<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>This is now resolved - thanks to those who replied.</p>
    <p>Turned out the permissions on the signing & encryption keys
      were such that shibd couldn't read them. Not sure why it wasn't
      screaming about it into the logs, or why shibd -t didn't groan
      (the way it did when I intentionally pointed it at non-existent
      files or broke the password, to see whether it was checking those
      things).</p>
    <p>Thanks Peter Schober for confirming I'm such an OAuth non-expert
      that I don't even know the difference between OAuth and SAML ;)<br>
    </p>
    <p>I'll pass your other comments about certificates and signing on
      to the IdP folk.</p>
    <p><br>
    </p>
  </body>
</html>