On Fri, Nov 8, 2013 at 3:09 PM, Brent Putman <putmanb at georgetown.edu> wrote: > > And of course they also need to fix their horked-up KeyDescriptor data, > their use of ds:X509Data/ds:X509Certificate is completely incorrect. Brent, can you elaborate on what you're seeing here? The reason I ask is because xmlsectool choked on the certificate as well. Tom