On 11/26/14, 2:01 AM, "Adam Dong" <adamdong at vidder.com> wrote: >Now my questions are: During the validation, will IDP check that SP’s >signing cert (non-self-signed) is issued by a trusted root CA ? https://wiki.shibboleth.net/confluence/display/SHIB2/TrustManagement -- Scott