Initial Setup -- Cannot Get SP and IDP Talking

Paul Hethmon paul.hethmon at clareitysecurity.com
Wed Nov 20 08:45:31 EST 2013


Verify you've given Shib SP the correct metadata. That's either the public key is wrong or there's a time skew between the IdP and SP servers. The incoming SAML Response will have the public key embedded in it so you can compare it to what SP is loading.

Paul

From: Sam Agnew <saa2012 at qatar-med.cornell.edu<mailto:saa2012 at qatar-med.cornell.edu>>
Reply-To: Shibboleth Users <users at shibboleth.net<mailto:users at shibboleth.net>>
Date: Wednesday, November 20, 2013 3:55 AM
To: Shibboleth Users <users at shibboleth.net<mailto:users at shibboleth.net>>
Subject: Re: Initial Setup -- Cannot Get SP and IDP Talking

What I am now getting after successful login on the loginpage (UserPassword auth via LDAP) is the following from the SP:

opensaml::FatalProfileException at (https://unixadmin.qatar-med.cornell.edu/Shibboleth.sso/SAML2/POST)

Unable to establish security of incoming assertion.

The shibd.log says:
2013-11-20 11:45:18 WARN Shibboleth.SSO.SAML2 [3]: detected a problem with assertion: Unable to establish security of incoming assertion.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131120/6e9cc368/attachment.html 


More information about the users mailing list