<div dir="ltr">I've been given metadata for vended service that contains an X509 certificate, but the IdP (v2) does not see it as an encryption key (sends a SAML status indicating failure to encrypt, with logs indicating no key encryption credential found for the entity).<div><br>The vendor tells me they have "encryption turned on" and confirmed the metadata. The certificate in the metadata however is fully contained within <ds:Signature...>...</ds:Signature>. Can / should such a cert be used by the IdP to encrypt the SAML response?</div><div><br></div><div>David Bantz</div><div>UA OIT IAM</div></div>