SAML encryption
Ramkumar Ramsubbu
ramkumar.ramsubbu.consultant at nielsen.com
Mon Oct 12 17:16:35 UTC 2020
Hi Steve,
Sorry, yes the issue is related to Signature validation.
We tried comparing the signing key in the saml response with the IDP
metadata signing key. It matches and also compared with the signing key
sent to SP. Both are matching.
Still we get this error.
Thanks,
Ramkumar Ramasubbu
CPS
On Mon, Oct 12, 2020 at 10:27 PM Mak, Steve <makst at upenn.edu> wrote:
> Ramkumar,
>
> > org.opensaml.ws.security.SecurityPolicyException: Validation of protocol
> message signature failed
> > at
> org.opensaml.common.binding.security.SAMLProtocolMessageXMLSignatureSecurityPolicyRule.doEvaluate(SAMLProtocolMessageXMLSignatureSecurityPolicyRule.java:138)
> > at
> org.opensaml.common.binding.security.SAMLProtocolMessageXMLSignatureSecurityPolicyRule.evaluate(SAMLProtocolMessageXMLSignatureSecurityPolicyRule.java:107)
>
> Correct me if I'm wrong but isn't this a signature validation failure and
> not related to encryption?
> Have you double-checked that you're using the same cert pair for IdP
> response or assertion signing that is in your IdP metadata file that was
> sent to the SP?
>
> - Steve
>
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20201012/56e8e9ee/attachment.htm>
More information about the users
mailing list