Yet another Idp error after SP upgrade

Cantor, Scott cantor.2 at osu.edu
Mon Aug 12 14:26:42 EDT 2013


On 8/12/13 2:14 PM, "Mike Flynn" <shibbolethlynda at yahoo.com> wrote:

>Well, you folks are saying that I changed an entityID etc to cause this
>error - but like I said - I copied etc verbatim.  No change....  Only
>certain IDps are failing (and still
> failing now).

Then it couldn't have worked before, at least based on the errors claimed.
If it was a case of some kind of TLS stack issue, then sure, I could
imagine an upgrade causing something, but not audience errors or signed
redirect failures, or decryption failures.

>In the logs I am getting things like this:
>
>
>2013-08-12 08:46:44 ERROR OpenSAML.SOAPClient [7]: SOAP client detected a
>SAML error: (saml1p:Responder) (Message did not meet security
>requirements)
>2013-08-12 08:46:44 ERROR Shibboleth.AttributeResolver.Query [7]:
>attribute authority returned a SAML error

Also a sign the entityID or key changed, generally the latter.

You've already said at an earlier point in this thread that you had
multiple keys and removed one. I can't say when you did it, but it seems
like that's clearly the issue. I think you had both keys active,
apparently being used in special circumstances, and then you dropped one
and had IdPs stuck on old metadata (possibly due to their own malfeasance
in keeping metadata updated) and now it fails because you switched off the
old key.

That is the most straightforward change that explains most of this
behavior.

-- Scott




More information about the users mailing list