Renewing Shibboleth Certificate

Wavyne Belance wbelance at luc.edu
Tue Sep 11 07:29:04 EDT 2012


Hello All
 
I am in the process of renewing the Shibboleth certificate and at the end of the process I am getting this error message when I try to connect: "Message was signed, but signature could not be verified."
The certificate is updated in my metadata and its location and  the key are in the relying-party.xml file. I also see the saml2 assertion being sent with the correct certificate when I turn debugging on. Where did I go wrong?
The certificate was also successfully loaded in tomcat. Both tomcat and the IdP start w/o issues but when I try to authenticate I get the above message. 
 
Are there step by step guides to renewing the Shibboleth certificate? 
 
TIA
Wavyne Belance

 
You can check the certificate that is being used by the IdP by looking at the certificate subelement of <security:Credential id="IdPCredential" xsi:type="security:X509Filesystem"> in relying-party.xml.  You'll need to compare that certificate to the one in the metadata file you supplied to the PingFederate SP.  You can make sure they match by updating one, the other, or both.

Let us know if we can help further,
Nate.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120911/5316654a/attachment.html 


More information about the users mailing list