<S12:Envelope xmlns:S12="http://www.w3.org/2003/05/soap-envelope"
    xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd"
    xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd"
    xmlns:xenc="http://www.w3.org/2001/04/xmlenc#" xmlns:wst="http://docs.oasis-open.org/ws-sx/ws-trust/200512"
    xmlns:xs="http://www.w3.org/2001/XMLSchema">
    <S12:Header>
        <wsse:Security>
            <wsu:Timestamp wsu:Id="id-06540FF6159365931114525933973941">
                <wsu:Created>2016-01-12T10:09:57.284Z</wsu:Created>
                <wsu:Expires>2016-01-12T10:14:56.284Z</wsu:Expires>
            </wsu:Timestamp>
            <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">
                <!-- original XUA:CH Auth SAML Assertion (X-User-Authentication), plain XML
                structure -->
            </saml2:Assertion>
            <Signature xmlns="http://www.w3.org/2000/09/xmldsig#">
                <SignedInfo>
                    <CanonicalizationMethod 
                        Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n-
                        20010315#WithComments"/>
                    <SignatureMethod Algorithm="http://www.w3.org/2000/09/
                        xmldsig#dsa-sha1"/>
                    <Reference URI="">
                        <Transforms>
                            <Transform Algorithm="http://www.w3.org/2000/09/
                                xmldsig#enveloped-signature"/>
                        </Transforms>
                        <DigestMethod Algorithm="http://www.w3.org/2000/09/
                            xmldsig#sha1"/>
                        <DigestValue>uooqbWYa5VCqcJCbuymBKqm17vY=</DigestValue>
                    </Reference>
                </SignedInfo>
                <SignatureValue>
                    KedJuTob5gtvYx9qM3k3gm7kbLBwVbEQRl26S2tmXjqNND7MRGtoew==
                </SignatureValue>
                <KeyInfo>
                    <KeyValue>
                        <DSAKeyValue>
                            <P>
                                /KaCzo4Syrom78z3EQ5SbbB4sF7ey80etKII864WF64B81uRpH5t9jQTxe
                                Eu0ImbzRMqzVDZkVG9xD7nN1kuFw==
                            </P>
                            <Q>li7dzDacuo67Jg7mtqEm2TRuOMU=</Q>
                            <G>Z4Rxsnqc9E7pGknFFH2xqaryRPBaQ01khpMdLRQnG541Awtx/
                                XPaF5Bpsy4pNWMOHCBiNU0NogpsQW5QvnlMpA==
                            </G>
                            <Y>qV38IqrWJG0V/
                                mZQvRVi1OHw9Zj84nDC4jO8P0axi1gb6d+475yhMjSc/
                                BrIVC58W3ydbkK+Ri4OKbaRZlYeRA==
                            </Y>
                        </DSAKeyValue>
                    </KeyValue>
                </KeyInfo>
            </Signature>
        </wsse:Security>
    </S12:Header>
    <S12:Body wsu:Id="req">
        <wst:RequestSecurityToken>
            <wst:RequestType>http://schemas.xmlsoap.org/ws/2005/02/trust/Issue</wst:RequestType>
            <wsp:AppliesTo xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy">
                <wst:EndpointReference>
                    <wst:Address>https://sp.community.ch</wst:Address>
                </wst:EndpointReference>
            </wsp:AppliesTo>
            <wst:TokenType>http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLV2.0</wst:TokenType>
            <wst:Claims Dialect="http://bag.admin.ch/epr/2017/annex/5/addendum/2"
                xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">
                <!-- dialect is a proposal, to allow for future changes of semantics-->
                <!--http://docs.oasis-open.org/ws-sx/ws-trust/v1.4/errata01/os/ws-trust-1.4-
                errata01-os-complete.html#_Toc325658943 -->
                <saml2:Attribute Name="urn:oasis:names:tc:xspa:1.0:subject:subject-id">
                    <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"> ...
                    </saml2:AttributeValue>
                </saml2:Attribute>
                <saml2:Attribute Name="urn:oasis:names:tc:xspa:1.0:subject:organization-id">
                    <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"> ...
                    </saml2:AttributeValue>
                </saml2:Attribute>
                <saml2:Attribute Name="urn:oasis:names:tc:xspa:1.0:subject:organization">
                    <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"> ...
                    </saml2:AttributeValue>
                </saml2:Attribute>
                <saml2:Attribute Name="urn:oasis:names:tc:xacml:2.0:subject:role">
                    <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"> ...
                    </saml2:AttributeValue>
                </saml2:Attribute>
                <saml2:Attribute Name="urn:oasis:names:tc:xacml:2.0:resource:resource-id">
                    <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"> (syntax as used in
                        iti-18 XDSDocumentEntryPatientId) </saml2:AttributeValue>
                </saml2:Attribute>
                <saml2:Attribute Name="urn:oasis:names:tc:xspa:1.0:subject:purposeofuse">
                    <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
                        <PurposeOfUse xmlns="urn:h7-org:v3" xs:type="CE" code=" NORM "
                            codeSystem="2.16.756.5.30.1.127.3.10.5" codeSystemName="eHealth Suisse Verwendungszweck"
                            displayName=" Normalzugriff "/>
                    </saml2:AttributeValue>
                </saml2:Attribute>
            </wst:Claims>
        </wst:RequestSecurityToken>
    </S12:Body>
</S12:Envelope>
