<soap:Envelope xmlns:soap="http://www.w3.org/2003/05/soap-envelope"
               xmlns:ds="http://www.w3.org/2000/09/xmldsig#"
               xmlns:epd="urn:e-health-suisse:2015:policy-administration"
               xmlns:wsa="http://www.w3.org/2005/08/addressing"
               xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd"
               xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
    <soap:Header>
        <wsa:Action>urn:e-health-suisse:2015:policy-enforcement:AuthorizationDecisionRequest</wsa:Action>
        <wsa:MessageID>urn:uuid:e4bb38c7-e546-4bb1-8d68-2bccf783dfbf</wsa:MessageID>
        <wsa:To>https://ehealthsuisse.ihe-europe.net/adr-provider?wsdl</wsa:To>
        <wsse:Security>

            <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
                             xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy"
                             xmlns:xs="http://www.w3.org/2001/XMLSchema"
                             xmlns:wst="http://docs.oasis-open.org/ws-sx/ws-trust/200512"
                             ID="_cb9d4dd8-fb3a-49b9-bd87-48689508a3f2"
                             IssueInstant="2017-12-11T14:22:52.731Z"
                             Version="2.0">
                <saml2:Issuer>https://ehealthsuisse.ihe-europe.net/STS</saml2:Issuer>
                <ds:Signature>
                    <ds:SignedInfo>
                        <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
                        <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
                        <ds:Reference URI="#_cb9d4dd8-fb3a-49b9-bd87-48689508a3f2">
                            <ds:Transforms>
                                <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
                                <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
                            </ds:Transforms>
                            <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
                            <ds:DigestValue>TWjPXjEGlG39oQSV2OmjlNrboAQ=</ds:DigestValue>
                        </ds:Reference>
                    </ds:SignedInfo>
                    <ds:SignatureValue>gzB13CQk83i7WHY2WrH4iIta4fMWTv3FG1u/fV6dvOTtGWJxqoZFHV/Fjh4t0ng/0a+8kcPHoFnIBjrYf5g7x+GYpjtKcT7E5ggGFubM8OXuMhrmoK0NNFaB7TRqf0y+gIs2nxQjDHO52p2KF6NT9Ibk3Rxnt4uEP6sxhwiFTX8=</ds:SignatureValue>
                    <ds:KeyInfo>
                        <ds:X509Data>
                            <ds:X509Certificate>MIIDhjCCAu+gAwIBAgIBCzANBgkqhkiG9w0BAQ0FADBFMQswCQYDVQQGEwJDSDEMMAoGA1UECgwD
                                SUhFMSgwJgYDVQQDDB9laGVhbHRoc3Vpc3NlLmloZS1ldXJvcGUubmV0IENBMB4XDTE3MDMyMjE2
                                MDgyNFoXDTI3MDMyMjE2MDgyNFowQjELMAkGA1UEBhMCQ0gxDDAKBgNVBAoMA0lIRTElMCMGA1UE
                                AwwcZWhlYWx0aHN1aXNzZS5paGUtZXVyb3BlLm5ldDCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkC
                                gYEAw5dTR17Y1w9cIhY0XSP9Cx7ThQ05YZTf4pKGgGb5ZZbFqm9Q5EKIrJT2EHE7MGO6D/miU3Jt
                                BUmexcf9ceftSXEW+FaNVAqDePBst4l2RSZeJvez0FmcbWcPeufsUumcGXGAJmNmSviMLd1IrMEh
                                whv6wuQvspY0Y2wAOvSkUmECAwEAAaOCAYcwggGDMEoGA1UdHwRDMEEwP6A9oDuGOWh0dHBzOi8v
                                ZWhlYWx0aHN1aXNzZS5paGUtZXVyb3BlLm5ldC9nc3MvY3JsLzIyL2NhY3JsLmNybDBIBglghkgB
                                hvhCAQQEOxY5aHR0cHM6Ly9laGVhbHRoc3Vpc3NlLmloZS1ldXJvcGUubmV0L2dzcy9jcmwvMjIv
                                Y2FjcmwuY3JsMEgGCWCGSAGG+EIBAwQ7FjlodHRwczovL2VoZWFsdGhzdWlzc2UuaWhlLWV1cm9w
                                ZS5uZXQvZ3NzL2NybC8yMi9jYWNybC5jcmwwCQYDVR0TBAIwADAOBgNVHQ8BAf8EBAMCBPAwEQYJ
                                YIZIAYb4QgEBBAQDAgXgMB0GA1UdDgQWBBSG1oKBcZvZJWlqKJ9i/67Htv7frDAfBgNVHSMEGDAW
                                gBQol+/d3jFYbFbyhkbiEeQ+OHFfLzAzBgNVHSUELDAqBggrBgEFBQcDAgYIKwYBBQUHAwQGCisG
                                AQQBgjcUAgIGCCsGAQUFBwMBMA0GCSqGSIb3DQEBDQUAA4GBAI1OT9P0oSrfNedZ4T4CfxPoUOFC
                                D1tU2X3iRAZFPoUHeFBiccsqMYnNlo3S2cKP6gxt+QPTGNSs171sS0MLa73aR8qrQC+vl5ZP7q4+
                                /3hYQLe+z3DjSflZNW6shSAp4vD43Dnd8OzgX41LRw1gSEWuAK/+7CedM6IkFEUV2NSF</ds:X509Certificate>
                        </ds:X509Data>
                    </ds:KeyInfo>
                </ds:Signature>
                <saml2:Subject>
                    <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"
                                  NameQualifier="urn:gs1:gln">7601000080776</saml2:NameID>
                    <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
                        <saml2:SubjectConfirmationData InResponseTo="_43ef3e4fefdb03a31781d7ea52617674bcd25a6c26"
