shibboleth-sp "message not signed" issue.

Cantor, Scott cantor.2 at osu.edu
Fri Sep 28 15:51:16 EDT 2012


On 9/28/12 3:34 PM, "Erica Johansson" <ericalj at gmail.com> wrote:
>
>I'm unfortunately learning SSO as I go, so, I'm sorry if this seems like
>an obvious/simple issue. I am leaning towards an issue with the metadata,
>but I'm not certain how to check that further or resolve it if it is.

It depends what trust model you're trying to use. If you want to use what
we recommend, then you need to correct the IdP's metadata to contain the
proper certificate. If you want to use PXIX, then you'll have to add
extensions to the metadata to carry the appropriate trust anchor and add a
KeyName with the appropriate value.

Both trust engines are documented in the wiki in terms of what has to
appear in the metadata to work.

>I've verified the sp-cert referenced in shibboleth2.xml is still valid
>and hasn't been touched. I've verified on the ADFS portion that the
>relying data matches the sp-cert as well.

The SP's certificate isn't the point here. You're decrypting fine, so that
part is already correct.

-- Scott




More information about the users mailing list