<div dir="ltr">Hello,<div>I have an SP credentials setup similar to what is shown in the <a href="https://shibboleth.atlassian.net/wiki/spaces/SP3/pages/2067398968/Multiple+Credentials#MultipleCredentials-KeyRollover">cert rollover</a> documentation.</div><div>I have ended up in a situation where I have two certs that do not specify the "use" attribute.</div><div>I assume this is not best practice - and I am working towards marking one of them as "use=encryption".</div><div><br></div><div>But I am curious about which cert is used for signing in this case? Is it the first cert in the config without the "use" attribute?</div><div><br></div><div>Thanks,</div><div>Jay</div></div>