Shibboleth IdP 3.0 - Signature Validation Error
Gross, James
JamesGross at uncc.edu
Mon Mar 2 17:07:40 EST 2015
Marvin,
The vendor is not using the Shibboleth SP, but what appears to be homegrown SAML integration. It would not surprise me if they did not handle the new line properly on their end. My best chance for quick resolution would be to prevent it from being sent in the first place.
- James
On Mar 2, 2015, at 4:53 PM, Marvin Addison <marvin.addison at gmail.com<mailto:marvin.addison at gmail.com>> wrote:
I've enabled SAML logging within both the IdP2 and IdP3 environment and have noticed that the IdP 3.0 assertion contains a "
" after every line of the X509 certificate that is not present in the logs for the 2.0 IdP. Is it possible that this is throwing off the signature validation?
I noticed the weird characters in the SP logs as well recently while troubleshooting an integration with our new IdPv3 instance. I worked through the problem eventually without changing certs on either endpoint, so I chalked it up to a logging artifact on the SP side. Still may be a bug, but not a signature validation bug afaict.
M
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150302/f07058e7/attachment.html
More information about the users
mailing list