Arthur, Shibboleth treats the certificate as a bag for a public key and little more. Trust is based on metadata. The private key that is being used to sign messages from the IdP doesn't match any valid public key in the IdP's metadata as loaded by the SP. https://samltest.id/faq/ Take care, Nate.