> Ah yes, the usual suspect: 4096 cert being used by the SP, not > updated from prior 2048 cert in metadata at the IdP. Ah, key block size then, not digest. Live and learn. -- Scott