SAML encryption

Ramkumar Ramsubbu ramkumar.ramsubbu.consultant at nielsen.com
Mon Oct 12 15:44:38 UTC 2020


Hi,

SP hit our IDP & got the saml response. While trying to decrypt SP gets the
below Error. But if we try to take the SAML response  & decrypt it manually
using SPs private key, We are able to decrypt it. But gets below error when
IDP & SP directly connects.

org.opensaml.ws.security.SecurityPolicyException: Validation of protocol
message signature failed

at
org.opensaml.common.binding.security.SAMLProtocolMessageXMLSignatureSecurityPolicyRule.doEvaluate(SAMLProtocolMessageXMLSignatureSecurityPolicyRule.java:138)

at
org.opensaml.common.binding.security.SAMLProtocolMessageXMLSignatureSecurityPolicyRule.evaluate(SAMLProtocolMessageXMLSignatureSecurityPolicyRule.java:107)


Anyone faced such issues ? Any pointer on this will be very helpful.

Thanks in Advance.

Thanks,
Ramkumar Ramasubbu
CPS



On Thu, Oct 8, 2020 at 7:03 PM Alan Buxey <alan.buxey at myunidays.com> wrote:

> hi,
>
>> Just to verify, we tried to comment all the key sections in the SP Vendor
>> metadata file. Even then the SAML assertion was encrypted. That raised my
>> doubt if IDP's key is used to encrypt.
>>
>
> are you sure it wasnt still being signed ?
>
> alan
>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20201012/012f0c6d/attachment.htm>


More information about the users mailing list