On 6/11/13 5:01 PM, Cantor, Scott wrote: > Oh, that's probably the tenth time I made that mistake, I just assumed we had KS support. Guess you're right, then. We do have a KeystoreCredentialResolver in OpenSAML, but IIRC Chad was very opposed to supporting keystores in any way in the IdP itself (at least as far as our own code is concerned).