Error Unable to find certificate chain
de Oliveira, Vitor
vmiranda at ptc.com
Wed May 25 08:19:59 EDT 2016
Hello Folks,
I am configuring Shibboleth with Apache as a Service Provider.
After installing Shibboleth and configuring files httpd.conf (Apache), apache22 and shibboleth2 (Shibboleth), deploying IdP metadata file and generating SP metadata using the Metadatagenerator handler we tried to make a connection between the IdP and SP.
We, then, had the following error:
</exServiceHealth>
<exServiceHealth exHealthStatus="Warning" exServiceName="Monitored System Events">
<exDescription exHealthStatus="Warning"><b>System Event: Time:</b> 2016-05-24 18:27:19, <b>Age:</b> 629Ms, <b>Level:</b> Functional Loss<br><b>Comments:</b><br>Unable to validate SAML2 Trusted Service Provider. The trusted relationship with this entity will not be functional!<br>Error Validating X509 Certificate of Trusted Provider<br>Trusted Provider Type: SAML2 Trusted Service Provider<br>Trusted Provider Id: https://myhost.com/WebUI/<br>Error Validating X509 Signing Certificate<br>X509 Certificate Version: 3<br>X509 Certificate Subject: CN=svg.local<br>X509 Certificate Issuer: CN=svg.local<br>X509 Certificate Serial Number: 13215475894996166680<br>X509 Certificate Start Date: 2016-05-24 09:27:46<br>X509 Certificate Expiration Date: 2026-05-22 09:27:46<br>X509 Certificate Validation Root Exception: com.novell.nidp.NIDPException: Unable to find certificate chain. Root Cause: java.security.cert.CertPathBuilderException: Unable to find certificate chain.</exDescription>
</exServiceHealth>
</exHealth>
</exExceleratorResults>
I googled and it seems is a problem with the configuration regarding federated SSO. I am not sure if I configured everything I need in order to make this work.
Would someone have an idea of what might be happening/missing?
Vitor
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160525/b4573432/attachment.html>
More information about the users
mailing list