[JIRA] Commented: (JOST-162) Globally enabling schema validation breaks the Signature metadata filter

Chad La Joie (JIRA) noreply at shibboleth.net
Wed Sep 28 14:26:25 BST 2011


    [ https://issues.shibboleth.net/jira/browse/JOST-162?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13588#comment-13588 ] 

Chad La Joie commented on JOST-162:
-----------------------------------

Well, this looks like the infamous "shib:Scope regexp default value" problem.  Obviously anything that changes the DOM in anything but incredibly trivial ways is going to break the signature and replacing attribute values and what not is certainly a non-trivial change.

So, for now, I'm treating this as a documentation issue.  I've added a new section to https://wiki.shibboleth.net/confluence/display/OpenSAML/OSTwoUserManSigErrors and specifically noted normalized-value Xerces feature.

> Globally enabling schema validation breaks the Signature metadata filter
> ------------------------------------------------------------------------
>
>                 Key: JOST-162
>                 URL: https://issues.shibboleth.net/jira/browse/JOST-162
>             Project: OpenSAML 2 - Java
>          Issue Type: Bug
>          Components: SAML 2
>    Affects Versions: 2.5.0
>         Environment: Jetty 7.4, Java 1.6, Linux, latest endorsed libraries
>            Reporter: Scott Cantor
>            Assignee: Chad La Joie
>
> When schema validation is enabled for the parser pool in the IdP, the signature metadata filter starts refusing to validate the signature over metadata that is known to be valid. It loads in other respects.

--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira


More information about the commits mailing list