Decoding encrypted attributes from an IDP
Cantor, Scott
cantor.2 at osu.edu
Mon Jul 23 16:30:16 EDT 2012
On 7/23/12 4:14 PM, "Rob Whitener" <rob.whitener at audaxhealth.com> wrote:
>
>At Scott Cantor's suggestion, I asked our partner to encrypt the whole
>assertion, rather than just the attributes (they took it upon themselves
>to have the attributes remain encrypted as well, inside the already
>encrypted assertion? Seems like too much encryption
> to me).
It also won't fix your issue, although...
>Now, we are seeing errors like this in Syslog:
>
>Jul 23 19:18:21 ip-10-90-230-192 shibboleth-sp: 1343071101 ERROR
>Shibboleth.Listener [24585] shib_check_user: remoted message returned an
>error: A valid authentication statement was not found in the incoming
>message.
That means you can't decrypt with the key they used, as Nate said, and
that should also be happening in the original case of the
EncryptedAttribute (not in syslog, it will just be a warning in shibd.log).
-- Scott
More information about the users
mailing list