A Shibboleth IdP is pushing an unsolicited SAML2 Response to a Shibboleth SP. The SP is reporting in the browser window that the "Assertion contains an unacceptable AudienceRestriction," which is not true. As it turns out, the IdP is not including a NameID in the assertion. Which endpoint is at fault here? Thanks, Tom