New IdP Install & Certificate Error

Brian Chongtai Brian.Chongtai at nsc.edu
Wed Dec 31 17:17:56 EST 2014


Hello,
                This is my first time setting up Shibboleth and I'm running into an error when attempting to test authentication on testshib.  To provide some background, I'm running Shibboleth IdP 2.4.3 linked to Active Directory.  I'm also using the self-signed SSL certificate that was generated during the installation but have created a separate keystore for Tomcat to eliminate certificate errors on the login page.

On testshib, I'm able to plug in our URL and get to the login page but when entering valid login credentials am presented with an "opensaml::FatalProfileException at (https://sp.testshib.org/Shibboleth.sso/SAML2/POST)" error.  If I enter invalid login credentials, however, I do get a 'Login has failed' message which seems to indicate that Shibboleth is communicating successfully with our AD.  Below are the last few lines of the shibd.log.  If anyone has any suggestions or pointers on where to look next it would be greatly appreciated.

2014-12-31 16:51:15 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [5]: validating signature profile
2014-12-31 16:51:15 DEBUG XMLTooling.CredentialCriteria [5]: keys didn't match
2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.ExplicitKey [5]: unable to validate signature, no credentials available from peer
2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: validating signature using certificate from within the signature
2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: signature verified with key inside signature, attempting certificate validation...
2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: checking that the certificate name is acceptable
2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: adding to list of trusted names (https://shibboleth.nsc.edu/idp/shibboleth)
2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: certificate subject: CN=shibboleth.nsc.edu
2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: unable to match DN, trying TLS subjectAltName match
2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: matched DNS/URI subjectAltName to a key name (https://shibboleth.nsc.edu/idp/shibboleth)
2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: performing certificate path validation...
2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: failed to validate certificate chain using supplied PKIX information
2014-12-31 16:51:15 ERROR OpenSAML.SecurityPolicyRule.XMLSigning [5]: unable to verify message signature with supplied trust engine
2014-12-31 16:51:15 WARN Shibboleth.SSO.SAML2 [5]: detected a problem with assertion: Message was signed, but signature could not be verified.

Thanks,
Brian
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141231/70bc3a4d/attachment.html 


More information about the users mailing list