<div dir="ltr"><div>Hi, <br></div><div>below are the error messages i'm getting.</div><div><br></div>2019-08-26 08:25:44 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [3] [default]: validating signature profile<br>2019-08-26 08:25:44 DEBUG XMLTooling.TrustEngine.PKIX [3] [default]: validating signature using certificate from within the signature<br>2019-08-26 08:25:44 DEBUG XMLTooling.TrustEngine.PKIX [3] [default]: signature verified with key inside signature, attempting certificate validation...<br>2019-08-26 08:25:44 DEBUG XMLTooling.TrustEngine.PKIX [3] [default]: checking that the certificate name is acceptable<br>2019-08-26 08:25:44 DEBUG XMLTooling.TrustEngine.PKIX [3] [default]: adding to list of trusted names (urn:saml2:mkoramcfinscom)<br>2019-08-26 08:25:44 DEBUG XMLTooling.TrustEngine.PKIX [3] [default]: certificate subject: CN=<a href="http://idp.mfintl.com">idp.mfintl.com</a>,OU=Domain Control Validated<br>2019-08-26 08:25:44 DEBUG XMLTooling.TrustEngine.PKIX [3] [default]: unable to match DN, trying TLS subjectAltName match<br>2019-08-26 08:25:44 DEBUG XMLTooling.TrustEngine.PKIX [3] [default]: unable to match subjectAltName, trying TLS CN match<br>2019-08-26 08:25:44 ERROR XMLTooling.TrustEngine.PKIX [3] [default]: certificate name was not acceptable<br>2019-08-26 08:25:44 WARN OpenSAML.SecurityPolicyRule.XMLSigning [3] [default]: unable to verify message signature with supplied trust engine<br>2019-08-26 08:25:44 WARN Shibboleth.SSO.SAML2 [3] [default]: error processing incoming assertion: Message was signed, but signature could not be verified.<br><div><br></div><div><br></div><div>my understanding is IDP name doesn't need to match the signing certificate name.</div></div>