<HTML><HEAD>
<META content="text/html; charset=utf-8" http-equiv=Content-Type>
<META name=GENERATOR content="MSHTML 9.00.8112.16447"></HEAD>
<BODY style="MARGIN: 4px 4px 1px; FONT: 10pt Segoe UI">
<DIV>AA</DIV>
<DIV> </DIV>
<DIV>We are configuring shibboleth to interact with a PingFederate SP, but we are getting the below error message:</DIV>
<DIV> </DIV>
<DIV>Missing or invalid signature (UNVERIFIED commentary: [Not checking signature with configured verification cert AA:BB:CC:DD:EE:FF:GG because it does not match the embeded certificate in the signature.]) on assertion (ID=_99999999999999999999). All assertions must have valid signatures because the Response was not signed or the system is configured to require a signed assertion from (our idp)</DIV>
<DIV> </DIV>
<DIV>It appears that our metadata cert doesn't match the SAML assertion cert that is being transmitted. Can something explain why this has occurred and what can be done to fix it?</DIV>
<DIV> </DIV>
<DIV> </DIV>
<DIV>TIA</DIV>
<DIV> </DIV></BODY></HTML>