"Credential failed name check" ERROR
IAM David Bantz
dabantz at alaska.edu
Wed Oct 10 13:41:52 EDT 2018
Thanks for sanity check. Vendor made another change at their end (I think
it may have just been restart of SP) after which the integration worked
immediately. I do not know what SP implementation they use.
David Bantz
On Wed, Oct 10, 2018 at 7:35 AM Cantor, Scott <cantor.2 at osu.edu> wrote:
> > I haven't seen this error previously. This is early processing of
> incoming
> > request; it seems to say checking a signed request failed, but refers to
> > "Credential" failed, providing a CN that makes no sense either Cherwell
> or to
> > me (subjectName='CN=ualaska.cherwellondemand.com
> > <http://wellondemand.com/> ,OU=Domain Control Validated') Is that the CN
> > from a certificate? Not a certificate in the SP metadata!
>
> If it's not in the metadata then you know what the real problem is, same
> as it always is. The message is the usual "falls through into PKIX trust
> engine" result when the key isn't in the metadata. You're falling through
> from direct to indirect trust. SP 3 disables PKIX by default and IdP 4 will
> do the same.
>
> -- Scott
>
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20181010/cc4b3d80/attachment.html>
More information about the users
mailing list