Message was signed, but signature could not be verified.
IAM David Bantz
dabantz at alaska.edu
Mon Jul 11 17:57:25 UTC 2022
I expect the certificate public key for signed assertions from the IdP to
be in (using same . convention):
EntityDescriptor.IDPSSODescriptor.KeyDescriptor use="signing”.X509
certificate
Signing key and signature at the EntityDescriptor level may be signing the
IdP’s metadata.
On 11Jul2022 at 09:09:04, "Goldberg, Arthur P via users" <
users at shibboleth.net> wrote:
> ...
>
> 1. AzureIdPMetadata.xml contains a certificate, identified by the
> nested elements EntityDescriptor.Signature.KeyInfo.X509Data.X509Certificate
> (where the dot notation indicates nesting).
>
>
>
> I’m simultaneously verifying with the IdP managers that this certificate
> in AzureIdPMetadata.xml is the IdP’s certificate which is used to
> communicate with my SP.
>
>
>
> Running shibboleth 3.2.2.
>
>
>
> Thanks
>
> Arthur
>
>
>
>
>
> --
>
> Arthur Goldberg, PhD
>
> Mount Sinai Data Warehouse <https://labs.icahn.mssm.edu/msdw/>
>
> Scientific Computing and Data
> <https://labs.icahn.mssm.edu/minervalab/scientific-computing-and-data>
>
> Associate Professor of Genetics and Genomic Sciences
> Institute for Data Science and Genomic Technology
> Mount Sinai School of Medicine
>
>
>
> Arthur.Goldberg at mssm.edu
>
> 646 526 5020
> Zoom
> <https://mssm.zoom.us/my/arthur.goldberg?pwd=LzByMGJOZC9wM3A2aHV6OU94eUtSQT09>
>
>
> --
> For Consortium Member technical support, see
> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220711/f64f6e6c/attachment.htm>
More information about the users
mailing list