SP randomly failed to validate certificate IDP certicate.
DE VEGA BARREIRO, Manuel (Manuel)
manuel.devega at alcatel-lucent.com
Tue Jun 26 15:35:54 BST 2012
Hi,
I use this systems in a Shibooleth environment:
Shibooleth IDP 1.3 running in Solaris 10 server
Shibooleth SP running in apache and RH 5.3 Linux
Authentication and profile exchange between IDP and SP works fine, but time to time SP client refuse to accept IDP certificate:
2012-06-26 12:29:49 DEBUG XMLTooling.SOAPTransport.CURL [91]: sending SOAP message to https://10.122.4.76:7122/coi-idp/AA
2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: About to connect() to 10.122.4.76 port 7122
2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: Trying 10.122.4.76...
2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: connected
2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: Connected to 10.122.4.76 (10.122.4.76) port 7122
2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: successfully set certificate verify locations:
2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: CAfile: /etc/pki/tls/certs/ca-bundle.crt CApath: none
2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: SSL re-using session ID
2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: SSLv3, TLS handshake, Client hello (1):
2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: SSLv3, TLS handshake, Server hello (2):
2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: SSLv3, TLS handshake, CERT (11):
2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]:
2012-06-26 12:29:49 DEBUG XMLTooling.SOAPTransport.CURL [91]: invoking custom X.509 verify callback
2012-06-26 12:29:49 DEBUG XMLTooling.TrustEngine.ExplicitKey [91]: attempting to match credentials from peer with end-entity certificate
2012-06-26 12:29:49 DEBUG XMLTooling.TrustEngine.ExplicitKey [91]: no keys within this peer's key information matched the given end-entity certificate
2012-06-26 12:29:49 DEBUG XMLTooling.TrustEngine.PKIX [91]: performing certificate path validation...
2012-06-26 12:29:49 DEBUG XMLTooling.TrustEngine.PKIX [91]: failed to validate certificate chain using supplied PKIX information
2012-06-26 12:29:49 ERROR XMLTooling.SOAPTransport.CURL [91]: supplied TrustEngine failed to validate SSL/TLS server certificate
2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: SSLv3, TLS alert, Server hello (2):
I'm sure that certificate are ok, because most of the time SP accept it without any complains:
2012-06-26 12:13:28 DEBUG XMLTooling.SOAPTransport.CURL [86]: sending SOAP message to https://10.122.4.76:7122/coi-idp/AA
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: Connection 0 seems to be dead!
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: Closing connection #0
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: About to connect() to 10.122.4.76 port 7122
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: Trying 10.122.4.76...
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: connected
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: Connected to 10.122.4.76 (10.122.4.76) port 7122
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: successfully set certificate verify locations:
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: CAfile: /etc/pki/tls/certs/ca-bundle.crt CApath: none
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSL re-using session ID
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS handshake, Client hello (1):
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS handshake, Server hello (2):
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS handshake, CERT (11):
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]:
2012-06-26 12:13:28 DEBUG XMLTooling.SOAPTransport.CURL [86]: invoking custom X.509 verify callback
2012-06-26 12:13:28 DEBUG XMLTooling.TrustEngine.ExplicitKey [86]: attempting to match credentials from peer with end-entity certificate
2012-06-26 12:13:28 DEBUG XMLTooling.TrustEngine.ExplicitKey [86]: end-entity certificate matches peer RSA key information
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS handshake, Server key exchange (12):
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: 2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS handshake, Server finished (14):
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS handshake, Client key exchange (16):
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS change cipher, Client hello (1):
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS handshake, Finished (20):
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS change cipher, Client hello (1):
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS handshake, Finished (20):
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSL connection using DHE-RSA-AES256-SHA
2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: Server certificate:
Both server use NTP server to avoid time differences between servers.
Any idea about why SP randomly refuse to validate IDP certificate?
Regards.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120626/4894d407/attachment.html
More information about the users
mailing list