ADFS :Opensaml2 Integration: Signature did not validate against the credential's key

Peter Williams pwilliams at rapattoni.com
Mon Feb 24 10:24:45 EST 2014


Lets summarize facts (ie indicate which statements are false below)

adfs 2.1 (in windows 20120r2) can interwork with the minimal opensaml sp

adfs is using windows-generated 1024bit key, using default cryptoprovider (not some hsm)

The sp fails when using a 2048 bit key, with the same conditions as above otherwise.

(ITS WITH LOOKING at the cryptoprovider for the 2048bit key in windows. Is it the same as that for the 1024bit case?)

my last 2 guesses are that

2048 bit key is not using an exponent compatible with the Java cps
The bitlength is not byte aligned, which upsets some receiving cps.

I tried and failed to compile the source on windows : the c# build mechanisms are just too old for my modern dev platform. I dont have the willpower to go back to building with open source Java tool chains. You might want to do the latter, since obviously it will reveal the source of the exception clearly.

Sorry could not help more.


Sent from Surface Pro

From: smita.sree2007 at gmail.com<mailto:smita.sree2007 at gmail.com>
Sent: ?Sunday?, ?February? ?23?, ?2014 ?9?:?24? ?PM
To: Shib Dev<mailto:dev at shibboleth.net>

We use  Java 1.6.0_45.

Williams,

We already have JCE files.

Thanks
Smitha



--
View this message in context: http://shibboleth.1660669.n2.nabble.com/ADFS-Opensaml2-Integration-Signature-did-not-validate-against-the-credential-s-key-tp7595247p7595653.html
Sent from the Shibboleth - Developers mailing list archive at Nabble.com.
--
To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20140224/6891ac75/attachment.html 


More information about the dev mailing list