> Arguably the vendor is ignoring encryption; they do not consume encrypted > SAML assertions, and the cert is explicitly designated for use as signing cert. That's inarguably ignoring it. You're good to go then. -- Scott