diff --git a/nefed.xml b/nefed.xml
index 637b3f524823ec57c8bf2fc8b262c6dd1879de3d..a037274d5f875e8e79fab09f4b7d25e188b4216c 100644
--- a/nefed.xml
+++ b/nefed.xml
@@ -23107,18 +23107,16 @@
                     https://www.hannonhill.com/legal/privacy.html</mdui:PrivacyStatementURL>
                 <mdui:Logo height="85" width="141" xml:lang="en"></mdui:Logo>
             </mdui:UIInfo>
+            <init:RequestInitiator
+                 xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init"
+                Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init"
+                Location="https://unomaha.cascadecms.com/Shibboleth.sso/Login" />
+            <idpdisc:DiscoveryResponse
+                xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol"
+                Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol"
+                Location="https://unomaha.cascadecms.com/Shibboleth.sso/Login" index="1" />
         </Extensions>
-        <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol">
-            <Extensions>
-                <init:RequestInitiator
-                    xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init"
-                    Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init"
-                    Location="https://unomaha.cascadecms.com/Shibboleth.sso/Login" />
-                <idpdisc:DiscoveryResponse
-                    xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol"
-                    Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol"
-                    Location="https://unomaha.cascadecms.com/Shibboleth.sso/Login" index="1" />
-            </Extensions>
+    <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol">
             <KeyDescriptor>
                 <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                     <ds:KeyName>
@@ -23232,18 +23230,16 @@
                     https://www.hannonhill.com/legal/privacy.html</mdui:PrivacyStatementURL>
                 <mdui:Logo height="85" width="141" xml:lang="en"></mdui:Logo>
             </mdui:UIInfo>
+            <init:RequestInitiator
+                xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init"
+                Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init"
+                Location="https://unomaha-dev.cascadecms.com/Shibboleth.sso/Login" />
+            <idpdisc:DiscoveryResponse
+                xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol"
+                Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol"
+                Location="https://unomaha-dev.cascadecms.com/Shibboleth.sso/Login" index="1" />
         </Extensions>
         <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol">
-            <Extensions>
-                <init:RequestInitiator
-                    xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init"
-                    Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init"
-                    Location="https://unomaha-dev.cascadecms.com/Shibboleth.sso/Login" />
-                <idpdisc:DiscoveryResponse
-                    xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol"
-                    Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol"
-                    Location="https://unomaha-dev.cascadecms.com/Shibboleth.sso/Login" index="1" />
-            </Extensions>
             <KeyDescriptor>
                 <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                     <ds:KeyName>