<soap:Envelope xmlns:soap="http://www.w3.org/2003/05/soap-envelope"
               xmlns:xd="http://www.w3.org/2000/09/xmldsig#"
               xmlns:xe="http://www.w3.org/2001/04/xmlenc#">
    <soap:Header xmlns:wsa="http://www.w3.org/2005/08/addressing">
        <wsa:Action>urn:e-health-suisse:2015:policy-administration:AddPolicy</wsa:Action>
        <wsa:MessageID>306de2f9-f272-4eff-bedc-45e8ea825575</wsa:MessageID>
        <wsa:ReplyTo>
            <wsa:Address>http://www.w3.org/2005/08/addressing/anonymous</wsa:Address>
        </wsa:ReplyTo>
        <wsa:To/>
        <wss:Security xmlns:wss="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd">
            <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
                             xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy"
                             xmlns:xs="http://www.w3.org/2001/XMLSchema"
                             xmlns:wst="http://docs.oasis-open.org/ws-sx/ws-trust/200512"
                             ID="_6b3d4e66-3b5f-4d84-b4b3-40da2bd6eae9"
                             IssueInstant="2017-12-11T14:48:14.494Z"
                             Version="2.0">
                <saml2:Issuer>https://ehealthsuisse.ihe-europe.net/STS</saml2:Issuer>
                <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                    <ds:SignedInfo>
                        <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
                        <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
                        <ds:Reference URI="#_6b3d4e66-3b5f-4d84-b4b3-40da2bd6eae9">
                            <ds:Transforms>
                                <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
                                <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
                            </ds:Transforms>
                            <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
                            <ds:DigestValue>qwiTWwUO2wQmaWC3ng9ABcxFwd4=</ds:DigestValue>
                        </ds:Reference>
                    </ds:SignedInfo>
                    <ds:SignatureValue>uHgNUKuPgWHhfOSsmUldk0RrZBHGZs+moo0YJ0l1i0JPqb/6UVy2bv4AppHpxJf5wL1hJx14wmG5+i/Od5YNvTZmJPu3d8+qMc0+deappCU5zdcwvC439flsXBnGkE8Ou4H4tEl1DKXEOXUbDZQbmRwrDji07YfVvGncGlemiLY=</ds:SignatureValue>
                    <ds:KeyInfo>
                        <ds:X509Data>
                            <ds:X509Certificate>MIIDhjCCAu+gAwIBAgIBCzANBgkqhkiG9w0BAQ0FADBFMQswCQYDVQQGEwJDSDEMMAoGA1UECgwD
                                SUhFMSgwJgYDVQQDDB9laGVhbHRoc3Vpc3NlLmloZS1ldXJvcGUubmV0IENBMB4XDTE3MDMyMjE2
                                MDgyNFoXDTI3MDMyMjE2MDgyNFowQjELMAkGA1UEBhMCQ0gxDDAKBgNVBAoMA0lIRTElMCMGA1UE
                                AwwcZWhlYWx0aHN1aXNzZS5paGUtZXVyb3BlLm5ldDCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkC
                                gYEAw5dTR17Y1w9cIhY0XSP9Cx7ThQ05YZTf4pKGgGb5ZZbFqm9Q5EKIrJT2EHE7MGO6D/miU3Jt
                                BUmexcf9ceftSXEW+FaNVAqDePBst4l2RSZeJvez0FmcbWcPeufsUumcGXGAJmNmSviMLd1IrMEh
                                whv6wuQvspY0Y2wAOvSkUmECAwEAAaOCAYcwggGDMEoGA1UdHwRDMEEwP6A9oDuGOWh0dHBzOi8v
                                ZWhlYWx0aHN1aXNzZS5paGUtZXVyb3BlLm5ldC9nc3MvY3JsLzIyL2NhY3JsLmNybDBIBglghkgB
                                hvhCAQQEOxY5aHR0cHM6Ly9laGVhbHRoc3Vpc3NlLmloZS1ldXJvcGUubmV0L2dzcy9jcmwvMjIv
                                Y2FjcmwuY3JsMEgGCWCGSAGG+EIBAwQ7FjlodHRwczovL2VoZWFsdGhzdWlzc2UuaWhlLWV1cm9w
                                ZS5uZXQvZ3NzL2NybC8yMi9jYWNybC5jcmwwCQYDVR0TBAIwADAOBgNVHQ8BAf8EBAMCBPAwEQYJ
                                YIZIAYb4QgEBBAQDAgXgMB0GA1UdDgQWBBSG1oKBcZvZJWlqKJ9i/67Htv7frDAfBgNVHSMEGDAW
                                gBQol+/d3jFYbFbyhkbiEeQ+OHFfLzAzBgNVHSUELDAqBggrBgEFBQcDAgYIKwYBBQUHAwQGCisG
                                AQQBgjcUAgIGCCsGAQUFBwMBMA0GCSqGSIb3DQEBDQUAA4GBAI1OT9P0oSrfNedZ4T4CfxPoUOFC
                                D1tU2X3iRAZFPoUHeFBiccsqMYnNlo3S2cKP6gxt+QPTGNSs171sS0MLa73aR8qrQC+vl5ZP7q4+
                                /3hYQLe+z3DjSflZNW6shSAp4vD43Dnd8OzgX41LRw1gSEWuAK/+7CedM6IkFEUV2NSF</ds:X509Certificate>
                        </ds:X509Data>
                    </ds:KeyInfo>
                </ds:Signature>
                <saml2:Subject>
                    <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"
                                  NameQualifier="urn:gs1:gln">7601000080776</saml2:NameID>
                    <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
                        <saml2:SubjectConfirmationData InResponseTo="_43ef3e4fefdb03a31781d7ea52617674bcd25a6c26"
                                                       NotOnOrAfter="2017-12-11T16:48:14.494Z"
                                                       Recipient="https://sp.community.ch/epd"/>
                    </saml2:SubjectConfirmation>
                </saml2:Subject>
                <saml2:Conditions NotBefore="2017-12-11T14:48:14.494Z" NotOnOrAfter="2017-12-11T16:48:14.494Z">
                    <saml2:AudienceRestriction>
                        <saml2:Audience>urn:e-health-suisse:token-audience:all-communities</saml2:Audience>
                    </saml2:AudienceRestriction>
                </saml2:Conditions>
