certificate name was not acceptable
William Griffin-Dubson
wrgriffi at coastal.edu
Wed Feb 1 10:06:18 EST 2017
How could this be the case? I copied over the entire credentials directory from the Windows server to the Linux one. It should be using all of the same certificates.
Thanks,
Bill
On Wed, 2017-02-01 at 09:30 -0500, Bill Griffin-Dubson wrote:
We are running into an issue with our Shibboleth IDP installation.
We are using a Windows server for our current IDP 3.2.1 called Shib1
We are working on replacing this server with a Linux one also running IDP 3.2.1 called ShibA.
We are using the same metadata and certificates, and when we are ready to make the switch ShibA will be changed to Shib1 to replace it.
We are in the testing phase now and we are running into the following issue.
On the webpage on the SP after logging in successfully on the idp I receive the following message:
Message was signed, but signature could not be verified.
The logs on the SP show:
ERROR XMLTooling.TrustEngine.PKIX [1]: certificate name was not acceptable
I am positive that the IDP and the SP are using the same metadata, but it is the metadata from Shib1. We are using Shib1's metadata so we won't have to push out a new metadata file to all of our SP's after we make the switch. We want this to be as seamless as possible.
Any help with this would be greatly appreciated.
Thanks,
Bill
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170201/bc834310/attachment.html>
More information about the users
mailing list