> Will the IdP honor <KeyDescriptor use="signing"> and use the key > only for validating the signature on requests - i.e., not encrypt the > response? Yes, of course. -- Scott