Native ADFS support and signature verification
Robert Lowe
robertmlowe at rmlowe.com
Tue Sep 19 08:16:14 EDT 2017
Trying to use the native ADFS support with an Access Control Service IdP.
We have actually had this working previously, but on this occasion we're
getting the “Message was signed, but signature could not be verified”
message. I understand what this message means, but what is confusing me is
the following in the log:
2017-09-18 14:42:23 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [2]:
validating signature profile
2017-09-18 14:42:23 ERROR XMLTooling.TrustEngine.PKIX [2]: certificate name
was not acceptable
2017-09-18 14:42:23 ERROR OpenSAML.SecurityPolicyRule.XMLSigning [2]:
unable to verify message signature with supplied trust engine
This seems to imply that PKIX is being used, however I understood that
Shibboleth doesn't use PKIX by default and we haven't explicitly configured
any TrustEngines. Is this not the case when using the ADFS support?
--
Best regards,
Robert Lowe
http://crepuscular.rmlowe.com/
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170919/6aed056e/attachment.html>
More information about the users
mailing list