As was noted by Ian and Peter, the root of your issue here is the protocol support string being wrong, which is what the error message means (no SAML 2.0 role found). -- Scott