Shibboleth SP 3.0.3 : exception loading remote resource: SignatureMetadataFilter unable to verify signature at root of metadata instance.
Dalvi, Vikram (GE Capital, consultant)
vikram.dalvi at ge.com
Tue Jan 8 05:24:29 EST 2019
Hi,
We are trying to load remote IDP meatdata in our SP, for some reason it is giving us below exception in shibd.log,
===========================
OpenSAML.MetadataProvider : building MetadataFilter of type RequireValidUntil
2019-01-08 10:01:35 INFO OpenSAML.MetadataProvider : building MetadataFilter of type Signature
2019-01-08 10:01:35 INFO XMLTooling.SecurityHelper : loading certificate(s) from file (/appbin/web/shibboleth-sp/etc/shibboleth/idp-signing.crt)
2019-01-08 10:01:35 INFO XMLTooling.CredentialResolver.File : no private key resolved, usable for verification/trust only
2019-01-08 10:01:35 INFO XMLTooling.StorageService : cleanup thread started...running every 900 seconds
2019-01-08 10:01:35 INFO OpenSAML.MetadataProvider.XML : loaded XML resource (https://eas.devshibboleth.comfin.ge.com:8443/idp/shibboleth)
2019-01-08 10:01:35 INFO OpenSAML.MetadataProvider : applying metadata filter (RequireValidUntil)
2019-01-08 10:01:35 INFO OpenSAML.MetadataProvider : applying metadata filter (Signature)
2019-01-08 10:01:35 WARN OpenSAML.MetadataFilter.Signature : filtering out entity at root of instance after failed signature check: Root metadata element was unsigned.
2019-01-08 10:01:35 WARN OpenSAML.MetadataProvider.XML : adjusted reload interval to 600 seconds
2019-01-08 10:01:35 WARN OpenSAML.MetadataProvider.XML : trying backup file, exception loading remote resource: SignatureMetadataFilter unable to verify signature at root of metadata instance.
2019-01-08 10:01:35 INFO OpenSAML.MetadataProvider.XML : using local backup of remote resource
2019-01-08 10:01:35 INFO OpenSAML.MetadataProvider.XML : loaded XML resource (/appbin/web/shibboleth-sp/etc/shibboleth/idp-metadata.xml)
2019-01-08 10:01:35 INFO OpenSAML.MetadataProvider : applying metadata filter (RequireValidUntil)
2019-01-08 10:01:35 INFO OpenSAML.MetadataProvider : applying metadata filter (Signature)
2019-01-08 10:01:35 INFO Shibboleth.Application : no TrustEngine specified or installed, using default of ExplicitKey
2019-01-08 10:01:35 INFO Shibboleth.Application : building AttributeExtractor of type XML...
2019-01-08 10:01:35 INFO Shibboleth.AttributeExtractor.XML : loaded XML resource (/appbin/web/shibboleth-sp/etc/shibboleth/attribute-map.xml)
2019-01-08 10:01:35 INFO Shibboleth.AttributeExtractor.XML : creating mapping for Attribute urn:oasis:names:tc:SAML:attribute:subject-id
===========================
In shibd_warn.log we are seeing below messages
==========================
2019-01-08 10:01:35 WARN OpenSAML.MetadataFilter.Signature : filtering out entity at root of instance after failed signature check: Root metadata element was unsigned.
2019-01-08 10:01:35 WARN OpenSAML.MetadataProvider.XML : adjusted reload interval to 600 seconds
2019-01-08 10:01:35 WARN OpenSAML.MetadataProvider.XML : trying backup file, exception loading remote resource: SignatureMetadataFilter unable to verify signature at root of metadata instance.
==========================
After it is unable to verify signature for remote metadata it is loading backup copy of metadata file, for which we do not see any signature validation errors in logs. Both files are same.
Can you please help us in figuring out this one.
Thanks and Regards,
Vikram Dalvi
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190108/68ba5cfd/attachment.html>
More information about the users
mailing list