Error: Message was signed, but signature could not be verified.
Goldberg, Arthur P
arthur.p.goldberg at mssm.edu
Tue May 25 19:27:48 UTC 2021
Thanks again Nate.
I found a helpful article on Azure AD SAML federation using Shibboleth SP<https://rohanislam2.medium.com/azure-ad-saml-federation-using-shibboleth-sp-ad40f9c94eab>. Based on its recipe I had the Azure folks re-issue me a metadata file for the Azure identity provider. That resolved the problem below and got SSO working!
Regards
Arthur
On 5/24/21, 7:56 PM, "users on behalf of Nate Klingenstein" <users-bounces at shibboleth.net on behalf of ndk at signet.id> wrote:
USE CAUTION: External Message.
Arthur,
Shibboleth treats the certificate as a bag for a public key and little more. Trust is based on metadata. The private key that is being used to sign messages from the IdP doesn't match any valid public key in the IdP's metadata as loaded by the SP.
https://urldefense.proofpoint.com/v2/url?u=https-3A__samltest.id_faq_&d=DwICAg&c=shNJtf5dKgNcPZ6Yh64b-A&r=ZCkl1RSA6OLXGMeLhWIeG8wvWwYPCSABQEpGFXsWEJg&m=o-Njom8BS94HvUtNepTBW2KxAcTZVEk4DWdoQ67zHcM&s=v_X52L1sK94AzXzf-ih1UfYOUHHXvQh8o2a69UffwCw&e=
Take care,
Nate.
--
For Consortium Member technical support, see https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwICAg&c=shNJtf5dKgNcPZ6Yh64b-A&r=ZCkl1RSA6OLXGMeLhWIeG8wvWwYPCSABQEpGFXsWEJg&m=o-Njom8BS94HvUtNepTBW2KxAcTZVEk4DWdoQ67zHcM&s=bVZ3f49z_ZpjTbAL7UWn9g5atVkM0YSFneQlffABa-Q&e=
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210525/cd3d96c6/attachment.htm>
More information about the users
mailing list