ADFS :Opensaml2 Integration: Signature did not validate against the credential's key

smita.sree2007 at gmail.com smita.sree2007 at gmail.com
Tue Feb 18 06:38:53 EST 2014


Hi Scott,
Really appreciate all your help

Rreagrding the points in
https://wiki.shibboleth.net/confluence/display/OpenSAML/OSTwoUserManSigErrors

1. Ensure your keys are right
 >> We had asked the IDP client to make sure that the private key ,they use
to sign, is the right pair of the the public key the given us(SP) to
validate. They replied that, they use ADFS's token-signing certificate  to
sign, and what they given us , is the ADFS's communication certificate. They
tell , those should match( I am not aware of ADFS config, so not really able
to make sure the keys are right)
 

2. Ensure your software is update
>> We use Opensaml 2.2.3. After this issue, we have upgraded to Opensaml
>> 2.6.1 and tested. Results were same.


3. Ensure the content isn't being changed by your parser
>> If this is the case, the flow should not have worked when we tested using
>> , my test certificate. With my test certificate the flow worked fine, but
>> not with the IDP'd original certificate.


4. Validate the signature with known-good tools
    -I 'm working tocheck this, for my working SAML response also ,online
signature verifier gave negative result. So bit confused on that.
5. Compare the content
    -This one I 'll work with client to get the pre-signed data and compare
	
Thanks
Smitha	



--
View this message in context: http://shibboleth.1660669.n2.nabble.com/ADFS-Opensaml2-Integration-Signature-did-not-validate-against-the-credential-s-key-tp7595247p7595398.html
Sent from the Shibboleth - Developers mailing list archive at Nabble.com.


More information about the dev mailing list