Message was signed, but signature could not be verified.

Cantor, Scott cantor.2 at osu.edu
Wed Aug 13 20:08:31 EDT 2014


On 8/13/14, 8:02 PM, "Farzan Qureshi" <fqureshi at rosmini.school.nz> wrote:

>Thank you for the explanation and I agree with you. This is it. It must
>be overlapping SP metadata due to the entityID. I will try to separate
>the services.

You seem to have managed to get them running isolated on one server, so
you can split the names up and try that before spending time on separate
machines, but you do not run SPs on IdP machines unless they have some
reason to be that way.

>Just a quick question. Do you have any idea or know someone who has
>integrated office 365 with Shibboleth. Is there really a need to
>configure SP?

It has nothing to do with "need".

Running an IdP in production requires understanding how it works and
having the ability to test and make changes, and that requires running and
understanding SAML SPs. Period. If you skip that step, you'll be one of
the many sites whose IdP constantly fails every time you change something.
You can't manage a SSO system without understanding both halves.

-- Scott



More information about the users mailing list