Metadata does not contain signing certificate
tvdijen opened this issue · 3 comments
tvdijen commented
I'd expect it to contain a <KeyDescriptor use="signing">
with the value of saml_sp_publickey
(parameters.yml)
thijskh commented
Agreed. We do not currently check the authnrequest signatures. but since profile signs its authnrequests, it publish the key (or stop signing the requests).
thijskh commented
Yes