sp.testshib ssl trust
Adam Ward
Adam.Ward at migliori.co.uk
Thu Nov 19 11:22:58 EST 2015
Hi,
I'm getting
2015-11-19 05:47:54 DEBUG OpenSAML.MessageDecoder.SAML2 [128]: extracting issuer from SAML 2.0 protocol message
2015-11-19 05:47:54 DEBUG OpenSAML.MessageDecoder.SAML2 [128]: message from (https://idp.southdowns.ac.uk/idp/shibboleth)
2015-11-19 05:47:54 DEBUG OpenSAML.MessageDecoder.SAML2 [128]: searching metadata for message issuer...
2015-11-19 05:47:54 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [128]: evaluating message flow policy (replay checking on, expiration 60)
2015-11-19 05:47:54 DEBUG XMLTooling.StorageService [128]: inserted record (_9847bb10d3c5b3f9859dbea984d1b7ab) in context (MessageFlow) with expiration (1447930309)
2015-11-19 05:47:54 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [128]: validating signature profile
2015-11-19 05:47:54 DEBUG XMLTooling.CredentialCriteria [128]: keys didn't match
2015-11-19 05:47:54 DEBUG XMLTooling.CredentialCriteria [128]: keys didn't match
2015-11-19 05:47:54 DEBUG XMLTooling.TrustEngine.ExplicitKey [128]: unable to validate signature, no credentials available from peer
2015-11-19 05:47:54 DEBUG XMLTooling.TrustEngine.PKIX [128]: validating signature using certificate from within the signature
2015-11-19 05:47:54 DEBUG XMLTooling.TrustEngine.PKIX [128]: signature verified with key inside signature, attempting certificate validation...
2015-11-19 05:47:54 DEBUG XMLTooling.TrustEngine.PKIX [128]: checking that the certificate name is acceptable
2015-11-19 05:47:54 DEBUG XMLTooling.TrustEngine.PKIX [128]: adding to list of trusted names (https://idp.southdowns.ac.uk/idp/shibboleth)
2015-11-19 05:47:54 DEBUG XMLTooling.TrustEngine.PKIX [128]: certificate subject: CN=idp.southdowns.ac.uk
2015-11-19 05:47:54 DEBUG XMLTooling.TrustEngine.PKIX [128]: unable to match DN, trying TLS subjectAltName match
2015-11-19 05:47:54 DEBUG XMLTooling.TrustEngine.PKIX [128]: matched DNS/URI subjectAltName to a key name (https://idp.southdowns.ac.uk/idp/shibboleth)
2015-11-19 05:47:54 DEBUG XMLTooling.TrustEngine.PKIX [128]: performing certificate path validation...
2015-11-19 05:47:54 DEBUG XMLTooling.TrustEngine.PKIX [128]: failed to validate certificate chain using supplied PKIX information
2015-11-19 05:47:54 ERROR OpenSAML.SecurityPolicyRule.XMLSigning [128]: unable to verify message signature with supplied trust engine
After attempting to login to the sp.testshib, I thought it was test meta file conflicts but apparently not. Any ideas?
Thanks
Adam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151119/bf9eb190/attachment-0001.html>
More information about the users
mailing list