decryption problem

Christopher Bongaarts cab at umn.edu
Mon Jun 18 05:48:40 BST 2012


On 6/17/2012 10:39 PM, Cantor, Scott wrote:
> On 6/17/12 11:17 PM, "Christopher Bongaarts" <cab at umn.edu> wrote:
>
>> My best guess is that the SP's cert doesn't match the private key, but
>> I've had him regenerate keys 3 times now with identical results, so I
>> thought I'd at least check before making him do it again...
>
> Well, it's the cert you're being told to use, not the one it happens to
> have installed. The other rare possibility is a glitch in the names in the
> certificates if the keys are the same but the certificates on each end are
> different.
>
> They can try adding extractNames="false" to the CredentialResolver. I
> don't think that would affect the situation with those log messages, but
> I'd like to investigate further if it does.

Just doublechecked and saw that /Shibboleth.sso/Metadata was giving a 
different cert than I had on the IdP.  Syncing those up should hopefully 
resolve things.
-- 
%%  Christopher A. Bongaarts   %%  cab at umn.edu          %%
%%  OIT - Identity Management  %%  http://umn.edu/~cab  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%




More information about the users mailing list