Failure to validate Response Signature
Rainer Hoerbe
rainer at hoerbe.at
Thu Oct 4 04:44:42 EDT 2012
I am using the default security policy in a SP 2.5 configuration. The IdP's metadata contains the certificate, a diff on the values of <ds:X509Certificate> in response and metadata does not show any difference. Yet the SP complains:
ERROR XMLTooling.TrustEngine.PKIX [2]: certificate name was not acceptable
ERROR OpenSAML.SecurityPolicyRule.XMLSigning [2]: unable to verify message signature with supplied trust engine
In my understanding the explicit trust engine is first, and PKIX is second. I do not understand the second error message.
- Rainer
"Give a man an answer and you help him for a day. Teach a man to search and you help him for a lifetime."
More information about the users
mailing list