Shibboleth Idp 2.4.0 - Having issues changing Metadata

Kevin Foote kpfoote at uoregon.edu
Tue Jul 8 16:28:30 EDT 2014



On Jul 8, 2014, at 12:05 PM, Ben Branch <BBranch at uco.edu> wrote:
>  
> openssl req -config idp-cert.cnf -new -x509 -keyout idp.new.key -out idp.new.crt 2> /dev/null
>  
> After creating the new crt and key files, I copied them into the /opt/shibboleth-idp/credentials directory and renamed them to the right names and double checked ownership of the files.   After renaming them, I did a “cat idp.crt” to get the X509 key and put that into my /opt/shibboleth-idp/metadata/idp-metadata.xml.  I then uploaded my metadata totestshib.org to test and see if my new certs are working and now I am getting the following error messages in their log:
>  
> 2014-07-08 14:29:42 ERROR OpenSAML.SecurityPolicyRule.XMLSigning [245]: unable to verify message signature with supplied trust engine
> 2014-07-08 14:29:42 WARN Shibboleth.SSO.SAML2 [245]: detected a problem with assertion: Message was signed, but signature could not be verified.

Ben,

You probably have multiple md files on testshib right now with the same entityID.. 
This can be fixed .. working on it


--------
thanks
 kevin.foote



More information about the users mailing list