<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="generator" content="Windows Mail 17.5.9600.20315">
<style type="text/css"><!--html { font-family: "Color Emoji", "Calibri", "Segoe UI", "Meiryo", "Microsoft YaHei UI", "Microsoft JhengHei UI", "Malgun Gothic", "sans-serif"; }--></style><style data-externalstyle="true"><!--
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph {
margin-top:0in;
margin-right:0in;
margin-bottom:0in;
margin-left:.5in;
margin-bottom:.0001pt;
}
p.MsoNormal, li.MsoNormal, div.MsoNormal {
margin:0in;
margin-bottom:.0001pt;
}
p.MsoListParagraphCxSpFirst, li.MsoListParagraphCxSpFirst, div.MsoListParagraphCxSpFirst, 
p.MsoListParagraphCxSpMiddle, li.MsoListParagraphCxSpMiddle, div.MsoListParagraphCxSpMiddle, 
p.MsoListParagraphCxSpLast, li.MsoListParagraphCxSpLast, div.MsoListParagraphCxSpLast {
margin-top:0in;
margin-right:0in;
margin-bottom:0in;
margin-left:.5in;
margin-bottom:.0001pt;
line-height:115%;
}
--></style>
</head>
<body dir="ltr">
<div data-externalstyle="false" dir="ltr" style="font-family: 'Calibri', 'Segoe UI', 'Meiryo', 'Microsoft YaHei UI', 'Microsoft JhengHei UI', 'Malgun Gothic', 'sans-serif';font-size:12pt;">
<div>For your clients 2048 (adfs) case, apply to the sp</div>
<div><br>
</div>
<div><a href="http://www.oracle.com/technetwork/java/javase/downloads/jce-6-download-429243.html" target="_parent">http://www.oracle.com/technetwork/java/javase/downloads/jce-6-download-429243.html</a></div>
<div><br>
</div>
<div>let us know if things work then.</div>
<div><br>
</div>
<div>There are n variants of rsa2048/sha256, with different names for the same thing. Some, that control interworking, require policy files.</div>
<div><br>
</div>
<div>I think that&nbsp;one is supposed&nbsp;to pay&nbsp;consultancy fees to one of the 250million exceptional folk, for this kind of hidden knowhow.&nbsp;There are hidden taxes on interworking with adfs, that is.&nbsp;note the license agreement of the Java regime, which obligates the
 (&nbsp;now not open ) world to the us. Usual us crypto politics&#8230; don't know why&nbsp;I'm singling out the us, since the&nbsp;uk no better with&nbsp;both suffering from acute spying addictions.<br>
</div>
<div data-signatureblock="true">
<div><br>
</div>
<div>Sent from Surface Pro</div>
<div><br>
</div>
</div>
<div style="padding-top: 5px; border-top-color: rgb(229, 229, 229); border-top-width: 1px; border-top-style: solid;">
<div><font face=" 'Calibri', 'Segoe UI', 'Meiryo', 'Microsoft YaHei UI', 'Microsoft JhengHei UI', 'Malgun Gothic', 'sans-serif'" style="line-height: 15pt; letter-spacing: 0.02em; font-family: &quot;Calibri&quot;, &quot;Segoe UI&quot;, &quot;Meiryo&quot;, &quot;Microsoft YaHei UI&quot;, &quot;Microsoft JhengHei UI&quot;, &quot;Malgun Gothic&quot;, &quot;sans-serif&quot;; font-size: 12pt;"><b>From:</b>&nbsp;<a href="mailto:smita.sree2007@gmail.com" target="_parent">smita.sree2007@gmail.com</a><br>
<b>Sent:</b>&nbsp;&#8206;Friday&#8206;, &#8206;February&#8206; &#8206;21&#8206;, &#8206;2014 &#8206;12&#8206;:&#8206;27&#8206; &#8206;AM<br>
<b>To:</b>&nbsp;<a href="mailto:dev@shibboleth.net" target="_parent">Shib Dev</a></font></div>
</div>
<div><br>
</div>
<div dir="">
<div id="readingPaneBodyContent">Scott,<br>
<br>
This works now for the IDP client , when they tried with another certificate<br>
,which is a 1024bit/SHA1 certificate.&nbsp; :)<br>
<br>
Mostly issue should have been with the wrong key as you guessed. And it<br>
might have worked now, when they tried with a new setup , with another new<br>
certificate. But they think,the issue was Our SP implementation(using<br>
OpenSAML) , doesn't support 2048/sha256 certificate. But I had tested using<br>
my test certificate which is of&nbsp; 2048/sha256, and it worked fine .&nbsp; <br>
<br>
So just wanted to confirm once again that Opensaml doesn't have any<br>
restriction on certificate key size/algorithm as 2048/sha256,?<br>
<br>
<br>
Thanks<br>
Smitha Nair <br>
<br>
<br>
<br>
--<br>
View this message in context: http://shibboleth.1660669.n2.nabble.com/ADFS-Opensaml2-Integration-Signature-did-not-validate-against-the-credential-s-key-tp7595247p7595580.html<br>
Sent from the Shibboleth - Developers mailing list archive at Nabble.com.<br>
--<br>
To unsubscribe from this list send an email to dev-unsubscribe@shibboleth.net<br>
</div>
</div>
</div>
</body>
</html>