Message was signed, but signature could not be verified.
Nate Klingenstein
ndk at sudonym.me
Tue Jul 12 20:10:37 UTC 2022
Arthur,
Is this correct?
>
Yes.
> Given this, how does one DIRECTLY confirm that shibd is properly
> configured to verify messages sent by its configured IdP?
>
I'm not aware of any way to get it to output the certificate that it's
using for validation, though it might be doable on TRACE. But really,
that's trying much too hard.
You just need to make sure the entityID in the assertion matches the
entityID in the metadata and the key used to sign the assertion matches the
key for signature in the metadata loaded by the SP for that entityID.
That's it. If something doesn't match, fix it.
Hope this helps,
Nate
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220712/ec4d5775/attachment.htm>
More information about the users
mailing list