decryption problem
Christopher Bongaarts
cab at umn.edu
Mon Jun 18 05:48:40 BST 2012
On 6/17/2012 10:39 PM, Cantor, Scott wrote:
> On 6/17/12 11:17 PM, "Christopher Bongaarts" <cab at umn.edu> wrote:
>
>> My best guess is that the SP's cert doesn't match the private key, but
>> I've had him regenerate keys 3 times now with identical results, so I
>> thought I'd at least check before making him do it again...
>
> Well, it's the cert you're being told to use, not the one it happens to
> have installed. The other rare possibility is a glitch in the names in the
> certificates if the keys are the same but the certificates on each end are
> different.
>
> They can try adding extractNames="false" to the CredentialResolver. I
> don't think that would affect the situation with those log messages, but
> I'd like to investigate further if it does.
Just doublechecked and saw that /Shibboleth.sso/Metadata was giving a
different cert than I had on the IdP. Syncing those up should hopefully
resolve things.
--
%% Christopher A. Bongaarts %% cab at umn.edu %%
%% OIT - Identity Management %% http://umn.edu/~cab %%
%% University of Minnesota %% +1 (612) 625-1809 %%
More information about the users
mailing list