// Verify the signature
WSDocInfo docInfo = new WSDocInfo(token.getOwnerDocument());
assertion.verifySignature(requestData, docInfo);
// Parse the HOK subject if it exists
assertion.parseHOKSubject(requestData, docInfo);
// Now verify trust on the signature
Credential trustCredential = new Credential();
SAMLKeyInfo samlKeyInfo = assertion.getSignatureKeyInfo();
trustCredential.setPublicKey(samlKeyInfo.getPublicKey());