configuring metadata for Net+ Box SP

Douglas E. Engert deengert at anl.gov
Mon Jul 8 14:51:55 EDT 2013


Backing up a little,
I did find a note from box on 2/25/2013 that said:

> Do another quick test.  I changed a couple of config items, specifically around encryption.

So box did make some changes on their side to allow us to use the certificate in their metadata
to encrypt. So Box can accept encrypted assertion, its just not an option that they document.


On 7/8/2013 10:36 AM, Rob Gorrell wrote:
>
>     In that event, the metadata needs to contain a key. I just checked mine, and the copy I have from Box does contain one.
>
>
> I'm using the latest incarnation of their metadata, hosted at their URL: https://app.box.com/shared/3isa8qvvqn... looks to me like it does contain a key?
>
>     After running xmllint to make the box metadata easier to read,
>     we made one change, so their certificate could be used for encryption:
>
>
> So your change was the deletion of the 'use="signing"' part in the md:KeyDescriptor tag? I made this change as well, reloaded the metadata and now the error (returned by them) has changed to:
>
> Unexpected exception occurred in Response Handling: No decryption key to decrypt the assertion.
>
> -Rob
>
> --
> Robert W. Gorrell
> Middleware Engineer, Identity and Access Management
> University of NC at Greensboro
> 336-334-5954
>
>
>
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>

-- 

  Douglas E. Engert  <DEEngert at anl.gov>
  Argonne National Laboratory
  9700 South Cass Avenue
  Argonne, Illinois  60439
  (630) 252-5444


More information about the users mailing list