failed signature verification causing IdP not to load?
Rob Gorrell
rwgorrel at uncg.edu
Fri Jun 12 11:11:01 EDT 2015
I have a FileBackedHTTPMetadataProvider that we do SignatureValidation on
and requireSignedMetadata. Recently, after my IdP reloaded metadata from
this federation, it decided not to load with the following fatal errors:
11:02:00.519 - ERROR
[org.opensaml.saml2.metadata.provider.SignatureValidationFilter:311] -
Signature trust establishment failed for metadata entry
https://odapilib.libraryreserve.com/FederatedAuthentication/saml/trust
11:02:00.520 - ERROR
[org.opensaml.saml2.metadata.provider.SignatureValidationFilter:254] -
EntityDescriptor '
https://odapilib.libraryreserve.com/FederatedAuthentication/saml/trust'
failed signature verification, removing from metadata provider
11:02:00.540 - ERROR
[org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:411] -
Metadata provider failed to properly initializing, halting
org.opensaml.saml2.metadata.provider.MetadataProviderException:
java.lang.UnsupportedOperationException
11:02:00.546 - ERROR
[edu.internet2.middleware.shibboleth.common.config.BaseService:188] -
Configuration was not loaded for
shibboleth.RelyingPartyConfigurationManager service, error creating
components. The root cause of this error was:
java.lang.UnsupportedOperationException: null
Obviously, there is an entity in the metadata that fails signature
validation, but should that stop my IdP from loading? or simply omit that
entity but continue on? What would control something like that?
I spoke to another member of this federation who receives the same two
first errors about the failed signature validation, however, his IdP keeps
trucking and doesn't fail with the last two errors that mine does. I'm
trying to figure out if there is a setting that makes our IdP more
stringent when it comes to encountering this type of error in downloaded
metadata?
Thanks
-Rob
--
Robert W. Gorrell
Systems Architect, Identity and Access Management
University of NC at Greensboro
336-334-5954
PGP Key ID B36DB0CA
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150612/0a95e66a/attachment-0001.html>
More information about the users
mailing list