Failure to validate Response Signature
Cantor, Scott
cantor.2 at osu.edu
Thu Oct 4 12:25:44 EDT 2012
On 10/4/12 12:06 PM, "Rainer Hoerbe" <rainer at hoerbe.at> wrote:
>I agree. But how can that happen if the issuer matches the entityID in
>metadata and there is no difference in the certificates in response and
>metadata?
Usually there's a missing sanity check. Something you think is being used
re: metadata turns out not to be the case.
>Peter suggested to make an explicit configuration of the explicit trust
>engine to produce more messages. BTW, the wiki explains elements and
>attributes, but does not provide an example.
There's nothing much to do, it's just logging. If you change root category
to DEBUG, you'll get anything the trust engine will give you.
If you have tons of noise, you turned up some unneeded categories that are
set to INFO down below to avoid you getting swamped. Possibly that drowned
out something useful.
-- Scott
More information about the users
mailing list