ERROR OpenSSL : error code: 151584876 in ../crypto/pem/pem_lib.c, line 745 for SP Signing Certificate

Bhagwat, Shrikant shrbhagw at med.umich.edu
Mon Nov 28 19:27:32 UTC 2022


Hello


root at dep-capture-7cd6b577b8-df96z:/etc/shibboleth# cat /var/log/shibboleth/shibd.log
2022-11-28 18:58:49 INFO XMLTooling.Config : xmltooling 3.0.4 library initialization complete
2022-11-28 18:58:49 INFO OpenSAML.Config : opensaml 3.0.1 library initialization complete
2022-11-28 18:58:49 INFO Shibboleth.Config : shibboleth 3.0.4 library initialization complete
2022-11-28 18:58:49 INFO Shibboleth.Config : loaded XML resource (/etc/shibboleth/shibboleth2.xml)
2022-11-28 18:58:49 INFO Shibboleth.Config : Shibboleth SP Version 3.0.4
2022-11-28 18:58:49 INFO Shibboleth.Config : Library versions: log4shib 2.0.0, Xerces-C 3.2.2, XML-Security-C 2.0.2, XMLTooling-C 3.0.4, OpenSAML-C 3.0.1, Shibboleth 3.0.4
2022-11-28 18:58:49 INFO Shibboleth.Config : building ListenerService of type UnixListener...
2022-11-28 18:58:49 INFO Shibboleth.Listener : using socket address: shibd.sock
2022-11-28 18:58:49 INFO Shibboleth.Config : no StorageService plugin(s) installed, using (mem) in-memory instance
2022-11-28 18:58:49 INFO Shibboleth.Config : no ReplayCache specified, using arbitrary StorageService instance
2022-11-28 18:58:49 INFO Shibboleth.Config : no ArtifactMap specified, building in-memory ArtifactMap...
2022-11-28 18:58:49 INFO Shibboleth.Config : no SessionCache specified, using StorageService-backed instance
2022-11-28 18:58:49 INFO XMLTooling.StorageService : cleanup thread started...running every 900 seconds
2022-11-28 18:58:49 INFO Shibboleth.SessionCache : bound to arbitrary StorageService
2022-11-28 18:58:49 INFO Shibboleth.SessionCache : StorageService for 'lite' use not set, using standard StorageService
2022-11-28 18:58:49 INFO Shibboleth.Config : building SecurityPolicyProvider of type XML...
2022-11-28 18:58:49 INFO Shibboleth.SecurityPolicyProvider.XML : loaded XML resource (/etc/shibboleth/security-policy.xml)
2022-11-28 18:58:49 INFO OpenSAML.SecurityPolicyRule.Conditions : building SecurityPolicyRule of type Audience
2022-11-28 18:58:49 INFO OpenSAML.SecurityPolicyRule.Conditions : building SecurityPolicyRule of type Audience
2022-11-28 18:58:49 INFO OpenSAML.SecurityPolicyRule.Conditions : building SecurityPolicyRule of type Ignore
2022-11-28 18:58:49 INFO OpenSAML.SecurityPolicyRule.Conditions : building SecurityPolicyRule of type Ignore
2022-11-28 18:58:49 INFO OpenSAML.SecurityPolicyRule.Conditions : building SecurityPolicyRule of type Ignore
2022-11-28 18:58:49 INFO Shibboleth.Config : automatically blacklisting security algorithm (http://www.w3.org/2001/04/xmldsig-more#rsa-md5)
2022-11-28 18:58:49 INFO Shibboleth.Config : automatically blacklisting security algorithm (http://www.w3.org/2001/04/xmldsig-more#md5)
2022-11-28 18:58:49 INFO Shibboleth.Config : automatically blacklisting security algorithm (http://www.w3.org/2001/04/xmlenc#rsa-1_5)
2022-11-28 18:58:49 INFO Shibboleth.Config : building ProtocolProvider of type XML...
2022-11-28 18:58:49 INFO Shibboleth.ProtocolProvider.XML : loaded XML resource (/etc/shibboleth/protocols.xml)
2022-11-28 18:58:49 INFO Shibboleth.Application : auto-configuring SSO initiation for protocol (SAML2)
2022-11-28 18:58:49 INFO Shibboleth.Application : adding SessionInitiator of type (SAML2) to chain (/Login)
2022-11-28 18:58:49 INFO Shibboleth.Application : auto-configuring ArtifactResolution endpoints for protocol (SAML2)
2022-11-28 18:58:49 INFO Shibboleth.Application : adding ArtifactResolutionService for Binding (urn:oasis:names:tc:SAML:2.0:bindings:SOAP) at (/Artifact/SOAP)
