Error: Simple signature validation (with no request-derived credentials) failed
Cantor, Scott
cantor.2 at osu.edu
Fri Mar 25 15:39:18 UTC 2022
On 3/25/22, 11:14 AM, "users on behalf of Ryan Rumbaugh via users" <users-bounces at shibboleth.net on behalf of users at shibboleth.net> wrote:
> Hi all, I’m working with a vendor (Critical Labs) to try and determine why I’m getting the following exception.
> Searching the list, I think this occurs when a SP signs an authn request with a different key than what is in
> metadata. According to the vendor that is not the case,
I would assume the vendor's wrong.
> and FWIW I used the SAML authn request validator at https://www.samltool.com/validate_authn_req.php
> and it checks out.
Perhaps the metadata is wrong but you're pulling the key artificially in some way for the test. Maybe it's marked use="encryption". Or maybe that's not the metadata the IdP is using.
-- Scott
More information about the users
mailing list