Failure to validate Response Signature
Rainer Hoerbe
rainer at hoerbe.at
Thu Oct 4 13:31:30 EDT 2012
How do I have to interpret "Credential did not contain a verification key"? X509v3 Key Usage is "Digital Signature, non-repudiation".
DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [1]: validating signature profile
DEBUG XMLTooling.TrustEngine.ExplicitKey [1]: attempting to validate signature with the peer's credentials
DEBUG XMLTooling.TrustEngine.ExplicitKey [1]: public key did not validate signature: Credential did not contain a verification key.
DEBUG XMLTooling.TrustEngine.ExplicitKey [1]: no peer credentials validated the signature
- Rainer
Am 04.10.2012 um 18:35 schrieb Peter Schober <peter.schober at univie.ac.at>:
> * Rainer Hoerbe <rainer at hoerbe.at> [2012-10-04 18:07]:
>> Peter suggested to make an explicit configuration of the explicit
>> trust engine to produce more messages.
>
> Not more messages, only to spare you the false negatives of the PKIX
> trust engine (i.e., let it fail only trying explicit trust).
>
>> BTW, the wiki explains elements and attributes, but does not provide
>> an example.
>
> It's now all defaulted. See example-shibboleth2.xml from the
> distribution for examples. But it's probably not worth it as the logs
> from the explicit trust failing would be there either way (only the
> other's wouldn't),
> -peter
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list