ADFS :Opensaml2 Integration: Signature did not validate against the credential's key

Cantor, Scott cantor.2 at osu.edu
Tue Feb 18 10:32:27 EST 2014


On 2/18/14, 6:38 AM, "smita.sree2007 at gmail.com" <smita.sree2007 at gmail.com>
wrote:
>>> We had asked the IDP client to make sure that the private key ,they use
>to sign, is the right pair of the the public key the given us(SP) to
>validate. They replied that, they use ADFS's token-signing certificate  to
>sign, and what they given us , is the ADFS's communication certificate.
>They
>tell , those should match( I am not aware of ADFS config, so not really
>able
>to make sure the keys are right)

Well, then don't waste your time until you can, because that is very
likely to be the error. I have no reason to think those two keys would be
the same, and neither do you.

>3. Ensure the content isn't being changed by your parser
>>> If this is the case, the flow should not have worked when we tested
>>>using
>>> , my test certificate. With my test certificate the flow worked fine,
>>>but
>>> not with the IDP'd original certificate.

That is likely, yes.

I would bet $50 the key is wrong. So I strongly suggest you not waste your
time. If the IdP won't coooperate, then you need to escalate to management.

-- Scott




More information about the dev mailing list