sp(2.5.5) <-> idp(3.1.2) and ecdsa certs

Brent Putman putmanb at georgetown.edu
Tue Oct 20 14:28:46 EDT 2015



On 10/20/15 12:44 PM, Cantor, Scott wrote:
>
> Hmm. Hopefully Brent just tweaked something and a POST from the IdP actually does work. Otherwise this is getting pretty weird.

The obvious mistake - wrong key in metadata - doesn't seem to be the
case.  So I don't know, it is pretty weird.

Most interesting is that the SP can validate a metadata signature from
the Java xmlsectool.  The big delta there is xmlsectool is still using
Santuario 1.5.7, as where OpenSAML/IdP 3.x are using Santuario 2.0.3. 
So therein may lie the difference.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151020/28c99dac/attachment.html>


More information about the users mailing list