ADFS :Opensaml2 Integration: Signature did not validate against the credential's key

Peter Williams pwilliams at rapattoni.com
Fri Feb 21 11:48:52 EST 2014


For your clients 2048 (adfs) case, apply to the sp

http://www.oracle.com/technetwork/java/javase/downloads/jce-6-download-429243.html

let us know if things work then.

There are n variants of rsa2048/sha256, with different names for the same thing. Some, that control interworking, require policy files.

I think that one is supposed to pay consultancy fees to one of the 250million exceptional folk, for this kind of hidden knowhow. There are hidden taxes on interworking with adfs, that is. note the license agreement of the Java regime, which obligates the ( now not open ) world to the us. Usual us crypto politics... don't know why I'm singling out the us, since the uk no better with both suffering from acute spying addictions.

Sent from Surface Pro

From: smita.sree2007 at gmail.com<mailto:smita.sree2007 at gmail.com>
Sent: ?Friday?, ?February? ?21?, ?2014 ?12?:?27? ?AM
To: Shib Dev<mailto:dev at shibboleth.net>

Scott,

This works now for the IDP client , when they tried with another certificate
,which is a 1024bit/SHA1 certificate.  :)

Mostly issue should have been with the wrong key as you guessed. And it
might have worked now, when they tried with a new setup , with another new
certificate. But they think,the issue was Our SP implementation(using
OpenSAML) , doesn't support 2048/sha256 certificate. But I had tested using
my test certificate which is of  2048/sha256, and it worked fine .

So just wanted to confirm once again that Opensaml doesn't have any
restriction on certificate key size/algorithm as 2048/sha256,?


Thanks
Smitha Nair



--
View this message in context: http://shibboleth.1660669.n2.nabble.com/ADFS-Opensaml2-Integration-Signature-did-not-validate-against-the-credential-s-key-tp7595247p7595580.html
Sent from the Shibboleth - Developers mailing list archive at Nabble.com.
--
To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20140221/85b6e9db/attachment.html 


More information about the dev mailing list