OK. Thanks for a tip. I have manage to solve this using powershell script to modify ADFS metadata. Now it is validates sucessfully.
Unfortunatelly I have another error. When forwarding logon request from ADFS to Gluu I've got in the logs:
> 2017-04-15 16:19:23,366 - WARN [org.opensaml.profile.action.impl.LogEvent:76] -2017-04-15 16:21:54,252 - INFO [org.opensaml.saml.common.binding.impl.SAMLMetadataLookupHandler:128] - Message Handler: No metadata returned for http://sts.keralots.com/adfs/services/trust in role {urn:oasis:names:tc:SAML:2.0:metadata}SPSSODescriptor with protocol urn:oasis:names:tc:SAML:2.0:protocol
2017-04-15 16:21:54,255 - WARN [net.shibboleth.idp.profile.impl.SelectProfileConfiguration:111] - Profile Action SelectProfileConfiguration: Profile http://shibboleth.net/ns/profiles/saml2/sso/browser is not available for relying party configuration shibboleth.UnverifiedRelyingParty
2017-04-15 16:21:54,256 - WARN [org.opensaml.profile.action.impl.LogEvent:76] - An error event occurred while processing the request: InvalidProfileConfiguration