Assume that you have a SAML trust relationship with another site, and that site is digitally signing incoming SAML assertions to you.

When the SAML extension server generates an outbound SSL request, the received SSL Server Certificate is checked against the certificates stored in the JVM.

This section covers the viewpoint of a site administrator who wants to receive signed SAML data from a Trusted Affiliate.

At this point, you are configuring properties relating to the receiving half of the SAML relationship.

If the provided SSL Client Certificate exists in its Trusted Roots container, i Chain trusts the certificate; or, if the provided SSL Client Certificate was signed by a CA that is in the Trusted Roots container, then i Chain trusts the certificate.

If neither the client certificate nor its CA is found in i Chain's Trusted Roots container, the SSL Client certificate is rejected and the connection closed.

