On 3/20/14, 11:50 AM, "M. D." <mo...@abv.bg> wrote: > >By 'the entity cert' do you mean the certificate containing the >validation key, that should be used for signature validation?
Yes, typically. >So the KeyInfo.getX509Certificate() returns the exact right certificate >of all the certificates of all X509Elements? I can pretty much guarantee not, unless the usual ordering is followed. -- Scott