<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="generator" content="Windows Mail 17.5.9600.20315">
<style data-externalstyle="true"><!--
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph {
margin-top:0in;
margin-right:0in;
margin-bottom:0in;
margin-left:.5in;
margin-bottom:.0001pt;
}
p.MsoNormal, li.MsoNormal, div.MsoNormal {
margin:0in;
margin-bottom:.0001pt;
}
p.MsoListParagraphCxSpFirst, li.MsoListParagraphCxSpFirst, div.MsoListParagraphCxSpFirst, 
p.MsoListParagraphCxSpMiddle, li.MsoListParagraphCxSpMiddle, div.MsoListParagraphCxSpMiddle, 
p.MsoListParagraphCxSpLast, li.MsoListParagraphCxSpLast, div.MsoListParagraphCxSpLast {
margin-top:0in;
margin-right:0in;
margin-bottom:0in;
margin-left:.5in;
margin-bottom:.0001pt;
line-height:115%;
}
--></style>
</head>
<body dir="ltr">
<div data-externalstyle="false" dir="ltr" style="font-family: 'Calibri', 'Segoe UI', 'Meiryo', 'Microsoft YaHei UI', 'Microsoft JhengHei UI', 'Malgun Gothic', 'sans-serif';font-size:12pt;">
<div>Having done this kind of thing for 25 years, I take a guess (and its only a guess). Guesses are useful when otherwise blocked.</div>
<div><br>
</div>
<div>The validation cannot construct a valid credential, since its has no context with which to validate the user cert itself - not being self-signed. That is, the cert should be in whatever passes for opensaml's trust store (of designated &nbsp;root certs, self-signed
 or otherwise). Or, the parent of the cert, probably self-signed, shall be in said trust store. (I don't know if opensaml can auto-chain user certs to local superiors, or of the programmer is responsible for providing them, pre chained/discovered,&nbsp;in the cred
 structure).</div>
<div><br>
</div>
<div>Knowing Scott, a metadata file on a disk is the trust store, itself potentially signed of course.</div>
<div><br>
</div>
<div>Either you are &nbsp;just pointing to the wrong key (as is easy to do), or the correct cert itself is&nbsp;&#8220;determined&#8221; by the lib to be&nbsp;&#8220;invalid&#8221;, which status manifests as&nbsp;&#8220;signature cannot validate against the cred (which is locally considered invalid due to
 chaining)&#8221;.</div>
<div><br>
</div>
<div><br>
</div>
<div data-signatureblock="true">
<div><br>
</div>
<div>Sent from Surface Pro</div>
<div><br>
</div>
</div>
<div style="padding-top: 5px; border-top-color: rgb(229, 229, 229); border-top-width: 1px; border-top-style: solid;">
<div><font face=" 'Calibri', 'Segoe UI', 'Meiryo', 'Microsoft YaHei UI', 'Microsoft JhengHei UI', 'Malgun Gothic', 'sans-serif'" style="line-height: 15pt; letter-spacing: 0.02em; font-family: &quot;Calibri&quot;, &quot;Segoe UI&quot;, &quot;Meiryo&quot;, &quot;Microsoft YaHei UI&quot;, &quot;Microsoft JhengHei UI&quot;, &quot;Malgun Gothic&quot;, &quot;sans-serif&quot;; font-size: 12pt;"><b>From:</b>&nbsp;<a href="mailto:smita.sree2007@gmail.com" target="_parent">smita.sree2007@gmail.com</a><br>
<b>Sent:</b>&nbsp;&#8206;Saturday&#8206;, &#8206;February&#8206; &#8206;15&#8206;, &#8206;2014 &#8206;6&#8206;:&#8206;27&#8206; &#8206;PM<br>
<b>To:</b>&nbsp;<a href="mailto:dev@shibboleth.net" target="_parent">Shib Dev</a></font></div>
</div>
<div><br>
</div>
<div dir="">Thanks Scott, for looking into this issue. We are not able to make sure the key is right. Client tells that they use ADFS's tokensigning certificate to sign the response and ADFS's communication certificate is the one uploaded in our SP server.
 The flow works fine, if the IDP cleint uses a test certificate given by us. So Will there be any issue with the certificate which , the IDP client used through ADFS, If so how can we identify? Is there any way to identify the mismatch between the signing certificate
 and the public key certificate? &gt;From the OpenSAML debug log(attached in first email thread), I couldn't get any useful information to identify the issue? Thanks Smitha
<br>
<hr width="300" align="left">
View this message in context: <a href="http://shibboleth.1660669.n2.nabble.com/ADFS-Opensaml2-Integration-Signature-did-not-validate-against-the-credential-s-key-tp7595247p7595296.html" target="_parent">
Re: ADFS :Opensaml2 Integration: Signature did not validate against the credential's key</a><br>
Sent from the <a href="http://shibboleth.1660669.n2.nabble.com/Shibboleth-Developers-f1660781.html" target="_parent">
Shibboleth - Developers mailing list archive</a> at Nabble.com.<br>
</div>
</div>
</body>
</html>