<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<p>This is now resolved - thanks to those who replied.</p>
<p>Turned out the permissions on the signing & encryption keys
were such that shibd couldn't read them. Not sure why it wasn't
screaming about it into the logs, or why shibd -t didn't groan
(the way it did when I intentionally pointed it at non-existent
files or broke the password, to see whether it was checking those
things).</p>
<p>Thanks Peter Schober for confirming I'm such an OAuth non-expert
that I don't even know the difference between OAuth and SAML ;)<br>
</p>
<p>I'll pass your other comments about certificates and signing on
to the IdP folk.</p>
<p><br>
</p>
</body>
</html>