Spring SAML SP Can't Recognize IdP Certificate (Signature Validation Failed)

Cantor, Scott cantor.2 at osu.edu
Fri Feb 14 13:42:05 EST 2014


On 2/14/14, 12:51 PM, "nduan at dtechspace.com" <nduan at dtechspace.com> wrote:

>If I am not mistaking, the authentication assertion in Authn response
>message shall be signed by the IdP using its private key, and the SP
>would use IdP's public key, which is available in the IdP's metadata
>accessible by the SP, to verify the signature.

That's correct.

>Am I missing some 
>configuration parameters in either SP or IdP to enable SP to pick the
>right public key?

The IdP has nothing much to do with how an SP chooses to find keys. It
does include a KeyInfo hint and there can be obscure cases where that
causes problems, but it certainly has nothing to do with this.

-- Scott




More information about the users mailing list