Shibboleth SP saml assertion signature validation failure
Terry Zhou
terry.zhou at smartsheet.com
Wed Feb 1 16:00:40 UTC 2023
Posted it again.
Hey guys,
Our customer using adfs renewed their cert. After updating the their idp
metadata, we received the following error messages:
shibd.log:2023-01-27 18:29:50 WARN XMLTooling.Decrypter [5] [default]:
XMLSecurity exception while decrypting key: OpenSSL:RSA privateKeyDecrypt -
Error removing OAEPadding
shibd.log:2023-01-27 18:29:50 WARN OpenSAML.SecurityPolicyRule.XMLSigning
[5] [default]: unable to verify message signature with supplied trust engine
shibd.log:2023-01-27 18:29:50 WARN Shibboleth.SSO.SAML2 [5] [default]:
detected a problem with assertion: Message was signed, but signature could
not be verified.
shibd.log:2023-01-27 18:29:50 WARN Shibboleth.SSO.SAML2 [5] [default]:
error processing incoming assertion: Message was signed, but signature
could not be verified.
We used the "explicit key" as the trust engine, our shibboleth SP
is version 3.2.3-3.1.
We also verified everything based on
https://shibboleth.atlassian.net/wiki/spaces/SHIB2/pages/2577072495/NativeSPTroubleshootingCommonErrors#NativeSPTroubleshootingCommonErrors-Messagewassigned%2Cbutsignaturecouldnotbeverified.
Everything looks correct.
We noticed that our customer's public cert has a size of 2237, all our
other adfs customer's cert size is less than 2k, we suspected that might be
an issue.
Any help is much appreciated.
Thanks
Terry
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230201/db5486e2/attachment.htm>
More information about the users
mailing list