                                                       NotOnOrAfter="2017-12-11T16:22:52.731Z"
                                                       Recipient="https://sp.community.ch/epd"/>
                    </saml2:SubjectConfirmation>
                </saml2:Subject>
                <saml2:Conditions NotBefore="2017-12-11T14:22:52.731Z" NotOnOrAfter="2017-12-11T16:22:52.731Z">
                    <saml2:AudienceRestriction>
                        <saml2:Audience>urn:e-health-suisse:token-audience:all-communities</saml2:Audience>
                    </saml2:AudienceRestriction>
                </saml2:Conditions>
                <saml2:AuthnStatement AuthnInstant="2017-12-11T14:22:52.731Z"
                                      SessionNotOnOrAfter="2017-12-11T16:22:52.731Z">
                    <saml2:AuthnContext>
                        <saml2:AuthnContextClassRef>http://bag.admin.ch/LoA/3</saml2:AuthnContextClassRef>
                    </saml2:AuthnContext>
                </saml2:AuthnStatement>
                <saml2:AttributeStatement>
                    <saml2:Attribute Name="urn:oasis:names:tc:xspa:1.0:subject:subject-id">
                        <saml2:AttributeValue>Alexander Maes</saml2:AttributeValue>
                    </saml2:Attribute>
                    <saml2:Attribute Name="urn:oasis:names:tc:xacml:2.0:subject:role">
                        <saml2:AttributeValue>
                            <Role xmlns="urn:hl7-org:v3" code="HCP" codeSystem="2.16.756.5.30.1.127.3.10.6"
                                  codeSystemName="eHealth Suisse EPR Akteure"
                                  displayName="Behandelnde(r)"
                                  xs:type="CE"/>
                        </saml2:AttributeValue>
                    </saml2:Attribute>
                    <saml2:Attribute Name="urn:oasis:names:tc:xspa:1.0:subject:organization">
                        <saml2:AttributeValue>Uni Spital Zurich</saml2:AttributeValue>
                    </saml2:Attribute>
                    <saml2:Attribute Name="urn:oasis:names:tc:xspa:1.0:subject:organization-id">
                        <saml2:AttributeValue>7601001355781</saml2:AttributeValue>
                    </saml2:Attribute>
                    <saml2:Attribute Name="urn:oasis:names:tc:xacml:2.0:resource:resource-id">
                        <saml2:AttributeValue>761337610435209810^^^SPID&amp;2.16.756.5.30.1.127.3.10.3&amp;ISO</saml2:AttributeValue>
                    </saml2:Attribute>
                    <saml2:Attribute Name="urn:oasis:names:tc:xspa:1.0:subject:purposeofuse">
                        <saml2:AttributeValue>
                            <PurposeOfUse xmlns="urn:hl7-org:v3" code="NORM" codeSystem="2.16.756.5.30.1.127.3.10.5"
                                          codeSystemName="eHealth Suisse Verwendungszweck"
                                          displayName="Normalzugriff"
                                          xs:type="CE"/>
                        </saml2:AttributeValue>
                    </saml2:Attribute>
                </saml2:AttributeStatement>
            </saml2:Assertion>
        </wsse:Security>
    </soap:Header>
    <soap:Body>
        <xacml-samlp:XACMLAuthzDecisionQuery xmlns:xacml-samlp="urn:oasis:names:tc:xacml:2.0:profile:saml2.0:v2:schema:protocol"
                                             xmlns:xacml-context="urn:oasis:names:tc:xacml:2.0:context:schema:os"
                                             xmlns:hl7="urn:hl7-org:v3"
                                             InputContextOnly="false"
                                             ReturnContext="false"
                                             ID="_682fee8b-46c0-442a-8c54-fd9d656412fc"
                                             Version="2.0"
                                             IssueInstant="2016-02-09T09:30:10.5Z">
            <xacml-context:Request>
                <xacml-context:Subject>
                    <xacml-context:Attribute AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-id"
                                             DataType="http://www.w3.org/2001/XMLSchema#string">
                        <xacml-context:AttributeValue>7601000080776</xacml-context:AttributeValue>
                    </xacml-context:Attribute>
                    <xacml-context:Attribute AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-id-qualifier"
                                             DataType="http://www.w3.org/2001/XMLSchema#anyURI">
                        <xacml-context:AttributeValue>urn:gs1:gln</xacml-context:AttributeValue>
                    </xacml-context:Attribute>
                    <xacml-context:Attribute AttributeId="urn:ihe:iti:xca:2010:homeCommunityId"
