSCx9ZnosnEVjWHeBzj7uV2FTL8LtmIMeLt4vz6UVjpEr
vp2o7QtTkdeYHTkJ3fhB+Zoktrok8nx7SNE6MM/We5NQhZ70NUTfjX+ccekP/a2A
kuZQyd7/3w7BqorSTBfosPz8Mhbl0Kl4B1hm1JBeQ2QxeUaIsW7r2meBn3ByKWzN
F5Oa1GCS8v1sVU74Nq1QUh3uTM9bLUNfqI5veh/o209Hb4DE9G36lCIStwLIk2SS
dnge33iCeTlqWg6rnDfn4xwT/O0qBHMsx3agaaNAnuKvI8qXJm4H4cXgETaAGYMQ
mdymay1hopi11pT0XrApDIzDkbZdYUQANnEd4DL+PTR0Y7uPFqyGcnd+2Vb/QTtO
Q+kXwUdJ6Y8ktRZsPKUV35omhZR1idcfo7zOa1xxnx0AnpEzooMJdcgH0ek9u91I
VmUpRME+DQOCONLrzX7q8XwYadCB/EA50C8cHzm2k+XFfqNHlw==
                    </ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
 
        <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.hertie-school.org/idp/profile/Authn/SAML2/POST/SSO" index="0"/>
    </SPSSODescriptor>
</md:EntityDescriptor>