2022-11-28 18:58:49 INFO Shibboleth.Application : auto-configuring SSO endpoints for protocol (SAML2)
2022-11-28 18:58:49 INFO Shibboleth.Application : adding AssertionConsumerService for Binding (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST) at (/SAML2/POST)
2022-11-28 18:58:49 INFO Shibboleth.Application : adding AssertionConsumerService for Binding (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign) at (/SAML2/POST-SimpleSign)
2022-11-28 18:58:49 INFO Shibboleth.Application : adding AssertionConsumerService for Binding (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact) at (/SAML2/Artifact)
2022-11-28 18:58:49 INFO Shibboleth.Application : adding AssertionConsumerService for Binding (urn:oasis:names:tc:SAML:2.0:bindings:PAOS) at (/SAML2/ECP)
2022-11-28 18:58:49 INFO Shibboleth.Application : adding SessionInitiator of type (SAMLDS) to chain (/Login)
2022-11-28 18:58:49 INFO Shibboleth.Application : auto-configuring Logout initiation for protocol (SAML2)
2022-11-28 18:58:49 INFO Shibboleth.Application : adding LogoutInitiator of type (SAML2) to chain (/Logout)
2022-11-28 18:58:49 INFO Shibboleth.Application : auto-configuring Logout endpoints for protocol (SAML2)
2022-11-28 18:58:49 INFO Shibboleth.Application : adding SingleLogoutService for Binding (urn:oasis:names:tc:SAML:2.0:bindings:SOAP) at (/SLO/SOAP)
2022-11-28 18:58:49 INFO Shibboleth.Application : adding SingleLogoutService for Binding (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect) at (/SLO/Redirect)
2022-11-28 18:58:49 INFO Shibboleth.Application : adding SingleLogoutService for Binding (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST) at (/SLO/POST)
2022-11-28 18:58:49 INFO Shibboleth.Application : adding SingleLogoutService for Binding (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact) at (/SLO/Artifact)
2022-11-28 18:58:49 INFO Shibboleth.Application : auto-configuring Logout initiation for protocol (Local)
2022-11-28 18:58:49 INFO Shibboleth.Application : adding LogoutInitiator of type (Local) to chain (/Logout)
2022-11-28 18:58:49 INFO Shibboleth.Handler.DiscoveryFeed : feed files will be cached in /var/cache/shibboleth/
2022-11-28 18:58:49 INFO Shibboleth.Application : building MetadataProvider of type XML...
2022-11-28 18:58:49 INFO OpenSAML.MetadataProvider : building MetadataFilter of type Signature
2022-11-28 18:58:49 INFO XMLTooling.CredentialResolver.Chaining : building CredentialResolver of type File
2022-11-28 18:58:49 INFO XMLTooling.SecurityHelper : loading certificate(s) from file (/etc/shibboleth/p-weblogin_med_umich_edu_cert-FullChain.pem)
2022-11-28 18:58:49 INFO XMLTooling.CredentialResolver.File : no private key resolved, usable for verification/trust only
2022-11-28 18:58:49 INFO OpenSAML.MetadataProvider.XML : loaded XML resource (https://p-weblogin.med.umich.edu/nidp/saml2/metadata)
2022-11-28 18:58:49 INFO OpenSAML.MetadataProvider : applying metadata filter (Signature)
2022-11-28 18:58:49 INFO OpenSAML.MetadataProvider.XML : adjusted reload interval to 7200 seconds
2022-11-28 18:58:49 INFO Shibboleth.Application : no TrustEngine specified or installed, using default of ExplicitKey
2022-11-28 18:58:49 INFO Shibboleth.Application : building AttributeExtractor of type XML...
2022-11-28 18:58:49 INFO Shibboleth.AttributeExtractor.XML : loaded XML resource (/etc/shibboleth/attribute-map.xml)
2022-11-28 18:58:49 INFO Shibboleth.AttributeExtractor.XML : creating mapping for Attribute urn:oasis:names:tc:SAML:attribute:subject-id
2022-11-28 18:58:49 INFO Shibboleth.AttributeExtractor.XML : creating mapping for Attribute urn:oasis:names:tc:SAML:attribute:pairwise-id
2022-11-28 18:58:49 INFO Shibboleth.AttributeExtractor.XML : creating mapping for Attribute urn:oid:1.3.6.1.4.1.5923.1.1.1.6
