configuring metadata for Net+ Box SP

Rob Gorrell rwgorrel at uncg.edu
Mon Jul 8 10:18:12 EDT 2013


So I completed setting up my IdP for the bilateral trust with Box using the
metadata file they provided "as is" and i've asked Box to enable SSO for
us, but upon initial testing, I'm now having a problem. After
authenticating at our IdP, their SP is returning the following:

Error - Single Sign-On
Nonsuccess Response status: urn:oasis:names:tc:SAML:2.0:status:Responder
Status Message: Unable to encrypt assertion
Partner: https://prdidp.uncg.edu/idp/shibboleth
Target Resource: https://uncg.box.com/sso/ping_federate

my idp-process.log shows:
09:55:13.304 - ERROR
[edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:966]
- Could not resolve a key encryption credential for peer entity: box.net
09:55:13.305 - ERROR
[edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:276]
- Unable to construct encrypter
org.opensaml.xml.security.SecurityException: Could not resolve key
encryption credential

Is this something on my end? or perhaps I didn't provide my IdP's metadata
correctly to them or something was lost in translation?
https://prdidp.uncg.edu/idp/shibboleth being displayed by them as the
"Partner" is my correct entityID.

Thanks
-Rob


-- 
Robert W. Gorrell
Middleware Engineer, Identity and Access Management
University of NC at Greensboro
336-334-5954
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130708/d1720d13/attachment.html 


More information about the users mailing list