Signature trust could not be established via PKIX validation of signing credential
Cantor, Scott
cantor.2 at osu.edu
Wed Jul 10 19:30:15 EDT 2013
On 7/10/13 6:38 PM, "Schumacher, Adam J." <adamschumacher at creighton.edu>
wrote:
>I have verified that the certificate supplied in the request matches the
>certificate supplied in the SP metadata (copied both to a file and ran
>diff).
I don't think that could be the case unless you've disabled the trust
engine at the IdP that supports the direct key evaluation. It's falling
into PKIX which means it either didn't try the other, or it didn't work.
The content of the certificate aside from the key is totally irrelevant
unless the key doesn't match the metadata or it isn't checking that case.
-- Scott
More information about the users
mailing list