On 10/13/2017 11:18 AM, Tom Scavo wrote: > It's not that simple. A KeyDescriptor with use="signing" is used for > authentication at the TLS layer as well. That's not my understanding. Keys used in metadata are independent of the transport layer. -- John