<div dir="auto"><div>Peter,</div><div dir="auto"><br></div><div dir="auto">Good tip about encryption, I'll take a look. Ultimately, it'll depend on whether the customer's IdP will support encryption or not.</div><div dir="auto"><br></div><div dir="auto">Yes, the checklist is specific to my SP, but I had no idea what the hierarchy of xml files was. I had no idea metadata-providers.xml was the first thing you should fill out to configure your SP, then relying-party.xml to configure a "profile" (still unsure how a profile determines auth method), then general-authn.xml to configure the authentication method, which then goes to the auth-specific xml file. I don't see how that general order of xml docs is specific to my (mock) deployment.</div><div dir="auto"><br></div><div dir="auto">Again, thanks for your help.</div><div dir="auto">Brandon</div></div>