Shibboleth 3 SAML Response Debugging
Cantor, Scott
cantor.2 at osu.edu
Thu Jul 16 11:30:09 EDT 2015
On 7/16/15, 11:21 AM, "users on behalf of McKean, Brandon Scott - mckeanbs" <users-bounces at shibboleth.net on behalf of mckeanbs at jmu.edu> wrote:
>Hmm, I think I might have more information now, from testshib's log.
The signature was fine, but the encryption was performed under the wrong key. In this case, you would have to have the wrong metadata for testshib, I guess.
That assumes testshib actually reported a failure. Nothing in that log was a definitive end result of anything.
>This would reinforce what you said before about it being a credential issue, but I'm not sure where that would be breaking down. The openssl commands I did before verified idp-signing.key and idp-signing.crt matched, and they are set as such in idp.properties.
It evaluated your key just fine.
I am at this point lost as to who's failing, what's failing, and what the logs actually say because you've posted contradictory outcomes.
-- Scott
More information about the users
mailing list