Question around multiple keys in SAML Metadata

James Epp jamesaepp at gmail.com
Mon May 4 22:25:14 UTC 2026


Greetings, everyone

Sorry if this is noise/not considered topical. Couldn't find a "forum" to
ask a
SAML question like this that was open.

I've come into disagreement with a vendor (which acts as SP) as the result
of
key rollover. I found out that if we provide them with a SAML metadata file
(generated by Azure/Entra ID) which contains multiple KeyDescriptors, their
system fails to complete logins. This is apparently documented and their
workaround is to manually purge all but the one desired/active key the IdP
uses for signing.

If I had more reliable test results, I'd share them but it's a bit of a
challenge to break a working system just for testing.

I was all but certain SAML-compliance required SPs to allow use of multiple
keys and to allow valid signatures from any key to work for SAML
assertions.

The below would seem to support that, but I wanted to ask those more
familiar
with the nuance to give me the more detailed "it depends" answer.

https://docs.oasis-open.org/security/saml/Post2.0/sstc-metadata-iop.html
(2.6.1)

Thanks in advance!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260504/2d7b254e/attachment.htm>


More information about the users mailing list