ERROR Shibboleth.SSO.SAML2 [1]: failed to decrypt assertion: Unable to resolve any key decryption keys.

Cantor, Scott cantor.2 at
Mon Aug 29 20:12:42 EDT 2016

On 8/29/16, 7:58 PM, "users on behalf of Joel Levin" <users-bounces at on behalf of joel.aaron.levin at> wrote:

>    I'm missing something - but not sure what?

The metadata just isn't right, or more generally all of those checks you did just aren't right. Can't be. Not much else I can tell you.

The only other possible reason is if you're using the right key but a different certificate and the KeyInfo the IdP is embedding is crossing up the SP's ability to locate its key.

-- Scott

More information about the users mailing list