Hi, Emma.
It looks like all your difficulties this time can be attributed to SP configuration. Errors due to stale request isn't something IDP causes usually. Unless you press some "Back" button along the way, or make previous request replayed in any other way (or may be your system clock is not synced), it means SP sends invalid (replayed) request. Can't comment on the certificate question either, normally you need to upload certificate, not just its fingerprint, though.
Unfortunately, we don't cover SP-related issues under Community Support, only questions related to our products. Unless you'll be able to show how it's a Gluu Server's issue, your best chance to get some help is to contact this SP's support, or ask around in some related communities.