Service provider unable to load private key from file
Douglas E. Engert
deengert at anl.gov
Mon Sep 16 13:53:46 EDT 2013
On 9/16/2013 12:15 PM, Brian Reindel wrote:
> -rw-r--r--. 1 root root 1062 Sep 16 11:20 sp-cert.pem
> -rw-------. 1 shibd shibd 1704 Sep 16 11:20 sp-key.pem
PEM file are text. If it is encrypted, it will have some lines like:
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-256-CBC,E540B27179249688B5C4C9C0E75E157D
Use OpenSSL to verify the key is valid and encrypted:
openssl rsa -text -in sp-key.pem
This will also output the unencrypted key in PEM format too.
> That gives me the same error. While this:
>
> -rw-r--r--. 1 root root 1062 Sep 16 11:20 sp-cert.pem
> -rw-r--r--. 1 shibd shibd 1704 Sep 16 11:20 sp-key.pem
>
> Gives "Segmentation fault (core dumped)" and the service fails to
> start. I'm not sure why giving more permissions would return a worse
> result, but that is what is happening. One the owner has read on the
> key it fails with that.
>
>
> On Mon, Sep 16, 2013 at 12:47 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>> On 9/16/13 12:12 PM, "Brian Reindel" <brian at reindel.com> wrote:
>>>
>>> The permissions are as follows:
>>>
>>> -rw-r--r--. 1 root root 1062 Sep 16 11:20 sp-cert.pem
>>> -rw-------. 1 root root 1704 Sep 16 11:20 sp-key.pem
>>
>> Those are invalid, the key has to be owned by shibd. They will be when
>> installed in the normal way.
>>
>> -- Scott
>>
>>
>> --
>> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
--
Douglas E. Engert <DEEngert at anl.gov>
Argonne National Laboratory
9700 South Cass Avenue
Argonne, Illinois 60439
(630) 252-5444
More information about the users
mailing list