Unable to establish security of incoming assertion

Cantor, Scott cantor.2 at osu.edu
Wed Feb 19 11:48:19 EST 2014


On 2/19/14, 11:41 AM, "Dewberry, James" <JDewberry at nfp.com> wrote:
>
>They are not an established Idp. They say they are using SSO with a
>different SP, but I had to correct several problems in their assertion to
>get it to unmarshall: using ※IssueInstant" instead of ※AuthnInstant§, etc.
>I would not be surprised if the problem is with their metadata/key, I just
>have to prove it to them. So thanks for all your suggested next steps.

I would say based on that that it's very likely their signature is just
broken. If the SP they are claiming works is not a legitimate
implementation, then chances are it's a broken one that isn't even
checking signatures properly.

-- Scott




More information about the users mailing list