<saml:Assertion
  ID="idvalue31231231231312"
  IssueInstant="2001-12-31T12:00:00"
  Version="2.0"
  xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
  xmlns:xs="http://www.w3.org/2001/XMLSchema"
  xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
  xmlns:ds="http://www.w3.org/2000/09/xmldsig#"
  xsi:schemaLocation="urn:oasis:names:tc:SAML:2.0:assertion http://docs.oasis-open.org/security/saml/v2.0/saml-schema-assertion-2.0.xsd
  http://www.w3.org/2000/09/xmldsig# http://www.w3.org/TR/2002/REC-xmldsig-core-20020212/xmldsig-core-schema.xsd">
  <saml:Issuer>http://SomeIdentityProvider.dk/IdpService</saml:Issuer>
  <ds:Signature>
    <ds:SignedInfo>
      <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
      <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1" />
      <ds:Reference URI="#idvalue31231231231312">
        <ds:Transforms>
          <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#envelopedsignature" />
        </ds:Transforms>
        <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1" />
        <ds:DigestValue>TCDVSuG6grhyHbzhQFWFzGrxIPE=</ds:DigestValue>
      </ds:Reference>
    </ds:SignedInfo>
    <ds:SignatureValue>
      x/GyPbzmFEe85pGD3c1aXG4Vspb9V9jGCjwcRCKrtwPS6vdVNCcY5rHaFPYWkf+5
      EIYcPzx+pX1h43SmwviCqXRjRtMANWbHLhWAptaK1ywS7gFgsD01qjyen3CP+m3D
      w6vKhaqledl0BYyrIzb4KkHO4ahNyBVXbJwqv5pUaE4=
    </ds:SignatureValue>
    <ds:KeyInfo>
      <ds:X509Data>
        <!-- The Identity Provider's OCES Certificate -->
        <ds:X509Certificate>
          MIICyjCCAjOgAwIBAgICAnUwDQYJKoZIhvcNAQEEBQAwgakxCzAJBgNVBAYTAlVT
          MRIwEAYDVQQIEwlXaXNjb25zaW4xEDAOBgNVBAcTB01hZGlzb24xIDAeBgNVBAoT
          F1VuaXZlcnNpdHkgb2YgV2lzY29uc2luMSswKQYDVQQLEyJEaXZp
        </ds:X509Certificate>
      </ds:X509Data>
    </ds:KeyInfo>
  </ds:Signature>
  <saml:Subject>
    <saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName">
      C=DK,O=Pølsevognen,CN=Hans Jensen
    </saml:NameID>
    <saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
      <saml:SubjectConfirmationData
        Recipient="http://SomeServiceProvider.dk"
        NotOnOrAfter="2001-12-31T12:00:00"
        InResponseTo="Authn_request_identifier_1234567">
      </saml:SubjectConfirmationData>
    </saml:SubjectConfirmation>
  </saml:Subject>
  <saml:Conditions>
    <saml:AudienceRestriction>
      <saml:Audience>http://SomeServiceProvider.dk</saml:Audience>
    </saml:AudienceRestriction>
  </saml:Conditions>
  <saml:AuthnStatement
    AuthnInstant="2005-01-31T12:00:00Z"
    SessionIndex="29393948329">
    <saml:AuthnContext>
      <saml:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:X509</saml:AuthnContextClassRef>
    </saml:AuthnContext>
  </saml:AuthnStatement>
  <saml:AttributeStatement>
    <!-- Sur Name Core Attribute -->
    <saml:Attribute
      NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"
      Name="urn:oid:2.5.4.4"
      FriendlyName="surName">
      <saml:AttributeValue xsi:type="xs:string">Jensen</saml:AttributeValue>
    </saml:Attribute>
    <!-- Common Name Core Attribute -->
    <saml:Attribute
      NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"
      Name="urn:oid:2.5.4.3"
      FriendlyName="CommonName">
      <saml:AttributeValue xsi:type="xs:string">Hans Jensen</saml:AttributeValue>
    </saml:Attribute>
    <!-- Uid Core Attribute this is the Subject Serial Number -->
    <saml:Attribute
      NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"
      Name="urn:oid:0.9.2342.19200300.100.1.1">
      <saml:AttributeValue xsi:type="xs:string">PID:9802-2002-2-149339142439</saml:AttributeValue>
    </saml:Attribute>
    <!-- Email Core Attribute -->
    <saml:Attribute
      NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"
      Name="urn:oid:0.9.2342.19200300.100.1.3"
      FriendlyName="email">
      <saml:AttributeValue xsi:type="xs:string">jens@email.dk</saml:AttributeValue>
    </saml:Attribute>
    <!-- Assurance Level Core Attribute -->
    <saml:Attribute
      NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"
      Name="dk:gov:saml:attribute:AssuranceLevel">
      <saml:AttributeValue xsi:type="xs:string">2</saml:AttributeValue>
    </saml:Attribute>
    <!-- SpecVer Core Attribute -->
    <saml:Attribute
      NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"
      Name="dk:gov:saml:attribute:SpecVer">
      <saml:AttributeValue xsi:type="xs:string">DK-SAML-2.0</saml:AttributeValue>
    </saml:Attribute>
    <!-- Now comes attributes from the OCES attribute profile -->
    <!--- Certificate Serial Number Attribute -->
    <saml:Attribute
      NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"
      Name="urn:oid:2.5.4.5"
      FriendlyName="serialNumber">
      <saml:AttributeValue xsi:type="xs:string">234-2345-76745-23</saml:AttributeValue>
    </saml:Attribute>
    <!--- PID Number Attribute -->
    <saml:Attribute
      NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"
      Name="dk:gov:saml:attribute:PidNumberIdentifier">
      <saml:AttributeValue xsi:type="xs:string">9802-2002-2-9142544</saml:AttributeValue>
    </saml:Attribute>
    <!--- CPR Number Attribute -->
    <saml:Attribute
      NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"
      Name="dk:gov:saml:attribute:CprNumberIdentifier">
      <saml:AttributeValue xsi:type="xs:string">2702681273</saml:AttributeValue>
    </saml:Attribute>
  </saml:AttributeStatement>
</saml:Assertion>