certificate name was not acceptable

Cantor, Scott cantor.2 at osu.edu
Wed Feb 1 09:47:50 EST 2017


On 2/1/17, 9:30 AM, "users on behalf of William Griffin-Dubson" <users-bounces at shibboleth.net on behalf of wrgriffi at coastal.edu> wrote:

> The logs on the SP show:
> ERROR XMLTooling.TrustEngine.PKIX [1]: certificate name was not acceptable

That's just an SP falling through into the PKIX check because the explicit key compare against the metadata fails.
    
>    I am positive that the IDP and the SP are using the same metadata, but it is the metadata from Shib1.

The metadata's wrong or the signing key is, period. If you meant for the new IdP to be using the same keypair, which it should, you didn't pull that off correctly.

-- Scott




More information about the users mailing list