Unable to encrypt assertion - saml tracer

Vignesh, Vanna G. vignesh at musc.edu
Fri Jan 17 14:59:33 EST 2014


Thanks. I added a new relying party. It got auto-refreshed. I didn't do any restart. The new SP link worked fine but all other SP 's got broke. I got this error -'Could not resolve a key encryption credential for peer entity - opensaml fatal exception' and I had to revert the changes. What went wrong?


From: Vignesh, Vanna G.
Sent: Friday, January 17, 2014 9:37 AM
To: users at shibboleth.net
Subject: RE: Unable to encrypt assertion - saml tracer

This is the error in the idp.process log. " Could not resolve a key encryption credential for peer entity: https://xyz.SP.com"; " Unable to construct encrypter - Could not resolve key encryption credential"
The SP doesn't have any certificate in the metadata. But by default, IDP is signing all the assertions in the relying party. Is that the problem?

From: Vignesh, Vanna G.
Sent: Thursday, January 16, 2014 2:56 PM
To: users at shibboleth.net<mailto:users at shibboleth.net>
Subject: Unable to encrypt assertion - saml tracer


I added a new SP. Authentication succeeds but the error on SP's side says "Neither the message nor the assertion was signed by the identity provider". In the SAML tracer, I can see

<saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Responder" />
<saml2p:StatusMessage>Unable to encrypt assertion</saml2p:StatusMessage>

The default-relyingparty has signAssertions=never for saml1 and signAssertions=always for saml2.
a)Should I change never to always for saml1 in default relying party?
b)Should I create a new separate relying party for this SP?
c)Also, please note the nameidformat for this SP in the IDP metadata has "    <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</md:NameIDFormat>. I a m not sure if this matters.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140117/8e50f7bf/attachment.html 


More information about the users mailing list