[JIRA] Moved: (CPPXT-91) Failure to validate Response Signature

Scott Cantor (JIRA) noreply at shibboleth.net
Fri Oct 5 19:16:21 EDT 2012


     [ https://issues.shibboleth.net/jira/browse/CPPXT-91?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Scott Cantor moved SSPCPP-513 to CPPXT-91:
------------------------------------------

          Component/s:     (was: SAML 2.0 Single Sign-On)
                       Security
    Affects Version/s:     (was: 2.5.0)
                       1.5.0
                       1.5.1
           Issue Type: Improvement  (was: Bug)
                  Key: CPPXT-91  (was: SSPCPP-513)
              Project: XMLTooling - C++  (was: Shibboleth SP - C++)

> Failure to validate Response Signature
> --------------------------------------
>
>                 Key: CPPXT-91
>                 URL: https://issues.shibboleth.net/jira/browse/CPPXT-91
>             Project: XMLTooling - C++
>          Issue Type: Improvement
>          Components: Security
>    Affects Versions: 1.5.1, 1.5.0
>            Reporter: rhoerbe at idp.protectnetwork.org
>            Assignee: Scott Cantor
>            Priority: Minor
>              Labels: TrustEngine
>         Attachments: shibspKeyExtr.zip
>
>
> as described in the mail thread on shib-users from today:
> These are the log messages after the Response was decoded:
> OpenSAML.MessageDecoder.SAML2 [2]: extracting issuer from SAML 2.0 protocol message
> OpenSAML.MessageDecoder.SAML2 [2]: message from (https://apps.egiz.gv.at/moa-id-stork-test/)
> OpenSAML.MessageDecoder.SAML2 [2]: searching metadata for message issuer...
> OpenSAML.SecurityPolicyRule.MessageFlow [2]: evaluating message flow policy (replay checking on, expiration 60)
> XMLTooling.StorageService [2]: inserted record (_eb6...) in context (MessageFlow) with expiration ..
> OpenSAML.SecurityPolicyRule.XMLSigning [2]: validating signature profile
> XMLTooling.KeyInfoResolver.Inline [2]: resolved 0 certificate(s)
> XMLTooling.KeyInfoResolver.Inline [2]: resolved 0 CRL(s)
> XMLTooling.TrustEngine.ExplicitKey [2]: attempting to validate signature with the peer's credentials
> XMLTooling.TrustEngine.ExplicitKey [2]: public key did not validate signature: Credential did not contain a verification key.
> The zip-archive contains the IDP's certificate files, metadata, response message and logfiles.

--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira


More information about the commits mailing list