Saml2RelyingPartyRegistrationConfiguration does not support setting of decryptionX509Credentials.
Via Java Config it is possible to set decryption credentials like this:
final RelyingPartyRegistration relyingPartyRegistration = RelyingPartyRegistrations
.fromMetadataLocation("http://localhost:8081/auth/realms/DemoRealm/protocol/saml/descriptor")
.registrationId("demo-saml-client")
.entityId("demo-saml-client")
.signingX509Credentials(c -> c.add(getSigningCredential()))
.decryptionX509Credentials(c -> c.add(getDecryptionCredential()))
.build();
Unfortunately this is not possible via Spring Boot application.properties.