SP cannot decrypt EncryptedAssertion responses

Cantor, Scott cantor.2 at osu.edu
Fri Feb 26 09:23:39 EST 2016


> Would you please help me with what might be a Shibboleth SP
> configuration issue?

You have the wrong key in your SP's metadata.

> I suspect that this is a configuration error on my part, but I can't
> figure out what I did wrong.  The correct keying material (and other
> metadata) is loaded on both systems.  (Each entity uses the same
> key-pair for both signing and encryption.)  I confirmed this by using
> SAMLParser to decrypt the EncryptedAssertion response.

Well, then that would mean ADFS and Shibboleth don't interop, and we know that's not true, so...

-- Scott



More information about the users mailing list