Unknown or Unusable Identity Provider for Shib 3.2 SP

shibboleth.vse4h at simplelogin.com shibboleth.vse4h at simplelogin.com
Wed Jun 5 17:28:17 UTC 2024


Without making additional changes to the IdP, we're now actually able to trigger an authentication request from the SP. Rather than trying to understand that, I'd like to just move forward. We now have a saml response like **Missing certificate in metadata for 'https://development-service-provider'**. I've been looking at some documentation that suggests shibboleth signs by default with a self-signed keypair. We have in our shibboleth2.xml `<CredentialResolver type="File" key="cert/sp-key.pem" certificate="cert/sp-cert.pem"/>` which looks like it makes sense, as long as the paths to the cert and key are valid.



Sent with Proton Mail secure email.

On Wednesday, June 5th, 2024 at 9:29 AM, Cantor, Scott via users - users at shibboleth.net <users_at_shibboleth_net_uvbvr at simplelogin.co> wrote:

> Of course it's true also that if you have evidence of other SPs requesting your metadata in the logs, that suggests the absence of it from this SP would be meaningful.
> 
> But hoonestly, no, I can't see a way to connect from that to this error, so I guess you are rightly confused, but it doesn't change my conclusion. It's not possible to get the error ahead of an AuthnRequest being issued, when it had been working, unless the metadata on that end changed or expired (or something else unrelated broke and the timing was just hugely coincidental).
> 
> None of those guesses can be assessed without the SP logs and knowing how the metadata was managed and what state its in.
> 
> -- Scott
> 
> 
> --
> For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



More information about the users mailing list