<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
Karla,
<div class=""><br class="">
</div>
<div class="">The short answer is, the signing certificate.</div>
<div class=""><br class="">
</div>
<div class="">The long answer is that it’s up to the metadata.  Metadata for providers can contain keys for signing, encryption, or both, which is the default.  There’s almost nothing that the IdP needs to receive encrypted, though.  I can’t think of anything
 out of the box.  So, your metadata should match your deployment, and in a default deployment it’s mostly used to validate your signatures.</div>
<div class=""><br class="">
</div>
<div class="">Take care,</div>
<div class="">Nate.</div>
<div class=""><br class="">
<div>
<blockquote type="cite" class="">
<div class="">On Mar 14, 2016, at 12:59, Karla Borecky <<a href="mailto:kborecky@smith.edu" class="">kborecky@smith.edu</a>> wrote:</div>
<br class="Apple-interchange-newline">
<div class="">
<div style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;" class="">
(Not encryption, I know that now.) What would someone do if their v3 IdP were a new addition to InCommon?</div>
<br class="Apple-interchange-newline">
</div>
</blockquote>
</div>
<br class="">
</div>
</body>
</html>