The SAML 2 tests are now encrypting a NameID of jdoe inside the AuthnRequest, and the IdP is successfully decrypting that. It worked with and without a KeyInfo. The errors when I had the wrong key ran on for about a mile, but that's probably a mix of things, certainly the second copy of the key I have configured isn't helping that. -- Scott