<div dir="ltr"><div>Does the IDP (4.0.1) always verify the signature on signed AuthnRequests unlessĀ <a href="https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631694/SAML2SSOConfiguration">ignoreRequestSignatures</a> has been set to true?</div><div><br></div>We have an SP that is sending us signed AuthnRequests. We see occasional signature verification issues for this SP and in investigatingĀ this I discovered that that SP's advertised metadata did not match the metadata for them that we have in our IdP. The new metadata contains only one key with use="signing" and this key is different to the key in our metadata. We have a relying party override for this SP to set signAssertions="true", encryptAssertions="false".<div><br></div><div>The SP have confirmed that they are using the key in their advertised metadata. We only get signed AuthnRequests from this SP, and so I cannot understand how SSO is currently working if this is the case.</div><div><br></div><div>Thanks,</div><div><br></div><div>Max Spicer</div></div>