<div dir="ltr"><font face="arial, sans-serif">A few SPs digitally sign requests, but rotate their signing certificate frequently (and not always even just because they expire!). I've long accommodated them but am now considering the sage advice I've been given to disable validation of signed requests for (at least some of) these SPs. </font><br><br><font color="#444444" style=""><font face="arial, sans-serif">I can remove the </font><font face="monospace"><span class="gmail-s1" style="font-variant-ligatures:no-common-ligatures">AuthnRequestsSigned</span><span class="gmail-s2" style="font-variant-ligatures:no-common-ligatures">=</span></font><span class="gmail-s3" style="font-variant-ligatures:no-common-ligatures"><font face="monospace">"true"</font> </span><span class="gmail-s3" style="font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures">element a</span><span class="gmail-s3" style="font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures">nd signing certificate from our local cache of the SP metadata of course, but what will the IdP (5.4.2) do with a signed request that cannot be validated? Do I also need a relying-party override to ignore the fact that the signature on the request cannot be validated?</span></font><div><font color="#444444" style=""><span class="gmail-s3" style="font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures"><br></span></font></div><div><font color="#444444" style=""><span class="gmail-s3" style="font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures">David St PIerre Bantz</span></font></div><div><font color="#444444" style=""><span class="gmail-s3" style="font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures">U Alaska IAM</span></font></div></div>