Some problems about the certificate

Hao Liu Hao.Liu at astro.cf.ac.uk
Tue Apr 24 11:26:26 BST 2012


One possible problem is that you are using http while sp is expecting https.

On 24 Apr 2012, at 10:15, 杨如鹏 wrote:

> Hello, everyone. I am really new to shibboleth, and now I am trying to configure a simple test system for  shibboleth idp and sp. But there are some problems when the sp tries to get attribute from the idp. The related logs are here. The key in metadata to sp is the same as the content of idp.crt in idp. I do not how it comes. Can you help me? I will really appreciate of your help. 
> Best wishes
> 
> 2012-04-24 16:35:26 INFO Shibboleth.Application : building AttributeFilter of type XML...
> 2012-04-24 16:35:26 INFO Shibboleth.AttributeFilter : reload thread started...running when signaled
> 2012-04-24 16:35:26 INFO Shibboleth.AttributeFilter : loaded XML resource (/home/orbbyrp/shibboleth-sp/etc/shibboleth/attribute-policy.xml)
> 2012-04-24 16:35:26 INFO Shibboleth.Application : building AttributeResolver of type Query...
> 2012-04-24 16:35:26 INFO Shibboleth.Application : building CredentialResolver of type File...
> 2012-04-24 16:35:26 INFO XMLTooling.SecurityHelper : loading private key from file (/home/orbbyrp/shibboleth-sp/etc/shibboleth/idp-key.pem)
> 2012-04-24 16:35:26 INFO XMLTooling.SecurityHelper : loading certificate(s) from file (/home/orbbyrp/shibboleth-sp/etc/shibboleth/idp-cert.pem)
> 2012-04-24 16:35:26 INFO Shibboleth.Listener : registered remoted message endpoint (default::getHeaders::Application)
> 2012-04-24 16:35:26 INFO Shibboleth.Listener : listener service starting
> 2012-04-24 16:35:38 ERROR XMLTooling.TrustEngine.PKIX [2]: certificate name was not acceptable
> 2012-04-24 16:35:38 ERROR XMLTooling.SOAPTransport.CURL [2]: supplied TrustEngine failed to validate SSL/TLS server certificate
> 2012-04-24 16:35:38 ERROR Shibboleth.AttributeResolver.Query [2]: exception during SAML query to https://example.com:8443/idp/profile/SAML2/SOAP/AttributeQuery: CURLSOAPTransport failed while contacting SOAP endpoint (https://example.com:8443/idp/profile/SAML2/SOAP/AttributeQuery): SSL certificate problem, verify that the CA cert is OK. Details:
> error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
> 2012-04-24 16:35:38 ERROR Shibboleth.AttributeResolver.Query [2]: unable to obtain a SAML response from attribute authority
> 2012-04-24 16:35:38 INFO Shibboleth.SessionCache [2]: new session created: ID (_2ae8bd4d424d19525b5edb52c78d2da5) IdP (https://example.com:8080/idp/shibboleth) Protocol(urn:oasis:names:tc:SAML:2.0:protocol) Address (127.0.0.1)
> 2012-04-24 16:50:26 INFO XMLTooling.StorageService : purged 2 expired record(s) from storage
> 
> -- 
> Rupeng Yang
> Email: orbbyrp at gmail.com
> site: orbbyrp.com
> School of Computer Science and Technology, Shandong University
> No.1500, Middle of Shunhua Road
> Jinan 250101, Shandong, P.R.China
> 
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120424/3571cc51/attachment.html 


More information about the users mailing list