<?xml version="1.0" encoding="UTF-8"?>
<S:Envelope xmlns:S="http://schemas.xmlsoap.org/soap/envelope/" xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" xmlns:wsa="http://www.w3.org/2005/08/addressing" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" xmlns:saml="oasis:names:tc:SAML:1.0:assertion">
	<S:Header>
		<!-- wsa header -->
		<sbf:Framework xmlns:sbf="urn:liberty:sb" version="2.0"/>
		<sb:Sender xmlns:sb="urn:liberty:sb:2006-08" providerID="{{ &ECP_SP_ID }}"/>
		<wsa:MessageID>urn:uuid:{{ WSSE_MESSAGE_ID }}</wsa:MessageID>
		<wsa:To>{{ &ECP_DESTINATION_URL }}</wsa:To>
		<wsa:Action>urn:liberty:ssos:2006-08:AuthnRequest</wsa:Action>

		<!-- security token -->
		<wsse:Security>{{ &WSSE_SAML_TOKEN }}</wsse:Security>
	</S:Header>
	<S:Body>
		<samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
			AssertionConsumerServiceURL="{{ &ECP_CONSUMER_URL }}" ID="{{ ECP_REQUEST_ID }}"
			IssueInstant="{{ ECP_REQUEST_INSTANT }}" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Version="2.0">

			<saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">{{ &ECP_SP_ID }}</saml:Issuer>
			<samlp:NameIDPolicy AllowCreate="1" format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"/>
			<saml:AudienceRestriction xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">
				<!-- make assertion available to IdP to enable delegation requests -->
				<saml:Audience xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">{{ &ECP_IDP_ID }}</saml:Audience>
			</saml:AudienceRestriction>
		</samlp:AuthnRequest>
	</S:Body>
</S:Envelope>
