CRM is an app, not an IdP. You are trying it on the opposite side. It should be configured as a "Relying Party". The Federation Metadata document can describe both ends: IdP and RP.
I haven't tried CRM on ACS though, so I'm not sure it will work. (it should, but...). I do remember that it requires token encryption.