<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <p><br>
    </p>
    <br>
    <div class="moz-cite-prefix">On 2/8/17 3:13 PM, Klingenstein, Nate
      wrote:<br>
    </div>
    <blockquote
cite="mid:MWHPR01MB2222EB7CA3B8DFFCB817F2DEDE420@MWHPR01MB2222.prod.exchangelabs.com"
      type="cite">
      <pre wrap="">No, two are marked signing and one encryption.  I tried compressing them
down to a single KeyDescriptor with no use, but to no use.
</pre>
    </blockquote>
    <br>
    If it's not something else obvious: Does the encryption
    KeyDescriptor have any EncryptionMethod child elements?   Those
    historically weren't terribly common, although the Shib SP does
    include them now. Don't know about Spring Security SAML.  But if
    present, those do influence the resolution process. <br>
    <br>
    If so (or even if not), turning those 2 categories I mentioned in
    the other note up to TRACE might be informative.<br>
    <br>
  </body>
</html>