security error when testing Shibboleth IDP
Kaustubh Nagraj
kaustubh at easydita.com
Wed Oct 26 17:04:10 BST 2011
Hi,
I reinstalled everything and tried testing with the testshib service again.
This time I encountered the error:
ERROR:
opensaml: SecurityPolicyException
opensaml::SecurityPolicyException at (
https://sp.testshib.org/Shibboleth.sso/SAML2/POST)
Message was signed, but signature could not be verified.
LOG FILE:
No user identified by login handler.
I think the problem lies with the security certificates. I am not sure if it
lies with the certificates which IDP generates while installing or is it a
problem with my web servers' certificates. Or maybe I have got it all wrong
and the problem lies somewhere else. Could someone point me in the right
direction as to where I am going wrong?
Thanks,
Kaustubh
On Tue, Oct 25, 2011 at 2:24 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 10/25/11 2:16 PM, "Kaustubh Nagraj" <kaustubh at easydita.com> wrote:
> >
> >proxy: No protocol handler was valid for the URL /idp/status. If you are
> >using a DSO version of mod_proxy, make sure the proxy submodules are
> >included in the configuration using LoadModule.
>
> I would imagine you broke the ProxyPass commands. All of that is
> documented under Tomcat prep in the wiki, and if that doesn't help you,
> they have mailing lists.
>
> >I understand that IDP does not have a problem here, the problem is with
> >my web servers.
>
> Which is why you'd best go get that working first. Or just drop Apache.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20111026/0e9eb63a/attachment.html
More information about the users
mailing list