Validation of request simple signature failed for context issuer

Joel Leibovitz joelleobovitz at gmail.com
Fri Jul 10 20:05:33 EDT 2015


I have been working on this for past few hours - wondering if anyone has
tips on what I could have missed.

SP: Latest Shibboleth version on Windows 2012R2 64 bit
IdP: V2.4x - has over 300 SPs integrated without any issues.

I have made doubly sure the 'sp-cert.pem' was entered correctly in the IdP
(as we had done countless of other times) - but no go.

Exract from log file:

16:26:19.039 - DEBUG
[org.opensaml.xml.security.credential.criteria.EvaluableCredentialCriteriaRegistry:75]
- Registry located evaluable criteria class org.opensam
l.xml.security.credential.criteria.EvaluableKeyAlgorithmCredentialCriteria
for criteria class org.opensaml.xml.security.criteria.KeyAlgorithmCriteria
16:26:19.040 - DEBUG
[org.opensaml.xml.security.credential.criteria.EvaluableCredentialCriteriaRegistry:75]
- Registry located evaluable criteria class org.opensam
l.xml.security.credential.criteria.EvaluableEntityIDCredentialCriteria for
criteria class org.opensaml.xml.security.criteria.EntityIDCriteria
16:26:19.040 - DEBUG
[org.opensaml.xml.security.credential.criteria.EvaluableCredentialCriteriaRegistry:106]
- Registry could not locate evaluable criteria for cri
teria class org.opensaml.security.MetadataCriteria
16:26:19.040 - DEBUG
[org.opensaml.xml.security.credential.criteria.EvaluableCredentialCriteriaRegistry:75]
- Registry located evaluable criteria class org.opensam
l.xml.security.credential.criteria.EvaluableUsageCredentialCriteria for
criteria class org.opensaml.xml.security.criteria.UsageCriteria
16:26:19.041 - DEBUG
[org.opensaml.xml.signature.impl.ExplicitKeySignatureTrustEngine:153] -
Attempting to verify signature using trusted credentials
16:26:19.041 - DEBUG [org.opensaml.xml.security.SigningUtil:238] -
Verifying signature over input using public key of type RSA and JCA
algorithm ID SHA1withRSA
16:26:19.043 - DEBUG
[org.opensaml.xml.signature.impl.ExplicitKeySignatureTrustEngine:161] -
Failed to verify signature using either supplied candidate credential
or directly trusted credentials
16:26:19.043 - DEBUG
[org.opensaml.xml.signature.impl.PKIXSignatureTrustEngine:170] - Candidate
credential was either not supplied or did not contain verification
key
16:26:19.043 - DEBUG
[org.opensaml.xml.signature.impl.PKIXSignatureTrustEngine:171] - PKIX trust
engine requires supplied key, skipping PKIX trust evaluation
16:26:19.044 - WARN
[org.opensaml.common.binding.security.BaseSAMLSimpleSignatureSecurityPolicyRule:194]
- Simple signature validation (with no request-derived cre
dentials) failed
16:26:19.044 - WARN
[org.opensaml.common.binding.security.BaseSAMLSimpleSignatureSecurityPolicyRule:137]
- Validation of request simple signature failed for contex
t issuer: https://sp.foobar.edu/shibboleth-sp



On 8 July 2015 at 17:36, Cantor, Scott <cantor.2 at osu.edu> wrote:

> On 7/8/15, 8:21 PM, "users on behalf of Joel Leibovitz" <
> users-bounces at shibboleth.net on behalf of joelleobovitz at gmail.com> wrote:
>
>
>
> >Is there to find value sent by the SP - either from logs or headers?
>
> It isn't sent. That's why use of PKIX is impossible with that binding, you
> either know the key or you don't.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150710/b557255c/attachment-0001.html>


More information about the users mailing list