Yet another Idp error after SP upgrade
Mike Flynn
shibbolethlynda at yahoo.com
Mon Aug 12 09:01:44 EDT 2013
OK, I restored my old cfg onto the new servers. I still got 1 customer reporting an error since yesterday:
opensaml::FatalProfileException at (https://shib.lynda.com/Shibboleth.sso/SAML2/POST)
SAML response contained an error.
Error from identity provider:
Status: urn:oasis:names:tc:SAML:2.0:status:Requester
>Message: Invalid signature
>
Running shibd -check just has the deprecated settings warnings for my old config but no other errors.
________________________________
From: "Cantor, Scott" <cantor.2 at osu.edu>
To: Shib Users <users at shibboleth.net>
Sent: Sunday, August 11, 2013 4:43 PM
Subject: Re: Yet another Idp error after SP upgrade
On 8/11/13 7:40 PM, "Mike Flynn" <shibbolethlynda at yahoo.com> wrote:
>OK. I copyied the config and it's associated files from the old server
>to the new. I made changes to my old config file that were recommended
>by the Wiki (where appropriate) for the current version. I got rid of
>some unused session initiators.
None of that would cause anything you've described.
> Is my old config for the previous version still backwards compatible
>with the current version?
Yes.
>Would you recommend that I use that config as is until I can isolate what
>is causing these issues?
Probably so, yes. But what you did was change keys, changed an entityID,
that kind of thing. That's what causes such errors. If you don't undo
that, it's not going to fix anything.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130812/e7f80917/attachment.html
More information about the users
mailing list