Question around multiple keys in SAML Metadata

Paul B. Henson henson at acm.org
Mon May 4 22:40:24 UTC 2026


On Mon, May 04, 2026 at 05:25:14PM -0500, James Epp via users wrote:

> I've come into disagreement with a vendor
[...]
> I was all but certain SAML-compliance required SPs

Hehehehe... Vendors and standards compliance mix like oil and water ;).

Section 2.6.1 "Key Processing" is pretty clear:

"Each key expressed by a <md:KeyDescriptor> element within a particular
role MUST be treated as valid when processing messages or assertions in
the context of that role. Specifically, any signatures or transport
communications (e.g., TLS/SSL sessions) verifiable with a signing key
MUST be treated as valid, and any encryption keys found MAY be used to
encrypt messages or assertions (or encryption keys) intended for the
containing entity."

The standard allows multiple keys to be included in metadata, the
standard says each key MUST be treated as valid.

Your vendor doesn't have a leg to stand on, although sadly that will
likely have no impact on their desire or ability to fix their broken
implementation <sigh>.



More information about the users mailing list