Jostle and Shibboleth

Ullfig, Roberto Alfredo rullfig at uic.edu
Tue Jan 15 15:53:57 EST 2019


Thanks Matt – that did the trick! Not sure where my problem was but you had this in SPSSODescriptor:

AuthnRequestsSigned="false" WantAssertionsSigned="true"

And this:

<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">

Where I just had <ds:KeyInfo>

Or it might have been some other typo.

---
Roberto Ullfig - rullfig at uic.edu
Systems Administrator
Enterprise Architecture and Development | ACCC
University of Illinois - Chicago

From: users <users-bounces at shibboleth.net> On Behalf Of Matt Brennan
Sent: Monday, January 14, 2019 3:51 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: Jostle and Shibboleth

Roberto,

  I can send you what I have for metadata for Jostle if you think it will help ... but we haven't been a customer for over a year now so I cannot promise it's correct anymore. It was working a little over a year ago and the certs in it don't appear to have expired.

-Matt

On Mon, Jan 14, 2019 at 4:28 PM Cantor, Scott <cantor.2 at osu.edu<mailto:cantor.2 at osu.edu>> wrote:
Actually I would speculate you might have corrupted it in the metadata creation process, causing it to validate the signature with the key it saw in the message and then fail to validate the path of the certificate. But without a more complete log trace, I'm just guessing. But that probably fits better than the alternatives. If the key in the message wasn't the one used, the error should be something different.

-- Scott


--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190115/89fe90e4/attachment.html>


More information about the users mailing list