Missing Metadata -> Encryption Key Errors
Nate Klingenstein
ndk at internet2.edu
Mon Oct 19 22:42:52 EDT 2015
All,
I think the Installfest today encountered a strange bug in IdPv3.1.2. I don’t have the logs on hand or an installation with which to immediately confirm, but it’s pretty easy to test, and I can get the logs tomorrow if need be.
If an AttributeRequesterString match attribute filter policy exists for an SP that doesn’t have any metadata loaded associated with it, errors seem to get thrown regarding the encryption key being bad. Given that there is no key at all, much less metadata, this isn’t surprising, but the error message was pretty unintuitive.
Removing the attribute filter policy or fixing the entityID to match one that was present in metadata resulted in successful encryption and transmission of an assertion and associated attributes.
If the diagnosis is correct and it wouldn’t be too hard to trap that error as something more natural, it would make fixing that way more obvious.
Thanks in advance for your help,
Nate.
More information about the dev
mailing list