<HTML><HEAD>
<META content="text/html; charset=utf-8" http-equiv=Content-Type>
<META name=GENERATOR content="MSHTML 9.00.8112.16447"></HEAD>
<BODY style="MARGIN: 4px 4px 1px; FONT: 10pt Segoe UI; WORD-WRAP: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space">
<DIV>Nick</DIV>
<DIV> </DIV>
<DIV>Thanks for your help. That fixed my issue.</DIV>
<DIV> </DIV>
<DIV>Awesome!!!<BR><BR>>>> Nate Klingenstein <ndk@internet2.edu> 8/29/2012 2:02 PM >>><BR>Wavyne,</DIV>
<DIV><BR></DIV>
<DIV>
<DIV>
<BLOCKQUOTE type="cite"><SPAN style="WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; LETTER-SPACING: normal; BORDER-COLLAPSE: separate; FONT: medium Helvetica; WHITE-SPACE: normal; ORPHANS: 2; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px" class=Apple-style-span><SPAN style="FONT-FAMILY: 'Segoe UI'; FONT-SIZE: 13px" class=Apple-style-span>
<DIV>It appears that our metadata cert doesn't match the SAML assertion cert that is being transmitted. Can something explain why this has occurred and what can be done to fix it?</DIV></SPAN></SPAN></BLOCKQUOTE><BR></DIV>
<DIV>You can check the certificate that is being used by the IdP by looking at the certificate subelement of <security:Credential id="IdPCredential" xsi:type="security:X509Filesystem"> in relying-party.xml. You'll need to compare that certificate to the one in the metadata file you supplied to the PingFederate SP. You can make sure they match by updating one, the other, or both.</DIV></DIV>
<DIV><BR></DIV>
<DIV>Let us know if we can help further,</DIV>
<DIV>Nate.</DIV></BODY></HTML>