<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="generator" content="Windows Mail 17.5.9600.20315">
<style type="text/css"><!--html { font-family: "Color Emoji", "Calibri", "Segoe UI", "Meiryo", "Microsoft YaHei UI", "Microsoft JhengHei UI", "Malgun Gothic", "sans-serif"; }--></style><style data-externalstyle="true"><!--
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph {
margin-top:0in;
margin-right:0in;
margin-bottom:0in;
margin-left:.5in;
margin-bottom:.0001pt;
}
p.MsoNormal, li.MsoNormal, div.MsoNormal {
margin:0in;
margin-bottom:.0001pt;
}
p.MsoListParagraphCxSpFirst, li.MsoListParagraphCxSpFirst, div.MsoListParagraphCxSpFirst,
p.MsoListParagraphCxSpMiddle, li.MsoListParagraphCxSpMiddle, div.MsoListParagraphCxSpMiddle,
p.MsoListParagraphCxSpLast, li.MsoListParagraphCxSpLast, div.MsoListParagraphCxSpLast {
margin-top:0in;
margin-right:0in;
margin-bottom:0in;
margin-left:.5in;
margin-bottom:.0001pt;
line-height:115%;
}
--></style>
</head>
<body dir="ltr">
<div data-externalstyle="false" dir="ltr" style="font-family: 'Calibri', 'Segoe UI', 'Meiryo', 'Microsoft YaHei UI', 'Microsoft JhengHei UI', 'Malgun Gothic', 'sans-serif';font-size:12pt;">
<div>Lets summarize facts (ie indicate which statements are false below)</div>
<div><br>
</div>
<div>adfs 2.1 (in windows 20120r2) can interwork with the minimal opensaml sp</div>
<div><br>
</div>
<div>adfs is using windows-generated 1024bit key, using default cryptoprovider (not some hsm)</div>
<div><br>
</div>
<div>The sp fails when using a 2048 bit key, with the same conditions as above otherwise.</div>
<div><br>
</div>
<div>(ITS WITH LOOKING at the cryptoprovider for the 2048bit key in windows. Is it the same as that for the 1024bit case?)</div>
<div><br>
</div>
<div>my last 2 guesses are that </div>
<div><br>
</div>
<div>2048 bit key is not using an exponent compatible with the Java cps</div>
<div>The bitlength is not byte aligned, which upsets some receiving cps.</div>
<div><br>
</div>
<div>I tried and failed to compile the source on windows : the c# build mechanisms are just too old for my modern dev platform. I dont have the willpower to go back to building with open source Java tool chains. You might want to do the latter, since obviously
it will reveal the source of the exception clearly.</div>
<div><br>
</div>
<div>Sorry could not help more.</div>
<div><br>
</div>
<div data-signatureblock="true">
<div><br>
</div>
<div>Sent from Surface Pro</div>
<div><br>
</div>
</div>
<div style="padding-top: 5px; border-top-color: rgb(229, 229, 229); border-top-width: 1px; border-top-style: solid;">
<div><font face=" 'Calibri', 'Segoe UI', 'Meiryo', 'Microsoft YaHei UI', 'Microsoft JhengHei UI', 'Malgun Gothic', 'sans-serif'" style="line-height: 15pt; letter-spacing: 0.02em; font-family: "Calibri", "Segoe UI", "Meiryo", "Microsoft YaHei UI", "Microsoft JhengHei UI", "Malgun Gothic", "sans-serif"; font-size: 12pt;"><b>From:</b> <a href="mailto:smita.sree2007@gmail.com" target="_parent">smita.sree2007@gmail.com</a><br>
<b>Sent:</b> ‎Sunday‎, ‎February‎ ‎23‎, ‎2014 ‎9‎:‎24‎ ‎PM<br>
<b>To:</b> <a href="mailto:dev@shibboleth.net" target="_parent">Shib Dev</a></font></div>
</div>
<div><br>
</div>
<div dir="">
<div id="readingPaneBodyContent">We use Java 1.6.0_45. <br>
<br>
Williams,<br>
<br>
We already have JCE files.<br>
<br>
Thanks<br>
Smitha<br>
<br>
<br>
<br>
--<br>
View this message in context: http://shibboleth.1660669.n2.nabble.com/ADFS-Opensaml2-Integration-Signature-did-not-validate-against-the-credential-s-key-tp7595247p7595653.html<br>
Sent from the Shibboleth - Developers mailing list archive at Nabble.com.<br>
--<br>
To unsubscribe from this list send an email to dev-unsubscribe@shibboleth.net<br>
</div>
</div>
</div>
</body>
</html>