Not sure if the extended key usage was needed, but I added it using an openssl config file with the information in there and then the -extensions attribute pointing to a section in the config file. Also the keystore alias in the SP configuration (defaults to "signing") is the "Entry Name" in the cert, I updated the SP config to "1" as that's what OpenSSL defaults the entry name to. Once our federation info was updated, the cert worked fine. 🙂