SAML response signature is missing.

Laske Laskee laskekv995 at gmail.com
Fri Jun 14 08:03:16 EDT 2019


I learned this the hard way, but some providers don’t return signature in the assertion response. If it stared happening without you making any changes on your end, i seems that it’s on provider side. 

Oskar

> On Jun 14, 2019, at 1:10 PM, Losen, Stephen C (scl) <scl at virginia.edu> wrote:
> 
> Hi Joshua,
>  
> This looks like a problem on the SP. It looks like the SP does not have the metadata for your IDP. Does the SP fetch it dynamically from a URL or does it read it from a local file?  Looks like you publish your IDP metadata with InCommon and that your IDP entityID is “urn:mace:incommon:ncsu.edu” However, I browsed https://shib.ncsu.edu/idp/shibboleth and got a metadata file that looks wrong because it has references to “localhost.localdomain” Not a problem unless the SP is fetching this file.
>  
> I browsed the link to your SP and I immediately got an error. I was not redirected to your IDP to login. So the problem is likely on the SP, or at least that is where to start looking.
>  
> If the SP has a local copy of the IDP metadata, look for an expiration date at the top: validUntil=”expiration-date” If this has expired then that could be the problem. You can edit the file and remove the validUntil attribute.
>  
> Steve Losen
> ITS – Enterprise Infrastructure
> University of Virginia
> scl at virginia.edu    434-924-0640
>  
> From: users <users-bounces at shibboleth.net> On Behalf Of Joshua Snapp
> Sent: Friday, June 14, 2019 6:12 AM
> To: users at shibboleth.net
> Subject: SAML response signature is missing.
>  
> We could use help. Our primary system admin for our shibboleth IdP is unreachable while on vacation.
> Here's a little version info about our IdP:
> IdP version: 3.4.4
> Java version: 1.8.0_212
>  
> One of our SPs suddenly started receiving the following messages:
>  
> Error when logging into https://www.ebenefitsnow.com/sso/saml:
> SAML response signature is missing.
> 
> Other error reported by SP:
> No inbound configuration found for issuer:
> https://shib.ncsu.edu/idp/shibboleth
>  
> Can anyone provide insight into what may cause this behavior? We haven't made any changes to our configuration on the IdP. The configuration files are in version control. The last commit was April 16th. This problem just started on June 11th.
>  
> Thanks for any help you can provide.
>  
> --
> Joshua Snapp
> 
> Systems Programmer - Identity and Web Services Group
> North Carolina State University - Office of Information Technology
> 
> 1.919.513.0183  jksnapp at ncsu.edu
> 
> -- 
> For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190614/2f6c8ab1/attachment.html>


More information about the users mailing list