Shibboleth SP saml assertion signature validation failure
Terry Zhou
terry.zhou at smartsheet.com
Fri Jan 27 22:34:55 UTC 2023
Hey guys,
Our customer using adfs renewed their cert. After updating the their idp
metadata, we received the following error messages:
shibd.log:2023-01-27 18:29:50 WARN XMLTooling.Decrypter [5] [default]:
XMLSecurity exception while decrypting key: OpenSSL:RSA privateKeyDecrypt -
Error removing OAEPadding
shibd.log:2023-01-27 18:29:50 WARN OpenSAML.SecurityPolicyRule.XMLSigning
[5] [default]: unable to verify message signature with supplied trust engine
shibd.log:2023-01-27 18:29:50 WARN Shibboleth.SSO.SAML2 [5] [default]:
detected a problem with assertion: Message was signed, but signature could
not be verified.
shibd.log:2023-01-27 18:29:50 WARN Shibboleth.SSO.SAML2 [5] [default]:
error processing incoming assertion: Message was signed, but signature
could not be verified.
We used the "explicit key" as the trust engine, our shibboleth SP
is version 3.2.3-3.1.
We noticed that our customer's public cert has a size of 2237, all our
other adfs customer's cert size is less than 2k, we suspected that might be
an issue.
Any help is much appreciated.
Thanks
Terry
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230127/8460fc90/attachment.htm>
More information about the users
mailing list