> What is the suggested mechanism by which IdP metadata is signed and does dynamically reflect the IdP's configuration?

Metadata cannot, by definition, do its job if it dynamically reflects a system's actual configuration. Use cases require that it *not* reflect the actual configuration in a variety of scenarios. Automating it is, essentially, an anti-pattern.
