SAML Response may have multiple signatures validate all signatures. <Response> <Signature required="false" /> <Assertion> <Signature required="false" />? </Assertion> </Response> We should attempt first check & validate Response and/or Assertion