SHA1 signed authn request issue

Yavor Yanakiev yavor at nyu.edu
Fri Mar 10 15:47:22 EST 2017


The metadata file is shared between IdP v3.2 and v3.3 so it shouldn't be a
metadata issue.
Unsolicited authentication works fine.

On Fri, Mar 10, 2017 at 3:39 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> > We have a third party vendor which is sending a signed authentication
> > request but with SHA1. IdP v3.3 is rejecting the request with
>
> The failure isn't a SHA1 issue, we don't blacklist it. You just have the
> wrong metadata or they have the wrong key. Nothing mysterious, and the
> error in the log is telling you this outright (signature verification
> failed). Don't go looking for reasons, that is the reason.
>
> -- Scott
>
>


-- 
Yavor Yanakiev
Systems Developer for Identity Services
212-992-7585
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170310/e4459857/attachment.html>


More information about the users mailing list