I bumped the POM to RC6, and adjusted the OpenSAML and IdP code calling the method, it seems to be parsing my client cert now. Thanks, -- Scott