                                             DataType="http://www.w3.org/2001/XMLSchema#anyURI">
                        <xacml-context:AttributeValue>urn:oid:1.3.6.1.4.1.21367.2017.2.6.2</xacml-context:AttributeValue>
                    </xacml-context:Attribute>
                    <xacml-context:Attribute AttributeId="urn:oasis:names:tc:xacml:2.0:subject:role"
                                             DataType="urn:hl7-org:v3#CV">
                        <xacml-context:AttributeValue>
                            <hl7:CodedValue code="PAT" codeSystem="2.16.756.5.30.1.127.3.10.6" displayName="Patient(in)"/>
                        </xacml-context:AttributeValue>
                    </xacml-context:Attribute>
                    <xacml-context:Attribute AttributeId="urn:oasis:names:tc:xspa:1.0:subject:organization-id"
                                             DataType="http://www.w3.org/2001/XMLSchema#anyURI">
                        <xacml-context:AttributeValue>urn:oid:1.3.6.1.4.1.21367.2017.2.6.2</xacml-context:AttributeValue>
                    </xacml-context:Attribute>
                    <xacml-context:Attribute AttributeId="urn:oasis:names:tc:xspa:1.0:subject:purposeofuse"
                                             DataType="urn:hl7-org:v3#CV">
                        <xacml-context:AttributeValue>
                            <hl7:CodedValue code="NORM" codeSystem="2.16.756.5.30.1.127.3.10.5" displayName="Normalzugriff"/>
                        </xacml-context:AttributeValue>
                    </xacml-context:Attribute>
                </xacml-context:Subject>

                <xacml-context:Resource>
                    <xacml-context:Attribute AttributeId="urn:oasis:names:tc:xacml:1.0:resource:resource-id"
                                             DataType="http://www.w3.org/2001/XMLSchema#anyURI">
                        <xacml-context:AttributeValue>66ad46fb-3b23-4e82-98f6-6571e5924b27</xacml-context:AttributeValue>
                    </xacml-context:Attribute>
                    <xacml-context:Attribute AttributeId="urn:e-health-suisse:2015:epr-spid" DataType="urn:hl7-org:v3#II">
                        <xacml-context:AttributeValue>
                            <hl7:InstanceIdentifier root="2.16.756.5.30.1.127.3.10.3" extension="761337610455909127"/>
                        </xacml-context:AttributeValue>
                    </xacml-context:Attribute>
                    <xacml-context:Attribute AttributeId="urn:e-health-suisse:2015:policy-attributes:referenced-policy-set"
                                             DataType="http://www.w3.org/2001/XMLSchema#anyURI">
                        <xacml-context:AttributeValue>urn:e-health-suisse:2015:policies:exclusion-list</xacml-context:AttributeValue>
                    </xacml-context:Attribute>
                </xacml-context:Resource>
                <xacml-context:Resource>
                    <xacml-context:Attribute AttributeId="urn:oasis:names:tc:xacml:1.0:resource:resource-id"
                                             DataType="http://www.w3.org/2001/XMLSchema#anyURI">
                        <xacml-context:AttributeValue>e4ad4bc1-1f8b-4893-8a4b-758cd3cb0274</xacml-context:AttributeValue>
                    </xacml-context:Attribute>
                    <xacml-context:Attribute AttributeId="urn:e-health-suisse:2015:epr-spid" DataType="urn:hl7-org:v3#II">
                        <xacml-context:AttributeValue>
                            <hl7:InstanceIdentifier root="2.16.756.5.30.1.127.3.10.3" extension="761337610436974489"/>
                        </xacml-context:AttributeValue>
                    </xacml-context:Attribute>
                    <xacml-context:Attribute AttributeId="urn:e-health-suisse:2015:policy-attributes:referenced-policy-set"
                                             DataType="http://www.w3.org/2001/XMLSchema#anyURI">
                        <xacml-context:AttributeValue>urn:e-health-suisse:2015:policies:exclusion-list</xacml-context:AttributeValue>
                    </xacml-context:Attribute>
                </xacml-context:Resource>

                <xacml-context:Action>
                    <xacml-context:Attribute AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id"
                                             DataType="http://www.w3.org/2001/XMLSchema#anyURI">
                        <xacml-context:AttributeValue>urn:e-health-suisse:2015:policy-administration:AddPolicy</xacml-context:AttributeValue>
                    </xacml-context:Attribute>
                </xacml-context:Action>
                <xacml-context:Environment/>
            </xacml-context:Request>
        </xacml-samlp:XACMLAuthzDecisionQuery>
    </soap:Body>
</soap:Envelope>
