Unable to encrypt assertion - saml tracer
Vignesh, Vanna G.
vignesh at musc.edu
Thu Jan 16 14:56:25 EST 2014
I added a new SP. Authentication succeeds but the error on SP's side says "Neither the message nor the assertion was signed by the identity provider". In the SAML tracer, I can see
<saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Responder" />
<saml2p:StatusMessage>Unable to encrypt assertion</saml2p:StatusMessage>
The default-relyingparty has signAssertions=never for saml1 and signAssertions=always for saml2.
a)Should I change never to always for saml1 in default relying party?
b)Should I create a new separate relying party for this SP?
c)Also, please note the nameidformat for this SP in the IDP metadata has " <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</md:NameIDFormat>. I a m not sure if this matters.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140116/f45362bf/attachment.html
More information about the users
mailing list