Initial Setup -- Cannot Get SP and IDP Talking
Paul Hethmon
paul.hethmon at clareitysecurity.com
Wed Nov 20 08:45:31 EST 2013
Verify you've given Shib SP the correct metadata. That's either the public key is wrong or there's a time skew between the IdP and SP servers. The incoming SAML Response will have the public key embedded in it so you can compare it to what SP is loading.
Paul
From: Sam Agnew <saa2012 at qatar-med.cornell.edu<mailto:saa2012 at qatar-med.cornell.edu>>
Reply-To: Shibboleth Users <users at shibboleth.net<mailto:users at shibboleth.net>>
Date: Wednesday, November 20, 2013 3:55 AM
To: Shibboleth Users <users at shibboleth.net<mailto:users at shibboleth.net>>
Subject: Re: Initial Setup -- Cannot Get SP and IDP Talking
What I am now getting after successful login on the loginpage (UserPassword auth via LDAP) is the following from the SP:
opensaml::FatalProfileException at (https://unixadmin.qatar-med.cornell.edu/Shibboleth.sso/SAML2/POST)
Unable to establish security of incoming assertion.
The shibd.log says:
2013-11-20 11:45:18 WARN Shibboleth.SSO.SAML2 [3]: detected a problem with assertion: Unable to establish security of incoming assertion.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131120/6e9cc368/attachment.html
More information about the users
mailing list