<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <p><br>
    </p>
    <br>
    <div class="moz-cite-prefix">On 2/8/17 3:55 PM, Klingenstein, Nate
      wrote:<br>
    </div>
    <blockquote
cite="mid:MWHPR01MB2222411C344250CDDFAA249DDE420@MWHPR01MB2222.prod.exchangelabs.com"
      type="cite">
      <pre wrap="">What happens if a byte-identical certificate is placed in metadata
twice, once as an explicit use="signing" and once as an explicit
use="encryption", as compared to the more traditional use of separate
keys or no use element?
</pre>
    </blockquote>
    <br>
    AFAIK it's not a problem.  It's not going to result in one of them
    not being resolved or something like that.  Some people have been
    doing that for quite a long time, I think.<br>
    <br>
    As Scott said, having everything globally thing on DEBUG is probably
    confusing. TMI.  However, since you've now narrowed this down to a
    failure to resolve encryption key for the SP, putting the following
    on DEBUG or even TRACE temporarily might be informative:<br>
    <br>
    org.opensaml.xmlsec.impl<br>
    org.opensaml.saml.security.impl<br>
    <br>
    It will at least give you some trace data that the credentials you
    think are being processed in the metadata actually are, and what's
    going on with them.<br>
  </body>
</html>