Keystore for the SP configuration

Hi experts, I am slowly starting to get a bit desperate because I am unable to set up a SAML configuration on a Custom Domain. The problem is that every time I get a wrong certificate (Mendix signed) from the Metadata of the SP configuration, see image below and this certificate cannot be used for the configuration in TIH (The identity hub). Is there a manual that describes the (technical) specifications for the keystore. I have a private key and public key from the dutch PKI root. What am I doing wrong?? Kind regards Lars  
0 answers