<div dir="ltr">Thanks Tom for your answer. <div><br></div><div>That was the problem, although I was hoping that Shibb's IDP will give me a more accurate error; I'm not saying that the message was wrong, but that the error was more related to xml schema-valid than expire or wrong certificate.</div><div><br></div><div>Thanks again. </div><div><br></div><div>Regards.</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Sep 8, 2014 at 8:17 AM, Tom Scavo <span dir="ltr"><<a href="mailto:trscavo@gmail.com" target="_blank">trscavo@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On Mon, Sep 8, 2014 at 9:04 AM, Thomas Jones <<a href="mailto:thomas.jones.g@gmail.com">thomas.jones.g@gmail.com</a>> wrote:<br>
><br>
> I loaded Shib's idp.crt file into the SP (they stored it in the KeyStore)<br>
> but as you can see I getting a problem with the certificate.<br>
<br>
</span>For starters, the SP's metadata does not appear to be schema-valid.<br>
There should be a <md:KeyDescriptor> element around <ds:KeyInfo>, I<br>
believe.<br>
<span class="HOEnZb"><font color="#888888"><br>
Tom<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br></div>