Invalid OpenSSL traditional private key format IDP3.x

Shweta Kautia skautia at northcarolina.edu
Fri Aug 12 14:44:20 EDT 2016


Scott,

Thank you for looking into it. Individual who first set it up, doesn’t work here anymore, we have some documentation that we can reference.
Yes there was a password used to encrypt. We are using the same pwd to generate the new pair.
Unfortunately, we had to do a from-scratch implementation - and are now wanting to re-use the old keypair (if it’s an option).
We are doing a Dockerized IdP installation for our campuses, so we decided to do a clean install.

Can you please point me to any documentation of config changes required for from-scratch installation to support a password-protected key? I will communicate this to the Sys Admin who is setting it up. I am reading some info here, but not on how to change the IDP setup.

https://wiki.shibboleth.net/confluence/display/IDP30/SecurityAndNetworking#SecurityAndNetworking-EncryptionKeyandCertificate

We used the same keypair for signing and encryption.. and plan to do the same for V3(if possible).
We are not using a legacy relying-party.xml or other files, the only thing legacy is some definitions in attribute-resolver.xml for EPTID etc which have been said to be compatible for V3.


Thanks again,
Shweta


On Aug 12, 2016, at 2:04 PM, Cantor, Scott <cantor.2 at osu.edu<mailto:cantor.2 at osu.edu>> wrote:

I found the error message in the Java library, but it's not particularly
informative other than the obvious.

I assume you know whether the key was encrypted with a password, and I
also don't know if you're doing a proper upgrade or if you ignored our
instructions and tried to do it from scratch and are now trying to copy
back the old keypair. The default from-scratch install does not
configure things to support a password-protected key. A legacy
relying-party file would have the password in it, probably, but that
wouldn't work with a non-upgraded install.

Lot of variables here, none of them provided in the email to the list.

-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160812/c1430136/attachment.html>


More information about the users mailing list