<br><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">In that event, the metadata needs to contain a key. I just checked mine, and the copy I have from Box does contain one.<br>
</blockquote><div><br>I'm
using the latest incarnation of their metadata, hosted at their URL:
<a href="https://app.box.com/shared/3isa8qvvqn.">https://app.box.com/shared/3isa8qvvqn.</a>.. looks to me like it does
contain a key?<br> <div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">After running xmllint to make the box metadata easier to read,<br>
we made one change, so their certificate could be used for encryption:<br></blockquote><div><br>So your change was the deletion of the 'use="signing"' part in the md:KeyDescriptor tag? I made this change as well, reloaded the metadata and now the error (returned by them) has changed to:<br>
<br><span style="color:rgb(255,0,0);font-family:Helvetica,Arial,sans-serif;font-size:13px;font-style:normal;font-variant:normal;font-weight:bold;letter-spacing:normal;line-height:19px;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);display:inline!important;float:none">Unexpected exception occurred in Response Handling: No decryption key to decrypt the assertion.</span><br>
<br>-Rob<br><br></div></div></div></div>-- <br><div>Robert W. Gorrell<br>Middleware Engineer, Identity and Access Management</div>
<div>University of NC at Greensboro<br>336-334-5954</div>
<br><br><br>