Paste the certificate from your IdP metadata. It is compared with the one embedded in the signature, and used to verify signatures that carry no KeyInfo.