Error with RelyingPartyResolverService on new v3 setup

Mark Cairney Mark.Cairney at ed.ac.uk
Wed Feb 10 15:34:04 EST 2016



On 10/02/16 17:23, Cantor, Scott wrote:
>> I've started looking at setting up a test v3 IdP from scratch and am in
>> the process of migrating config from an existing v2 IdP over to it. The
>> IdP starts up and displays the status page at /idp/status but
>> /idp/profile/Status; /idp/profile/Metadata/SAML produces a 404 error
> No such thing, so yes, you should get a 404 from that.

OK found the thread discussing this- I can now see the metadata at 
/idp/shibboleth

>> spotted the following error in the logs which has me confused as I
>> haven't edited the relying-party.xml
> Nobody has reported that error, but it looks to me like a problem loading a key or certificate, guess it depends what the original format is. Don't know where we are documenting all the credential formats, but if it's not PEM, I'd start by converting it to PEM.

I had been using the keypair generated for the backchannel for signing 
and encryption to tie in with the predicted config of the upgraded 
servers. Rolling this back to the separate keypairs in idp.properties 
appears to fix the error. The idp-backchannel.crt is a PEM file though 
(confirmed with openssl x509 -text -in idp-backchannel.crt). Curious!

> -- Scott
>


-- 
The University of Edinburgh is a charitable body, registered in
Scotland, with registration number SC005336.



More information about the users mailing list