error: certificate name was not acceptable

irfan sarwar isarwar3334 at gmail.com
Mon Aug 26 09:21:38 EDT 2019


Hi,
below are the error messages i'm getting.

2019-08-26 08:25:44 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [3]
[default]: validating signature profile
2019-08-26 08:25:44 DEBUG XMLTooling.TrustEngine.PKIX [3] [default]:
validating signature using certificate from within the signature
2019-08-26 08:25:44 DEBUG XMLTooling.TrustEngine.PKIX [3] [default]:
signature verified with key inside signature, attempting certificate
validation...
2019-08-26 08:25:44 DEBUG XMLTooling.TrustEngine.PKIX [3] [default]:
checking that the certificate name is acceptable
2019-08-26 08:25:44 DEBUG XMLTooling.TrustEngine.PKIX [3] [default]: adding
to list of trusted names (urn:saml2:mkoramcfinscom)
2019-08-26 08:25:44 DEBUG XMLTooling.TrustEngine.PKIX [3] [default]:
certificate subject: CN=idp.mfintl.com,OU=Domain Control Validated
2019-08-26 08:25:44 DEBUG XMLTooling.TrustEngine.PKIX [3] [default]: unable
to match DN, trying TLS subjectAltName match
2019-08-26 08:25:44 DEBUG XMLTooling.TrustEngine.PKIX [3] [default]: unable
to match subjectAltName, trying TLS CN match
2019-08-26 08:25:44 ERROR XMLTooling.TrustEngine.PKIX [3] [default]:
certificate name was not acceptable
2019-08-26 08:25:44 WARN OpenSAML.SecurityPolicyRule.XMLSigning [3]
[default]: unable to verify message signature with supplied trust engine
2019-08-26 08:25:44 WARN Shibboleth.SSO.SAML2 [3] [default]: error
processing incoming assertion: Message was signed, but signature could not
be verified.


my understanding is IDP name doesn't need to match the signing certificate
name.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190826/0d4fbcf0/attachment.html>


More information about the users mailing list