IdP 3: error on SAML 1 AttributeQuery

Sara Hopkins sara.hopkins at ed.ac.uk
Wed Mar 18 13:17:23 EDT 2015


On 17/03/2015 15:50, Cantor, Scott wrote:

> Without digging in too far, that's what I'd expect if the message
> isn't signed and there's no client certificate presented, or at least
> none making it into Java-space.

Thanks Scott. The SP is on the default settings, so that would be 
message not signed but trust certificate presented as TLS credential, I 
think. However I don't know how to make the IdP log the SAML messages 
from the SP; the PROTOCOL_MESSAGE logger is enabled but I'm only seeing 
IdP messages in the log.

I don't see why the SP would present a TLS credential to my own IdP but 
not to my client's, unless something on his network is messing with the 
certificate contents. Possible of course, but it looks as though it's 
just jetty listening on port 8443.

Sara
-- 
Sara Hopkins
Support Team
UK Access Management Federation for Education and Research
web:    http://www.ukfederation.org.uk/

The University of Edinburgh is a charitable body, registered in
Scotland, with registration number SC005336.


More information about the users mailing list