"SAML response signature is not valid. "

Tom Poage tfpoage at ucdavis.edu
Tue Feb 28 20:25:15 EST 2017


Are they hosted on Amazon? ;-)

Cf. today's outage. It affected us.

https://status.aws.amazon.com


> On Feb 28, 2017, at 5:11 PM, IAM David Bantz <dabantz at alaska.edu> wrote:
> 
> Currently used certs expire 2034.
> 
> I still have certs that expired in 2014 in the IdP metadata for SPs that never consumed the new metadata with new certs in 2014.
> 
> But that hasn't changed since 2014.
> 
> David
> 
> 
> 
> On Tue, Feb 28, 2017 at 4:05 PM, Tom Poage <tfpoage at ucdavis.edu> wrote:
> Is your signing certificate expired? I've seen some vendors (erroneously) check the expiration date.
> 
> Tom.
> 
> > On Feb 28, 2017, at 4:24 PM, IAM David Bantz <dabantz at alaska.edu> wrote:
> >
> > An SP we've had integrated and working for years (OrigamiRisk) is now rejecting assertions from my IdP with the message "SAML response signature is not valid."
> >
> > Their error logs contain a seemingly complete copy of my IdP's signed response immediately after that message.
> >
> > The logged outgoing SAML from my IdP asserts success and includes requested attributes. The outgoing assertion is not encrypted. None of my other SPs appear to be affected.
> >
> > I want to say it must be the SP's problem, but if you can think of something further for me to look at in my IdP, I will appreciate it!
> >
> > Thanks,
> >
> >
> > David Bantz
> > UA OIT IAM
> > --
> > To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
> 
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
> 
> -- 
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



More information about the users mailing list