"SAML response signature is not valid. "
Tom Poage
tfpoage at ucdavis.edu
Tue Feb 28 20:25:15 EST 2017
Are they hosted on Amazon? ;-)
Cf. today's outage. It affected us.
https://status.aws.amazon.com
> On Feb 28, 2017, at 5:11 PM, IAM David Bantz <dabantz at alaska.edu> wrote:
>
> Currently used certs expire 2034.
>
> I still have certs that expired in 2014 in the IdP metadata for SPs that never consumed the new metadata with new certs in 2014.
>
> But that hasn't changed since 2014.
>
> David
>
>
>
> On Tue, Feb 28, 2017 at 4:05 PM, Tom Poage <tfpoage at ucdavis.edu> wrote:
> Is your signing certificate expired? I've seen some vendors (erroneously) check the expiration date.
>
> Tom.
>
> > On Feb 28, 2017, at 4:24 PM, IAM David Bantz <dabantz at alaska.edu> wrote:
> >
> > An SP we've had integrated and working for years (OrigamiRisk) is now rejecting assertions from my IdP with the message "SAML response signature is not valid."
> >
> > Their error logs contain a seemingly complete copy of my IdP's signed response immediately after that message.
> >
> > The logged outgoing SAML from my IdP asserts success and includes requested attributes. The outgoing assertion is not encrypted. None of my other SPs appear to be affected.
> >
> > I want to say it must be the SP's problem, but if you can think of something further for me to look at in my IdP, I will appreciate it!
> >
> > Thanks,
> >
> >
> > David Bantz
> > UA OIT IAM
> > --
> > To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list