* Ryan Larscheidt <larscheidt at doit.wisc.edu> [2013-05-21 23:24]: > This doesn't appear to be true, because we're using our IdP's > self-signed cert on the ECP endpoint with Office 365 (we're not in > production yet). Why would you want to do that? ECP is for subject's http user agents, it's not a "back channel" thing? -peter