<div dir="ltr">Sorry for wasting your time, but I found there was an error in my httpd configuration.<div>I didn't set the application ID of the endpoints (ie. /Shibboleth.sso), </div><div>which I mistakenly thought not necessary for the vhost strategy.</div><div>Thus when the endpoint is visited after authentication, it's taken as the default application, </div><div>which mismatches the recipient of the EncryptedKey entry.</div><div><br></div><div>In short, setting the applicationId of the endpoints solve the problem.</div></div>