<div dir="ltr"><span style="font-family:arial,sans-serif;font-size:13px">What is the recommended way to verify the signature of signed metadata with OpenSAML? </span><div style="font-family:arial,sans-serif;font-size:13px">

If you read the EntityDescriptor with a metadata provider and then try to verify the signature on EntityDescriptor you get </div><div style="font-family:arial,sans-serif;font-size:13px"><div><br></div><div><span style="color:rgb(38,38,38);line-height:16px">org.opensaml.xml.validation.ValidationException: Apache XMLSignature does not exist on SignatureImpl</span><br style="color:rgb(38,38,38);line-height:16px">

<span style="color:rgb(38,38,38);line-height:16px">ator g.opensaml.security.SAMLSignatureProfileValidator.validateSignatureImpl(SAMLSignatureProfileValidator.java:70)</span><br></div><div><br></div><div>From the source i can se that the release method used by initilize on the metadataprovider sets the <span style="color:rgb(38,38,38);line-height:16px">XMLSignature</span><span style="color:rgb(38,38,38);line-height:16px"> property to null.</span></div>

</div><div><div><br></div><div>--</div>Stefan</div>
</div>