sp.testshib ssl trust
Adam Ward
Adam.Ward at migliori.co.uk
Thu Nov 19 11:59:11 EST 2015
Hi Kevin,
Still getting:
<saml2p:Status><saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Responder"/><saml2p:StatusMessage>An error occurred.</saml2p:StatusMessage></saml2p:Status></saml2p:Response>
2015-11-19 11:57:01 DEBUG OpenSAML.MessageDecoder.SAML2 [6]: extracting issuer from SAML 2.0 protocol message
2015-11-19 11:57:01 DEBUG OpenSAML.MessageDecoder.SAML2 [6]: message from (https://idp.southdowns.ac.uk/idp/shibboleth)
2015-11-19 11:57:01 DEBUG OpenSAML.MessageDecoder.SAML2 [6]: searching metadata for message issuer...
2015-11-19 11:57:01 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [6]: evaluating message flow policy (replay checking on, expiration 60)
2015-11-19 11:57:01 DEBUG XMLTooling.StorageService [6]: inserted record (_76cd010f4fdc4cd770fee2459d6ef0d4) in context (MessageFlow) with expiration (1447952456)
2015-11-19 11:57:01 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [6]: validating signature profile
2015-11-19 11:57:01 DEBUG XMLTooling.KeyInfoResolver.Inline [6]: resolving ds:X509Certificate
2015-11-19 11:57:01 DEBUG XMLTooling.KeyInfoResolver.Inline [6]: resolved 1 certificate(s)
2015-11-19 11:57:01 DEBUG XMLTooling.KeyInfoResolver.Inline [6]: resolved 0 CRL(s)
2015-11-19 11:57:01 DEBUG XMLTooling.KeyInfoResolver.Inline [6]: resolving ds:X509Certificate
2015-11-19 11:57:01 DEBUG XMLTooling.KeyInfoResolver.Inline [6]: resolved 1 certificate(s)
2015-11-19 11:57:01 DEBUG XMLTooling.KeyInfoResolver.Inline [6]: resolved 0 CRL(s)
2015-11-19 11:57:01 DEBUG XMLTooling.KeyInfoResolver.Inline [6]: resolving ds:X509Certificate
2015-11-19 11:57:01 DEBUG XMLTooling.KeyInfoResolver.Inline [6]: resolved 1 certificate(s)
2015-11-19 11:57:01 DEBUG XMLTooling.KeyInfoResolver.Inline [6]: resolved 0 CRL(s)
2015-11-19 11:57:01 DEBUG XMLTooling.CredentialCriteria [6]: keys didn't match
2015-11-19 11:57:01 DEBUG XMLTooling.CredentialCriteria [6]: keys didn't match
2015-11-19 11:57:01 DEBUG XMLTooling.TrustEngine.ExplicitKey [6]: unable to validate signature, no credentials available from peer
2015-11-19 11:57:01 DEBUG XMLTooling.TrustEngine.PKIX [6]: validating signature using certificate from within the signature
2015-11-19 11:57:01 DEBUG XMLTooling.TrustEngine.PKIX [6]: signature verified with key inside signature, attempting certificate validation...
2015-11-19 11:57:01 DEBUG XMLTooling.TrustEngine.PKIX [6]: checking that the certificate name is acceptable
2015-11-19 11:57:01 DEBUG XMLTooling.TrustEngine.PKIX [6]: adding to list of trusted names (https://idp.southdowns.ac.uk/idp/shibboleth)
2015-11-19 11:57:01 DEBUG XMLTooling.TrustEngine.PKIX [6]: certificate subject: CN=idp.southdowns.ac.uk
2015-11-19 11:57:01 DEBUG XMLTooling.TrustEngine.PKIX [6]: unable to match DN, trying TLS subjectAltName match
2015-11-19 11:57:01 DEBUG XMLTooling.TrustEngine.PKIX [6]: matched DNS/URI subjectAltName to a key name (https://idp.southdowns.ac.uk/idp/shibboleth)
2015-11-19 11:57:01 DEBUG XMLTooling.TrustEngine.PKIX [6]: performing certificate path validation...
2015-11-19 11:57:01 DEBUG XMLTooling.TrustEngine.PKIX [6]: failed to validate certificate chain using supplied PKIX information
2015-11-19 11:57:01 ERROR OpenSAML.SecurityPolicyRule.XMLSigning [6]: unable to verify message signature with supplied trust engine
Any ideas what's up?
Thanks
Adam
-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Kevin Foote
Sent: Thursday, November 19, 2015 4:37 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: sp.testshib ssl trust
> On Nov 19, 2015, at 8:22 AM, Adam Ward <Adam.Ward at migliori.co.uk> wrote:
>
>
> After attempting to login to the sp.testshib, I thought it was test meta file conflicts but apparently not. Any ideas?
Adam please try again .. sp.testshib.org
--------
thanks
kevin.foote
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list