HIT Shibboleth Identity Provider (SAML 2.0)
Harbin Institute of Technology's own Shibboleth identity provider, self-hosted on HIT's registrable domain and asserting the scope hit.edu.cn. Publishes a SAML 2.0 EntityDescriptor anonymously at /idp/shibboleth with IDPSSODescriptor and AttributeAuthorityDescriptor roles, six key descriptors, and SSO/SLO endpoints over HTTP-Redirect, HTTP-POST, HTTP-POST-SimpleSign and SOAP. This is HIT's own engineering rather than a vendor contract running under HIT's name, and it is the strongest institution-operated machine-readable surface in this profile. Caveat, recorded rather than hidden: the served document is the unedited Shibboleth distribution template — it retains the stock "This is example metadata only" banner and an mdui:DisplayName of "A Name for the IdP at idp.hit.edu.cn" — and its validUntil is 2020-02-14, so a conforming SAML consumer would reject it as expired. The IdP is live; its published descriptor is stale. HIT does not appear in eduGAIN; the federation context is domestic (CARSI/CERNET).