IdP 3.3.1 SSL certificate signature verification failed

Cantor, Scott cantor.2 at osu.edu
Wed Jul 5 10:59:59 EDT 2017


On 7/5/17, 10:55 AM, "users on behalf of George Stoynev" <users-bounces at shibboleth.net on behalf of george.stoynev at mcgill.ca> wrote:

> If the certificate is self-signed would this have any impact on the 
> signature verification? I think it should not as long as the key in the 
> metadata is correct.

The content of the certificate has no impact.

> How to verify if the metadata is wrong? What is the most likely reason 
> for a metadata to be incorrect?

Either the code is wrong or the key in the metadata is. Both of them would produce the same result. Unless it's an implementation with known provenance and evidence of its correctness then there is nothing that can be concluded.

The reason is "people don't know what they're doing with keys or with metadata". There's nothing more deep to it in most cases.

-- Scott




More information about the users mailing list