unable to verify message signature with supplied trust engine

Sam Jacob skjacob at gmail.com
Fri Feb 28 12:50:14 EST 2014


we are getting this error just after the <samlp:Response>

" unable to verify message signature with supplied trust engine"
-----------------------------------------------------------------------
2014-02-28 10:31:46 DEBUG OpenSAML.MessageDecoder.SAML2POST [24]:
validating input
2014-02-28 10:31:46 DEBUG OpenSAML.MessageDecoder.SAML2POST [24]: decoded
SAML message:
<?xml version="1.0" encoding="utf-8"?><samlp:Response
ID="_23f4eded-0651-497c-bd7c-4d8e454b218b"
IssueInstant="2014-02-28T16:31:32Z" Version="2.0"
xmlns="urn:oasis:names:tc:SAML:2.0:assertion"
xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
..................details removed
</samlp:Response>
2014-02-28 10:31:46 DEBUG OpenSAML.MessageDecoder.SAML2 [24]: extracting
issuer from SAML 2.0 protocol message
2014-02-28 10:31:46 DEBUG OpenSAML.MessageDecoder.SAML2 [24]: message from
(icon)
2014-02-28 10:31:46 DEBUG OpenSAML.MessageDecoder.SAML2 [24]: searching
metadata for message issuer...
2014-02-28 10:31:46 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [24]:
evaluating message flow policy (replay checking on, expiration 60)
2014-02-28 10:31:46 DEBUG XMLTooling.StorageService [24]: inserted record
(_23f4eded-0651-497c-bd7c-4d8e454b218b) in context (MessageFlow) with
expiration (1393606952)
2014-02-28 10:31:46 DEBUG Shibboleth.SSO.SAML2 [24]: processing message
against SAML 2.0 SSO profile
2014-02-28 10:31:46 DEBUG Shibboleth.SSO.SAML2 [24]: extracting issuer from
SAML 2.0 assertion
2014-02-28 10:31:46 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [24]:
evaluating message flow policy (replay checking on, expiration 60)
2014-02-28 10:31:46 DEBUG XMLTooling.StorageService [24]: inserted record
(_12dc4b22-7d5c-4a11-b837-16d58f33e7f1) in context (MessageFlow) with
expiration (1393606952)
2014-02-28 10:31:46 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [24]:
validating signature profile
2014-02-28 10:31:46 DEBUG XMLTooling.TrustEngine.ExplicitKey [24]: unable
to validate signature, no credentials available from peer
2014-02-28 10:31:46 ERROR OpenSAML.SecurityPolicyRule.XMLSigning [24]:
unable to verify message signature with supplied trust engine
2014-02-28 10:31:46 WARN Shibboleth.SSO.SAML2 [24]: detected a problem with
assertion: Message was signed, but signature could not be verified.
2014-02-28 10:34:31 INFO Shibboleth.Listener [15]: detected socket closure,
shutting down worker thread
-- 
------------------------------------------------------------------------------------------------------


Any help appreciated
thanks
Sam Jacob
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140228/98521d17/attachment.html 


More information about the users mailing list