signature verification issues
Nate Klingenstein
ndk at signet.id
Thu Apr 22 17:48:26 UTC 2021
Rene,
Login was successful, but when your IdP went to sign a response or an assertion and send it back to SAMLtest, that signature was invalid when it was evaluated. That could be because the key in the metadata you've uploaded to SAMLtest doesn't match the key that you're using for signing, which is by far the most likely explanation, or it could hypothetically be because of a bug in the signing code, but since you're using 4.1 of a known working implementation, that pretty much narrows it down to a key mismatch.
You can replace your metadata on SAMLtest at any time by uploading new metadata with the same entityID and waiting for a few minutes for all caches to clear.
Take care,
Nate.
--------
Signet, Inc.
The Art of Access ®
https://www.signet.id
-----Original message-----
From: Rene Paquin
Sent: Thursday, April 22 2021, 8:26 am
To: users at shibboleth.net
Subject: signature verification issues
With version 4.1 I am testing my SSO with samltest.id. When I attempt to authenticate using samltest I get errors:
2021-04-22 14:15:14 WARN OpenSAML.SecurityPolicyRule.XMLSigning [28388] [default]: unable to verify message signature with supplied trust engine
2021-04-22 14:15:14 WARN Shibboleth.SSO.SAML2 [28388] [default]: error processing incoming assertion: Message was signed, but signature could
not be verified
However in the idp logs it shows as successful
2021-04-22 10:15:12,785 - 192.168.1.1 - INFO [net.shibboleth.idp.authn.impl.LDAPCredentialValidator:163] - Credential Validator ldap: Login by 'rpaquin' succeeded
2021-04-22 10:15:13,799 - 192.168.1.1 - INFO [Shibboleth-Audit.SSO:283] - 192.168.1.1|2021-04-22T14:14:55.457547Z|2021-04-22T14:15:13.798645Z|rpaquin|https://samltest.id/saml/sp|_67ac3b88ddb2917757522c022381f3dc|password|2021-04-22T14:15:12.792028Z|uid|AAdzZWNyZXQxKIj6lHLOoY9vnC21XDbpxX8bgXF2QylAUmBU/D9G0xFFJn5QR8AenBbNt5u7o8vNMiBXVEtzDd3aGD6iZJOz60QZ4EW5oXugd+NeUCSPaO4VSqDQ7c3x0IYguLpQVA==|transient|false|false|AES128-GCM|Redirect|POST||Success||23e72cc82baf28d7bdac7625341d18169a3dcfed990f90c8e908e67f07d63403|Mozilla/5.0
(Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36
So does this issue lie with the IDP or with the samlTest SP?
********************************
Rene Paquin - Systems Administrator
Wilfrid Laurier University
Waterloo, Ontario
(519)884-0710 x3795
rpaquin at wlu.ca <mailto:rpaquin at wlu.ca>
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list