<div dir="ltr">Thanks Tom for your answer. <div><br></div><div>That was the problem, although I was hoping that Shibb&#39;s IDP will give me a more accurate error; I&#39;m not saying that the message was wrong, but that the error was more related to xml schema-valid than expire or wrong certificate.</div><div><br></div><div>Thanks again. </div><div><br></div><div>Regards.</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Sep 8, 2014 at 8:17 AM, Tom Scavo <span dir="ltr">&lt;<a href="mailto:trscavo@gmail.com" target="_blank">trscavo@gmail.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On Mon, Sep 8, 2014 at 9:04 AM, Thomas Jones &lt;<a href="mailto:thomas.jones.g@gmail.com">thomas.jones.g@gmail.com</a>&gt; wrote:<br>
&gt;<br>
&gt; I loaded Shib&#39;s idp.crt file into the SP (they stored it in the KeyStore)<br>
&gt; but as you can see I getting a problem with the certificate.<br>
<br>
</span>For starters, the SP&#39;s metadata does not appear to be schema-valid.<br>
There should be a &lt;md:KeyDescriptor&gt; element around &lt;ds:KeyInfo&gt;, I<br>
believe.<br>
<span class="HOEnZb"><font color="#888888"><br>
Tom<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br></div>