2022-11-28 18:58:49 INFO Shibboleth.AttributeExtractor.XML : creating mapping for Attribute urn:mace:dir:attribute-def:eduPersonPrincipalName
2022-11-28 18:58:49 INFO Shibboleth.AttributeExtractor.XML : creating mapping for Attribute urn:oid:1.3.6.1.4.1.5923.1.1.1.9
2022-11-28 18:58:49 INFO Shibboleth.AttributeExtractor.XML : creating mapping for Attribute urn:mace:dir:attribute-def:eduPersonScopedAffiliation
2022-11-28 18:58:49 INFO Shibboleth.AttributeExtractor.XML : creating mapping for Attribute urn:oid:1.3.6.1.4.1.5923.1.1.1.7
2022-11-28 18:58:49 INFO Shibboleth.AttributeExtractor.XML : creating mapping for Attribute urn:mace:dir:attribute-def:eduPersonEntitlement
2022-11-28 18:58:49 INFO Shibboleth.AttributeExtractor.XML : creating mapping for Attribute urn:oid:1.3.6.1.4.1.5923.1.1.1.10
2022-11-28 18:58:49 INFO Shibboleth.AttributeExtractor.XML : creating mapping for Attribute urn:oasis:names:tc:SAML:2.0:nameid-format:persistent
2022-11-28 18:58:49 INFO Shibboleth.AttributeExtractor.XML : creating mapping for Attribute surname
2022-11-28 18:58:49 INFO Shibboleth.AttributeExtractor.XML : creating mapping for Attribute displayname
2022-11-28 18:58:49 INFO Shibboleth.AttributeExtractor.XML : creating mapping for Attribute uniquename
2022-11-28 18:58:49 INFO Shibboleth.AttributeExtractor.XML : creating mapping for Attribute phonenumber
2022-11-28 18:58:49 INFO Shibboleth.AttributeExtractor.XML : creating mapping for Attribute email
2022-11-28 18:58:49 INFO Shibboleth.Application : building AttributeFilter of type XML...
2022-11-28 18:58:49 INFO Shibboleth.AttributeFilter : loaded XML resource (/etc/shibboleth/attribute-policy.xml)
2022-11-28 18:58:49 INFO Shibboleth.Application : multiple CredentialResolver plugins, wrapping in a chain
2022-11-28 18:58:49 INFO Shibboleth.Application : building CredentialResolver of type Chaining...
2022-11-28 18:58:49 INFO XMLTooling.CredentialResolver.Chaining : building CredentialResolver of type File
2022-11-28 18:58:49 INFO XMLTooling.SecurityHelper : loading private key from file (/etc/shibboleth/sp-signing-key.pem)
2022-11-28 18:58:49 INFO XMLTooling.SecurityHelper : loading certificate(s) from file (/etc/shibboleth/sp-signing-key.pem)
2022-11-28 18:58:49 ERROR OpenSSL : error code: 151584876 in ../crypto/pem/pem_lib.c, line 745
2022-11-28 18:58:49 ERROR OpenSSL : error data: Expecting: CERTIFICATE
2022-11-28 18:58:49 ERROR XMLTooling.CredentialResolver.Chaining : caught exception processing embedded CredentialResolver element: Unable to load certificate(s) from file (/etc/shibboleth/sp-signing-key.pem).
2022-11-28 18:58:49 INFO XMLTooling.CredentialResolver.Chaining : building CredentialResolver of type File
2022-11-28 18:58:49 INFO XMLTooling.SecurityHelper : loading private key from file (/etc/shibboleth/sp-encrypt-key.pem)
2022-11-28 18:58:49 INFO XMLTooling.SecurityHelper : loading certificate(s) from file (/etc/shibboleth/sp-encrypt-key.pem)
2022-11-28 18:58:49 ERROR OpenSSL : error code: 151584876 in ../crypto/pem/pem_lib.c, line 745
2022-11-28 18:58:49 ERROR OpenSSL : error data: Expecting: CERTIFICATE
2022-11-28 18:58:49 ERROR XMLTooling.CredentialResolver.Chaining : caught exception processing embedded CredentialResolver element: Unable to load certificate(s) from file (/etc/shibboleth/sp-encrypt-key.pem).
2022-11-28 18:58:49 INFO Shibboleth.Listener : listener service starting


Any Idea ?


SB
**********************************************************
Electronic Mail is not secure, may not be read every day, and should not be used for urgent or sensitive issues 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20221128/0362cd16/attachment.htm>


More information about the users mailing list