Unable to establish security of incoming assertion

Cantor, Scott cantor.2 at osu.edu
Thu Jun 27 16:16:01 EDT 2013


On 6/27/13 4:11 PM, "Justin Russo" <justin9 at ymail.com> wrote:
>Initially when i set up shibboleth for the first time i test using
>University of south California idp.
>Now when im trying to connect to my IDP provider "ABC Company" i used the
>existing shibboleth2.xml file and modified it accordingly.

Don't. Use a modern 2.5 shibboleth2.xml without all that complexity in it.
Change the entityID in the <SSO> element, supply metadata, and that's it.

>do you think this is the cause

No. I think your IdP is the cause, I don't think it's configured sensibly,
unless it's Shibboleth, in which case I don't know how you got it to do
something so odd.

I told you to turn up logging, and get a dump of the SAML message, and see
if any other information surrounds the warning in the log.

https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPLogging

-- Scott




More information about the users mailing list