<HTML><HEAD>
<META content="text/html; charset=utf-8" http-equiv=Content-Type>
<META name=GENERATOR content="MSHTML 9.00.8112.16447"></HEAD>
<BODY style="MARGIN: 4px 4px 1px; FONT: 10pt Segoe UI; WORD-WRAP: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space">
<DIV>Nick</DIV>
<DIV>&nbsp;</DIV>
<DIV>Thanks for your help. That fixed my issue.</DIV>
<DIV>&nbsp;</DIV>
<DIV>Awesome!!!<BR><BR>&gt;&gt;&gt; Nate Klingenstein &lt;ndk@internet2.edu&gt; 8/29/2012 2:02 PM &gt;&gt;&gt;<BR>Wavyne,</DIV>
<DIV><BR></DIV>
<DIV>
<DIV>
<BLOCKQUOTE type="cite"><SPAN style="WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; LETTER-SPACING: normal; BORDER-COLLAPSE: separate; FONT: medium Helvetica; WHITE-SPACE: normal; ORPHANS: 2; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px" class=Apple-style-span><SPAN style="FONT-FAMILY: 'Segoe UI'; FONT-SIZE: 13px" class=Apple-style-span>
<DIV>It appears that our metadata cert doesn't match the SAML assertion cert that is being transmitted. Can something explain why this has occurred and what can be done to fix it?</DIV></SPAN></SPAN></BLOCKQUOTE><BR></DIV>
<DIV>You can check the certificate that is being used by the IdP by looking at the certificate subelement of &lt;security:Credential id="IdPCredential" xsi:type="security:X509Filesystem"&gt; in relying-party.xml. &nbsp;You'll need to compare that certificate to the one in the metadata file you supplied to the PingFederate SP. &nbsp;You can make sure they match by updating one, the other, or both.</DIV></DIV>
<DIV><BR></DIV>
<DIV>Let us know if we can help further,</DIV>
<DIV>Nate.</DIV></BODY></HTML>