<?xml version="1.0" encoding="UTF-8"?>

<!--
    Document   : symkeyResponse-instance.xml
    Modified   : June 21, 2008
    Author     : Arshad Noor
    Version    : 6.0
    
    Modified on June 21, 2008
    Changes in version 6.0:
    
    01) Instance was modified to accommodate the new requirements in the
        Permissions element where each "Permitted..." element must specify
        the ekmi:any attribute.  This attribute indicates whether the 
        specific permission is allowed for any value or specific ones.
        If ekmi:any is set to "true", then "xsi:nil" must also exist in
        the element and must be set to "true".
        
    Modified   : April 26, 2008
    Version    : 2.2
    Notes      : Changed GKID to GlobalKeyID, KUPID to KeyUsePolicyID
                 and ID to ApplicationID
    
    Created on : December 24, 2007, 4:50 PM
    Author     : anoor
    Description: Document is a SOAP response for a Symmetric Key secured 
                 by a Web Services Security (WSS) Header containing a 
                 digital signature.
                 
                 The KeyUsePolicy element embedded in the SymkeyResponse
                 permits the use of symmetric keys covered by this policy 
                 for the Payroll Application, between January 01, 2008 and 
                 December 31, 2008 and only between the hours of 07:00 and 
                 19:00 on those dates.
                 
                 Note that since all other permission types are missing, 
                 all those permissions are assumed to be granted.
-->

<SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/">
    <SOAP-ENV:Header>
        <wsse:Security xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" SOAP-ENV:mustUnderstand="1">
            <wsse:BinarySecurityToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" EncodingType="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Base64Binary" ValueType="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-x509-token-profile-1.0#X509v3" wsu:Id="XWSSGID-1174064048754-2062847767">MIIEJDCCAwygAwIBAgIITKSQy2Vmb7YwDQYJKoZIhvcNAQELBQAwZzEmMCQGA1UEAxMdU3Ryb25n
                S2V5IERFTU8gU3Vib3JkaW5hdGUgQ0ExJDAiBgNVBAsTG0ZvciBTdHJvbmdLZXkgREVNTyBVc2Ug
                T25seTEXMBUGA1UEChMOU3Ryb25nQXV0aCBJbmMwHhcNMDYwNzI1MTY0NjEwWhcNMDcwNzI1MTY1
                NjEwWjBpMREwDwYKCZImiZPyLGQBARMBOTEVMBMGA1UEAxMMU0tTIFNlcnZlci0xMSQwIgYDVQQL
                ExtGb3IgU3Ryb25nS2V5IERFTU8gVXNlIE9ubHkxFzAVBgNVBAoTDlN0cm9uZ0F1dGggSW5jMIIB
                IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAztppqRoU5A8plxx1Rz1QEUnlAAM1D5g9+isI
                hbwjtFSMYilnY4iV77xU/nsMOnMZ7RxsLYKdCzQ1ODVYqQwqmAvaJ5Z6SVy34gZ51YG+rSWE3NjF
                bOXW8RJYA/Tn6Lmht/qngrcaqqmtP0cAAiMRZOWtCTmC2K/LEqDabXSyU6Hh8ySNE3njybvmWpre
                zsYokTdvnWQqT6tKo1OwJsdJ1+hxM7DrnMLvMNq5reINfsKhDdX17wzhrBUx+hiYA/qo8tMXkL6w
                j75FY1X99K5u+4PN5dYugtzpSzIdUO5tIg58Avhzwo7hy5oofBlKFY22CeljQ36u0bMjuyGj6UYH
                GwIDAQABo4HRMIHOMA4GA1UdDwEB/wQEAwIEsDAdBgNVHQ4EFgQU4/eT58Sks6UqDE+3zpLm0TPD
                qP4wHwYDVR0jBBgwFoAU9NjAQegkbiIVUdGe3YRbEaW4BBUwJgYDVR0RBB8wHYEbc2VydmVyLmFk
                bWluQHN0cm9uZ2F1dGguY29tMBgGA1UdIAQRMA8wDQYLKwYEAdISg30BBAEwOgYDVR0fBDMwMTAv
                oC2gK4YpaHR0cDovL2RlbW8uc3Ryb25na2V5Lm9yZy9kZW1vLXN1Yi1jYS5jcmwwDQYJKoZIhvcN
                AQELBQADggEBAB0ti4SGinvqnQylieeVBgcyxuPqKGNPSnhq9E5PrJu8ICmIP5suiZ502kNWZ0Ue
                iYMhYlJdWcd+q61uLGqhRdfj76eDFmKQ4BN60Nj7rHWIqkTx6ordUUZay6R6bDkCZ3AR5b1oTbTk
                jYdbiANB/YmVYYo+ZpbnrfXHMxJ45ZjNtY25uQAvFMU4CULy28PS/jap6seUKIEn1Ajh298D3J0h
                zei/+rLeHJUF79RBM0hcDdUr5FIB3wb2RvS90gFmvYxhvYDMW9uIZUC/LEicfhVkjo9NqhplWFkz
            efh8SS22eeusqfFre8JM4SvfZ6i52AbcavqHKh+ol/4Ymne0lyw=</wsse:BinarySecurityToken>
            <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:SignedInfo>
                    <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#">
                        <InclusiveNamespaces xmlns="http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="wsse SOAP-ENV"/>
                    </ds:CanonicalizationMethod>
                    <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
                    <ds:Reference URI="#XWSSGID-1174064053213-1346600623">
                        <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
                        <ds:DigestValue>/9PZUkqoszW3NLYb9/5S+1/fFtY=</ds:DigestValue>
                    </ds:Reference>
                    <ds:Reference URI="#XWSSGID-1174064053213147098923">
                        <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
                        <ds:DigestValue>NIG4bKkt4cziEqFFuOoBTM81efU=</ds:DigestValue>
                    </ds:Reference>
                </ds:SignedInfo>
                <ds:SignatureValue>OJqWYjdEGjYNab46JKHMsheoxmApfGJF/ypGb20/8QQQE6BAy5cZtSW9AqUSiDMD8MaRo8x3Lfdx
                    S2WZAF0SuvFcJWVawtGmDfL3lV3ChYss7AVnYUzezHopBMiNhI5AnAlw3L5JvRTST7teuGPXxqdg
                    /KvViEYDaAYBTlJoXBKYkCg9Nef7eyqjfSU5QXVsBW5Ove4ZjpuwcDsmezsjCbo0U9FAvfcFT4hY
                    XGD/0IZwcwVm/c4pcOlmmF+xYW15REmOTd4ZUzzQ70yEgHNRL/XlhTYwdPjW+bDjCi++LwSgtPlC
                t2OM95lNmBqRpHjtkWB9iGU7PKHT+4PZW20FHw==</ds:SignatureValue>
                <ds:KeyInfo>
                    <wsse:SecurityTokenReference xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="XWSSGID-1174064053210-2007529707">
                        <wsse:Reference URI="#XWSSGID-1174064048754-2062847767" ValueType="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-x509-token-profile-1.0#X509v3"/>
                    </wsse:SecurityTokenReference>
                </ds:KeyInfo>
            </ds:Signature>
            <wsu:Timestamp xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="XWSSGID-1174064053213147098923">
                <wsu:Created>2007-03-16T16:54:13Z</wsu:Created>
                <wsu:Expires>2007-04-15T16:54:13Z</wsu:Expires>
            </wsu:Timestamp>
        </wsse:Security>
    </SOAP-ENV:Header>
    <SOAP-ENV:Body xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="XWSSGID-1174064053213-1346600623">
        <ekmi:SymkeyResponse xmlns:xsi='http://www.w3.org/2001/XMLSchema-instance' xmlns:ekmi='http://docs.oasis-open.org/ekmi/2008/01'
                             xmlns:xenc='http://www.w3.org/2001/04/xmlenc#' xsi:schemaLocation='http://docs.oasis-open.org/ekmi/2008/01 symkeyResponse.xsd'>            
            <ekmi:Symkey>
                <ekmi:GlobalKeyID>10514-1-235</ekmi:GlobalKeyID>
                <ekmi:KeyUsePolicy>
                    <ekmi:KeyUsePolicyID>10514-4</ekmi:KeyUsePolicyID>
                    <ekmi:PolicyName>DES-EDE KeyUsePolicy</ekmi:PolicyName>
                    <ekmi:KeyClass>HR-Class</ekmi:KeyClass>
                    <ekmi:KeyAlgorithm>http://www.w3.org/2001/04/xmlenc#tripledes-cbc</ekmi:KeyAlgorithm>
                    <ekmi:KeySize>192</ekmi:KeySize>
                    <ekmi:Status>Active</ekmi:Status>
                    <ekmi:Permissions>
                        <ekmi:PermittedApplications ekmi:any="false">
                            <ekmi:PermittedApplication>
                                <ekmi:ApplicationID>10514-23</ekmi:ApplicationID>
                                <ekmi:ApplicationName>Payroll Application</ekmi:ApplicationName>
                                <ekmi:Version>1.0</ekmi:Version>
                                <ekmi:DigestAlgorithm>http://www.w3.org/2000/09/xmldsig#sha1</ekmi:DigestAlgorithm>
                                <ekmi:DigestValue>NIG4bKkt4cziEqFFuOoBTM81efU=</ekmi:DigestValue>
                            </ekmi:PermittedApplication>
                        </ekmi:PermittedApplications>
                        <ekmi:PermittedDates ekmi:any="false">
                            <ekmi:PermittedDate>
                                <ekmi:StartDate>2008-01-01</ekmi:StartDate>
                                <ekmi:EndDate>2008-12-31</ekmi:EndDate>
                            </ekmi:PermittedDate>
                        </ekmi:PermittedDates>
                        <ekmi:PermittedDays ekmi:any="true" xsi:nil="true"/>
                        <ekmi:PermittedDuration  ekmi:any="true" xsi:nil="true"/>
                        <ekmi:PermittedLevels ekmi:any="true" xsi:nil="true"/>
                        <ekmi:PermittedLocations ekmi:any="true" xsi:nil="true"/>
                        <ekmi:PermittedNumberOfTransactions ekmi:any="true" xsi:nil="true"/>
                        <ekmi:PermittedTimes ekmi:any="false">
                            <ekmi:PermittedTime>
                                <ekmi:StartTime>07:00:00</ekmi:StartTime>
                                <ekmi:EndTime>19:00:00</ekmi:EndTime>
                            </ekmi:PermittedTime>
                        </ekmi:PermittedTimes>
                        <ekmi:PermittedUses ekmi:any="true" xsi:nil="true"/>
                    </ekmi:Permissions>
                </ekmi:KeyUsePolicy>
                <ekmi:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-1_5"/>    
                <xenc:CipherData>
                    <xenc:CipherValue>
                        E9zWB/y93hVSzeTLiDcQoDxmlNxTux+SffMNwCJmt1dIqzQHBnpdQ81g6DKdkCFjJMhQhywCx9sf
                        Yjv9h5FDqUiQXGOca8EU871zBoXBjDxjfg1pU8tGFbpWZcd/ATpJD/UJow/qimxi8+huUYJMtaGH
                        tXuLlWtx27STRcRpIsY=
                    </xenc:CipherValue>
                </xenc:CipherData>    
            </ekmi:Symkey>
        </ekmi:SymkeyResponse>
    </SOAP-ENV:Body>
</SOAP-ENV:Envelope>


