A minor note : maybe it would be worthwhile for an OpenSAML test to test the Java “security environment”, in the sense of (a) presence of the Unlimited Strength Jurisdiction Policy Files and (b) support for MD5. Mostly to help troubleshoot Jenkins when I update Java there, and forget something.