Shibboleth Artifact Binding : Inbound message issuer was not authenticated

Indunil Rathnayake indunil.uom at gmail.com
Wed Apr 25 04:26:53 EDT 2018


Hi,

Shibbolet is configured for SAML artifact binding and following error can
be seen in logs, when processing the ArtifactResolve SOAP request.

     ERROR
> [org.opensaml.ws.security.provider.MandatoryAuthenticatedMessageRule:37] -
> Inbound message issuer was not authenticated.
>     12:54:22.906 - WARN
> [edu.internet2.middleware.shibboleth.idp.profile.saml2.ArtifactResolution:199]
> - Message did not meet security requirements
>     org.opensaml.ws.security.SecurityPolicyException: Inbound message
> issuer was not authenticated.
>         at
> org.opensaml.ws.security.provider.MandatoryAuthenticatedMessageRule.evaluate(MandatoryAuthenticatedMessageRule.java:38)
> ~[openws-1.5.6.jar:na]
>

The issuer value of ArtifactResolve request, is same as the entityID of the
SP metadata. What it meant by authenticating the issuer? and how it's done?

Appreciate your help on this.

Thanks and Regards

-- 


*Indunil Rathnayake *
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20180425/66eb28ea/attachment.html>


More information about the users mailing list