[solved]: Wrong KeyInfo in ArtifactResponse from IdP causing SSO to fail

Cantor, Scott cantor.2 at osu.edu
Thu May 23 15:54:32 EDT 2013


On 5/23/13 1:14 PM, "Farrukh Najmi" <farrukh at wellfleetsoftware.com> wrote:

>This is to confirm that you were spot-on as usual in your helpful
>response. The problem ended being my incorrectly specifying the KeyInfo
>for jetty's SSL connector (used for transport layer encryption) in
>Jetty's keystore in the IdP metadata. I should have
> specified KeyInfo for Shib IdP's key in Shib IdP's keystore instead.
>Once I fixed this all is back to being well.

Oh, well, that's a different issue than I was talking about, but it would
be more likely to look like a signature error I suppose. I'm not really
sure your settings make sense here. An artifact exchange really doesn't
generally involve signing on either side. It's faster to do mutual TLS.
You don't normally need to encrypt or sign anything on the IdP when
artifacts are used.

>As a newbie to Shib, I am very impressed with the project, dev team and
>community.

I'm glad you're finding it so.

-- Scott





More information about the users mailing list