                <saml2:AuthnStatement AuthnInstant="2017-12-11T14:48:14.494Z"
                                      SessionNotOnOrAfter="2017-12-11T16:48:14.494Z">
                    <saml2:AuthnContext>
                        <saml2:AuthnContextClassRef>http://bag.admin.ch/LoA/3</saml2:AuthnContextClassRef>
                    </saml2:AuthnContext>
                </saml2:AuthnStatement>
                <saml2:AttributeStatement>
                    <saml2:Attribute Name="urn:oasis:names:tc:xspa:1.0:subject:subject-id">
                        <saml2:AttributeValue>Alexander Maes</saml2:AttributeValue>
                    </saml2:Attribute>
                    <saml2:Attribute Name="urn:oasis:names:tc:xacml:2.0:subject:role">
                        <saml2:AttributeValue>
                            <Role xmlns="urn:hl7-org:v3" code="HCP" codeSystem="2.16.756.5.30.1.127.3.10.6"
                                  codeSystemName="eHealth Suisse EPR Akteure"
                                  displayName="Behandelnde(r)"
                                  xs:type="CE"/>
                        </saml2:AttributeValue>
                    </saml2:Attribute>
                    <saml2:Attribute Name="urn:oasis:names:tc:xspa:1.0:subject:organization">
                        <saml2:AttributeValue>Uni Spital Zurich</saml2:AttributeValue>
                    </saml2:Attribute>
                    <saml2:Attribute Name="urn:oasis:names:tc:xspa:1.0:subject:organization-id">
                        <saml2:AttributeValue>7601001355781</saml2:AttributeValue>
                    </saml2:Attribute>
                    <saml2:Attribute Name="urn:oasis:names:tc:xacml:2.0:resource:resource-id">
                        <saml2:AttributeValue>761337610435209810^^^SPID&amp;2.16.756.5.30.1.127.3.10.3&amp;ISO</saml2:AttributeValue>
                    </saml2:Attribute>
                    <saml2:Attribute Name="urn:oasis:names:tc:xspa:1.0:subject:purposeofuse">
                        <saml2:AttributeValue>
                            <PurposeOfUse xmlns="urn:hl7-org:v3" code="NORM" codeSystem="2.16.756.5.30.1.127.3.10.5"
                                          codeSystemName="eHealth Suisse Verwendungszweck"
                                          displayName="Normalzugriff"
                                          xs:type="CE"/>
                        </saml2:AttributeValue>
                    </saml2:Attribute>
                </saml2:AttributeStatement>
            </saml2:Assertion>
        </wss:Security>
    </soap:Header>
    <soap:Body>
        <epd:AddPolicyRequest xmlns:epd="urn:e-health-suisse:2015:policy-administration"
                              xmlns:hl7="urn:hl7-org:v3"
                              xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
                              xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
                              xmlns:xacml-context="urn:oasis:names:tc:xacml:2.0:context:schema:os"
                              xmlns:xacml-saml="urn:oasis:names:tc:xacml:2.0:profile:saml2.0:v2:schema:assertion"
                              xmlns:xacml-samlp="urn:oasis:names:tc:xacml:2.0:profile:saml2.0:v2:schema:protocol"
                              xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
            <saml:Assertion ID="_b882d240-45cd-4fa3-aa9f-65394115d0e0" Version="2.0"
                            IssueInstant="2014-04-09T19:10:00.294Z">
                <saml:Issuer NameQualifier="urn:e-health-suisse:community-index">urn:oid:1.3.6.1.4.1.21367.2017.2.6.2</saml:Issuer>
                <saml:Statement xmlns="urn:oasis:names:tc:xacml:2.0:policy:schema:os"
                                xsi:type="xacml-saml:XACMLPolicyStatementType">
                    <PolicySet PolicyCombiningAlgId="urn:oasis:names:tc:xacml:1.0:policy-combining-algorithm:deny-overrides"
                               PolicySetId="urn:uuid:77d6b32b-051e-4abf-800b-51560d89411f">
                        <Description>Patient specific PolicySet for EPD Setup 21 - granting full access to a patient at EPD setup</Description>
                        <Target>
                            <Subjects>
                                <Subject>
                                    <SubjectMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:string-equal">
                                        <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#string">7601000080776</AttributeValue>
                                        <SubjectAttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-id"
                                                                    DataType="http://www.w3.org/2001/XMLSchema#string"/>
                                    </SubjectMatch>
                                    <SubjectMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:anyURI-equal">
                                        <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#anyURI">urn:gs1:gln</AttributeValue>
                                        <SubjectAttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:subject:subject-id-qualifier"
                                                                    DataType="http://www.w3.org/2001/XMLSchema#anyURI"/>
                                    </SubjectMatch>
