Message was signed, but signature could not be verified.
Goldberg, Arthur P
arthur.p.goldberg at mssm.edu
Mon Jul 11 18:21:12 UTC 2022
Thanks for the clarification, David.
I see a certificate at
IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<KeyDescriptor use="signing">
<KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
<X509Data>
<X509Certificate>...
which is close to your location.
Arthur
From: IAM David Bantz <dabantz at alaska.edu>
Date: Monday, July 11, 2022 at 1:57 PM
To: Shib Users <users at shibboleth.net>
Cc: "Goldberg, Arthur P" <arthur.p.goldberg at mssm.edu>
Subject: Re: Message was signed, but signature could not be verified.
USE CAUTION: External Message.
I expect the certificate public key for signed assertions from the IdP to be in (using same . convention):
EntityDescriptor.IDPSSODescriptor.KeyDescriptor use="signing”.X509 certificate
Signing key and signature at the EntityDescriptor level may be signing the IdP’s metadata.
On 11Jul2022 at 09:09:04, "Goldberg, Arthur P via users" <users at shibboleth.net<mailto:users at shibboleth.net>> wrote:
...
1. AzureIdPMetadata.xml contains a certificate, identified by the nested elements EntityDescriptor.Signature.KeyInfo.X509Data.X509Certificate (where the dot notation indicates nesting).
I’m simultaneously verifying with the IdP managers that this certificate in AzureIdPMetadata.xml is the IdP’s certificate which is used to communicate with my SP.
Running shibboleth 3.2.2.
Thanks
Arthur
--
Arthur Goldberg, PhD
Mount Sinai Data Warehouse<https://labs.icahn.mssm.edu/msdw/>
Scientific Computing and Data<https://labs.icahn.mssm.edu/minervalab/scientific-computing-and-data>
Associate Professor of Genetics and Genomic Sciences
Institute for Data Science and Genomic Technology
Mount Sinai School of Medicine
Arthur.Goldberg at mssm.edu<mailto:Arthur.Goldberg at mssm.edu>
646 526 5020
Zoom<https://urldefense.proofpoint.com/v2/url?u=https-3A__mssm.zoom.us_my_arthur.goldberg-3Fpwd-3DLzByMGJOZC9wM3A2aHV6OU94eUtSQT09&d=DwMFaQ&c=shNJtf5dKgNcPZ6Yh64b-A&r=ZCkl1RSA6OLXGMeLhWIeG8wvWwYPCSABQEpGFXsWEJg&m=Str7Z_PpQQue4GjHUXFDazpMS5_QMki7umi4qnm5WLI&s=Pdup8VTlJJfocgnjk11VB2p2dOn1_NTTXJSnrO4II2I&e=>
--
For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw<https://urldefense.proofpoint.com/v2/url?u=https-3A__shibboleth.atlassian.net_wiki_x_ZYEpPw&d=DwMFaQ&c=shNJtf5dKgNcPZ6Yh64b-A&r=ZCkl1RSA6OLXGMeLhWIeG8wvWwYPCSABQEpGFXsWEJg&m=Str7Z_PpQQue4GjHUXFDazpMS5_QMki7umi4qnm5WLI&s=kexg70s9xsVxRoul-6cwtjMLdMzH6XLLvkCuKEfWoFU&e=>
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220711/da17c7ed/attachment.htm>
More information about the users
mailing list