Shibboleth 3 SAML Response Debugging

Cantor, Scott cantor.2 at osu.edu
Wed Jul 15 16:38:44 EDT 2015


On 7/15/15, 4:28 PM, "users on behalf of McKean, Brandon Scott - mckeanbs" <users-bounces at shibboleth.net on behalf of mckeanbs at jmu.edu> wrote:

>Hmm, doing more digging I found that I hadn't commented out the encryption key/cert in credentials.xml

That file isn't used unless you're using a non-legacy relying party file, but if you are, then you need to have that credential defined.

>Is there something else that needs done for that part?

Disabling that would be a great deal of work if it's actually even possible. If you're concerned about not supporting decryption, just don't publish it in your metadata. It won't matter for anything you're testing anyway.

(None of this has anything to do with the error you posted.)

-- Scott



More information about the users mailing list