<div dir="ltr"><div><div>Greetings, everyone<br><br>Sorry if this is noise/not considered topical. Couldn't find a "forum" to ask a <br>SAML question like this that was open.<br><br>I've come into disagreement with a vendor (which acts as SP) as the result of <br>key rollover. I found out that if we provide them with a SAML metadata file <br>(generated by Azure/Entra ID) which contains multiple KeyDescriptors, their <br>system fails to complete logins. This is apparently documented and their <br>workaround is to manually purge all but the one desired/active key the IdP <br>uses for signing.<br><br>If I had more reliable test results, I'd share them but it's a bit of a <br>challenge to break a working system just for testing.<br><br>I was all but certain SAML-compliance required SPs to allow use of multiple <br>keys and to allow valid signatures from any key to work for SAML assertions. <br><br>The below would seem to support that, but I wanted to ask those more familiar <br>with the nuance to give me the more detailed "it depends" answer.<br><br><a href="https://docs.oasis-open.org/security/saml/Post2.0/sstc-metadata-iop.html">https://docs.oasis-open.org/security/saml/Post2.0/sstc-metadata-iop.html</a> (2.6.1)<br><br>Thanks in advance!</div></div></div>