Checks the configured signing certificate, or the partner key that verified a token, for revocation once it has verified a response, and continues the sign-in only if it is still accepted.
A refused certificate is answered 401 (STS-PKI-0129); a throw while
continuing is answered 500 (STS-FED-0042).
the request
the response
the federation relationship
what completes the sign-in
Optionaljwk: any
the partner key that verified a JWT, if that is what is checked
a promise of what proceed or the refusal returns
Forwards to
FederationSp.signerStillAccepted().