                                    <SubjectMatch MatchId="urn:hl7-org:v3:function:CV-equal">
                                        <AttributeValue DataType="urn:hl7-org:v3#CV">
                                            <hl7:CodedValue code="PAT" codeSystem="2.16.756.5.30.1.127.3.10.6"/>
                                        </AttributeValue>
                                        <SubjectAttributeDesignator DataType="urn:hl7-org:v3#CV"
                                                                    AttributeId="urn:oasis:names:tc:xacml:2.0:subject:role"/>
                                    </SubjectMatch>
                                </Subject>
                            </Subjects>
                            <Resources>
                                <Resource>
                                    <ResourceMatch MatchId="urn:hl7-org:v3:function:II-equal">
                                        <AttributeValue DataType="urn:hl7-org:v3#II">
                                            <hl7:InstanceIdentifier root="2.16.756.5.30.1.127.3.10.3" extension="761337610455909127"/>
                                        </AttributeValue>
                                        <ResourceAttributeDesignator DataType="urn:hl7-org:v3#II" AttributeId="urn:e-health-suisse:2015:epr-spid"/>
                                    </ResourceMatch>
                                </Resource>
                            </Resources>
                        </Target>
                        <Policy PolicyId="cbb1cd74-454e-4068-9cb0-718fb9c7b3d0"
                                RuleCombiningAlgId="identifier:rule-combining-algorithm:permit-overrides">
                            <Description>Sample Policy to be add</Description>
                            <Target/>
                            <Rule RuleId="31eb97ca-af83-4941-ad19-fa187aea1c63" Effect="Permit">
                                <Target>
                                    <Resources>
                                        <Resource>
                                            <ResourceMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:anyURI-equal">
                                                <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#anyURI">urn:icw:2013:record:interactions</AttributeValue>
                                                <ResourceAttributeDesignator AttributeId="urn:ihe-d:cookbook:2013:resource-type"
                                                                             DataType="http://www.w3.org/2001/XMLSchema#anyURI"/>
                                            </ResourceMatch>
                                        </Resource>
                                    </Resources>
                                    <Actions>
                                        <Action>
                                            <ActionMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:anyURI-equal">
                                                <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#anyURI">urn:icw:2013:record:search-response</AttributeValue>
                                                <ActionAttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id"
                                                                           DataType="http://www.w3.org/2001/XMLSchema#anyURI"/>
                                            </ActionMatch>
                                        </Action>
                                        <Action>
                                            <ActionMatch MatchId="urn:oasis:names:tc:xacml:1.0:function:anyURI-equal">
                                                <AttributeValue DataType="http://www.w3.org/2001/XMLSchema#anyURI">urn:icw:2013:record:view-all-response</AttributeValue>
                                                <ActionAttributeDesignator AttributeId="urn:oasis:names:tc:xacml:1.0:action:action-id"
                                                                           DataType="http://www.w3.org/2001/XMLSchema#anyURI"/>
                                            </ActionMatch>
                                        </Action>
                                    </Actions>
                                </Target>
                                <Condition>
                                    <Apply FunctionId="urn:icw:2013:record:function:interactedPreviously">
                                        <SubjectAttributeDesignator AttributeId="urn:oasis:names:tc:xspa:1.0:subject:organization-id"
                                                                    DataType="http://www.w3.org/2001/XMLSchema#anyURI"/>
                                        <ResourceAttributeDesignator AttributeId="urn:icw:2013:record:latest-organization-interaction"
                                                                     DataType="urn:icw:2013:record#interaction"/>
                                    </Apply>
                                </Condition>
                            </Rule>
                        </Policy>
                        <PolicySetIdReference>urn:e-health-suisse:2015:policies:access-level:delegation-and-normal</PolicySetIdReference>
                    </PolicySet>
                </saml:Statement>
            </saml:Assertion>
        </epd:AddPolicyRequest>
    </soap:Body>
</soap:Envelope>
