<div dir="ltr"><div>Tom - these are SP signing certs, not the IdP cert.</div><div><br></div><div>The SP in question is Gartner. Their current metadata has sha1 SignatureMethod and DigestMethod algorithms, and certificate "A".<br>
</div><div>To support sha256, they're issuing new metadata that has sha256 SignatureMethod and DigestMethod algorithms, and a new certificate (certificate "B").</div><div><br></div><div>They want to make sure that we're able to support both their sha1/cert A and sha256/cert B certificates at the same time, so our stuff won't break when they update their configuration. Both sets of metadata use the same entityId.</div>
<div><br></div><div>I was able to put two Signature elements in the metadata (sha1 and sha2), and it seems to work correctly (based on the configuration in internal.xml). Is this valid? Is it correct?</div><div><br></div>
<div>Liam</div></div>