Is it possible to configure Shibboleth (SP or IdP) with *two* metadata signing certificates (containing different keys) so that a federation could painlessly migrate to a new metadata signing key? Thanks, Tom