Signature validation failure = incorrect certificate?
Cantor, Scott
cantor.2 at osu.edu
Tue Nov 24 14:13:50 EST 2015
On 11/24/15, 2:10 PM, "users on behalf of IAM David Bantz" <users-bounces at shibboleth.net on behalf of dabantz at alaska.edu> wrote:
>
>When I attempt to log in to a new vendor SP, my IdP is unable to verify the signature on the request, with the following log entry
>
>I am interpreting this to mean either the vendor provided me a different certificate than used to sign the request, or that I botched the process of converting the certificate provided into the form needed in metadata. Have I missed other possible sources of failure that I need to explore?
A bug in their code is the other. Difficult to really know unfortunately, unless you can get a trustworthy statement that other SAML implementations or customers are successfully verifying their signed redirects.
-- Scott
More information about the users
mailing list