<div dir="ltr">A vended SP is upgrading their signing cert to one signed with sha512WithRSAEncryption . Adding the new cert as a second signing cert into their SP metadata seems the seamless way to ease the transition, eventually removing the old SHA1 signed cert after the transition is complete. I'm assuming/hoping IdP v2 will verify their SAML assertion which ever of the two certs they use to sign the assertion. Or is this more complex than I've assumed?<div><br></div><div>David Bantz</div><div>U Alaska</div></div>