missing - Resolving credentials

Jeff Mccullough jeffmc at berkeley.edu
Wed Dec 21 02:39:18 EST 2016


I have two version 3 IDP servers setup. One works when evaluating a signing credential from a local SP, and the other does not. One was done as an upgrade from v2 -> v3, while the other was a regular install. Here is the log from the working version (the upgrade)…

2016-12-20 22:31:29,571 - DEBUG [org.opensaml.saml.saml2.binding.security.impl.SAML2HTTPRedirectDeflateSignatureSecurityHandler:59] - Constructing signed content string from URL query string SAMLRequest=jZJPU8IwEMW%2FSid3GhKklAztTIWDzKAwt
Hrw4oR2kYwhqdlU5dtb%2FsiAB8dz%0AXt57%2B9sdodzqWmSN35glvDeAPvjaaoPi8JCQxhlhJSoURm4BhS9Fnt3PBA%2B7%0AonbW29JqEmSI4LyyZmwNNltwObgPVcLjcpaQjfc1Ckpxo1YdrFlYSm3Ah2zI%0A4nAF7g007EKoGpq3ipXV4DchoqX7IE4X87wgwaRtpozcZ%2FxyrM6GV16qqmlb%0AcK00nIyWUCk
Hpad5PifBdJKQl8EglrIqGV9ziNeDqKygB%2FHwpr%2BOIugPeStD%0AbGBq0EvjE8K7LOow3uGs6EaixwSPn0mwOHG4VaZS5vVvaKujCMVdUSw6x%2BGe%0AwOFhsFZA0tEevTgEu4tl%2FG0rfzZA0v%2FzxjPvVjeiF7nHErV4aIOmk4XVqtwF%0Amdb2c%2BxAekgIIzQ9frk%2Bn%2FQb%0A&RelayState=cooki
e%3Abe45c348&SigAlg=http%3A%2F%2Fwww.w3.org%2F2000%2F09%2Fxmldsig%23rsa-sha1&Signature=bxVBVx4JDggBYmQcmYlOe3oe9G7Beq61KWki6K3uky5ZW6fd12bd0dpIbkGMnVGNhbtiliHLle2Bneu6zs%2BQm0d3lwYVNVg0nhN6FQr0AaUyCnOWSEbqQf9bnxE%2Bvn7yU9IIdzZkDjL7GdpLeYV
raIUvUtQfxZNTR9NGRvcynwOzxgjk%2F%2FS7Nvc4TdMV68O8KMjDIi4aHfQYrHshg%2FAOovLesQkngIlAXTh8qSvKiTVX3NjkazbjsgxnNVCDjKeVG0mbQJ5A%2B8o0ILEqq8%2BGSxzFwRBpNcmvtZ05pUmqCzJvM9Bd%2BrvBXxFvH97Apy4w6SepBjh7aTX453txlmHDCQ%3D%3D
2016-12-20 22:31:29,571 - DEBUG [org.opensaml.saml.saml2.binding.security.impl.SAML2HTTPRedirectDeflateSignatureSecurityHandler:66] - Constructed signed content string for HTTP-Redirect DEFLATE SAMLRequest=jZJPU8IwEMW%2FSid3GhKklAztTIWDzK
AwtHrw4oR2kYwhqdlU5dtb%2FsiAB8dz%0AXt57%2B9sdodzqWmSN35glvDeAPvjaaoPi8JCQxhlhJSoURm4BhS9Fnt3PBA%2B7%0AonbW29JqEmSI4LyyZmwNNltwObgPVcLjcpaQjfc1Ckpxo1YdrFlYSm3Ah2zI%0A4nAF7g007EKoGpq3ipXV4DchoqX7IE4X87wgwaRtpozcZ%2FxyrM6GV16qqmlb%0AcK00nIyW
UCkHpad5PifBdJKQl8EglrIqGV9ziNeDqKygB%2FHwpr%2BOIugPeStD%0AbGBq0EvjE8K7LOow3uGs6EaixwSPn0mwOHG4VaZS5vVvaKujCMVdUSw6x%2BGe%0AwOFhsFZA0tEevTgEu4tl%2FG0rfzZA0v%2FzxjPvVjeiF7nHErV4aIOmk4XVqtwF%0Amdb2c%2BxAekgIIzQ9frk%2Bn%2FQb%0A&RelayState=co
okie%3Abe45c348&SigAlg=http%3A%2F%2Fwww.w3.org%2F2000%2F09%2Fxmldsig%23rsa-sha1
2016-12-20 22:31:29,571 - DEBUG [org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:199] - Message Handler:  Attempting to validate SAML protocol message simple signature using context entityID: https://mySP
2016-12-20 22:31:29,572 - DEBUG [org.opensaml.saml.security.impl.MetadataCredentialResolver:286] - Resolving credentials from metadata using entityID: https://mySP, role: {urn:oasis:names:tc:SAML
:2.0:metadata}SPSSODescriptor, protocol: urn:oasis:names:tc:SAML:2.0:protocol, usage: SIGNING
2016-12-20 22:31:29,572 - DEBUG [org.opensaml.saml.security.impl.MetadataCredentialResolver:435] - Retrieving role descriptor metadata for entity 'https://mySP' in role '{urn:oasis:names:tc:SAML:
2.0:metadata}SPSSODescriptor' for protocol 'urn:oasis:names:tc:SAML:2.0:protocol’
2016-12-20 22:31:29,574 - DEBUG [org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:271] - Message Handler:  Simple signature validation (with no request-derived credentials) was successful


The non-working version is missing these two lines in the logs… 

2016-12-20 22:31:29,572 - DEBUG [org.opensaml.saml.security.impl.MetadataCredentialResolver:286] - Resolving credentials from metadata using entityID: https://mySP, role: {urn:oasis:names:tc:SAML
:2.0:metadata}SPSSODescriptor, protocol: urn:oasis:names:tc:SAML:2.0:protocol, usage: SIGNING
2016-12-20 22:31:29,572 - DEBUG [org.opensaml.saml.security.impl.MetadataCredentialResolver:435] - Retrieving role descriptor metadata for entity 'https://mySP' in role '{urn:oasis:names:tc:SAML:
2.0:metadata}SPSSODescriptor' for protocol 'urn:oasis:names:tc:SAML:2.0:protocol’


Is there a configuration setting that is driving this or something else? The SP and its metadata file are the same for both IDP servers.

Thanks,
Jeff
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161220/99df0998/attachment-0001.html>


More information about the users mailing list