HiDominick Baier
Just want to double confirm with you on one concept based on your reply.
When client's STS (IdP) sends the Security Token to the Relying Party's STS, the digital signature certificate is actually included in the security token and when Replying Party's STS verifies the signature, it actually extracts the certification from the security token? That is the reason why we don't really need to install client's certificates to our certification store and we can just compare the thumbprint (and maybe together with IssuerName and so on)?
Initially, i have some confusion of whether the security token does include the certificate in the security token sent from client's STS to Relying Party's STS.