configuring metadata for Net+ Box SP
Douglas E. Engert
deengert at anl.gov
Mon Jul 8 12:13:48 EDT 2013
On 7/8/2013 10:36 AM, Rob Gorrell wrote:
>
> In that event, the metadata needs to contain a key. I just checked mine, and the copy I have from Box does contain one.
>
>
> I'm using the latest incarnation of their metadata, hosted at their URL: https://app.box.com/shared/3isa8qvvqn... looks to me like it does contain a key?
>
> After running xmllint to make the box metadata easier to read,
> we made one change, so their certificate could be used for encryption:
>
>
> So your change was the deletion of the 'use="signing"' part in the md:KeyDescriptor tag? I made this change as well, reloaded the metadata and now the error (returned by them) has changed to:
>
Yes.
I also down loaded their metadata from https://app.box.com/shared/3isa8qvvqn and this is the same
metadata we are using, (but we removed the use="signing")
> Unexpected exception occurred in Response Handling: No decryption key to decrypt the assertion.
We set this up in February, and my notes have us sending encrypted assertions
at that time from the 2.3.8 IDP.
Tried to today using Firefox with SAML tracer, and it is sending an encrypted
assertion, and login works.
The assertion is sent to https://sso.services.box.net/sp/ACS.saml2
My notes don't show if box had to turn on accepting encryption at their end
for our site. We did have a number of phone meetings and this may have come up
and they made a change.
I can send you our contact name at Box via private e-mail if that would help.
>
> -Rob
>
> --
> Robert W. Gorrell
> Middleware Engineer, Identity and Access Management
> University of NC at Greensboro
> 336-334-5954
>
>
>
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
--
Douglas E. Engert <DEEngert at anl.gov>
Argonne National Laboratory
9700 South Cass Avenue
Argonne, Illinois 60439
(630) 252-5444
More information about the users
mailing list