Failure to validate Response Signature

Rainer Hoerbe rainer at hoerbe.at
Thu Oct 4 04:44:42 EDT 2012


I am using the default security policy in a SP 2.5 configuration. The IdP's metadata contains the certificate, a diff on the values of <ds:X509Certificate> in response and metadata does not show any difference. Yet the SP complains:
ERROR XMLTooling.TrustEngine.PKIX [2]: certificate name was not acceptable
ERROR OpenSAML.SecurityPolicyRule.XMLSigning [2]: unable to verify message signature with supplied trust engine

In my understanding the explicit trust engine is first, and PKIX is second. I do not understand the second error message.

- Rainer
"Give a man an answer and you help him for a day. Teach a man to search and you help him for a lifetime."




More information about the users mailing list