Issue with consent configuration with IdP v5

Erwan Colin erwan.colin at mines-albi.fr
Fri May 17 09:59:48 UTC 2024


Hi,

we have functional IdP v5 without consent and now we wish to implement consent (https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199509862/ConsentConfiguration) with the most simple case to 
start with.

1. We enabled module
2. Set the Default relying party configuration (https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199509862/ConsentConfiguration#Default-relying-party-configuration)

We indeed have view with consent choices display after authentication (service with SP -> our IdpV5 -> our CAS -> Consent view) and after clicking on button "Accept" the following message is displayed :

opensaml::SecurityPolicyException at (https://exampleSP/Shibboleth.sso/SAML2/POST) Message was signed, but signature could not be verified. We have this message with several SP from several federation.

Has one of you faced this issue?

-- 
Erwan Colin
Ingénieur système/System engineer
IMT Mines Albi
🖁 +33 754 369 060
☎ +33 563 493 356
🚪 0A20

-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_0xF2710398C58BD857.asc
Type: application/pgp-keys
Size: 3139 bytes
Desc: OpenPGP public key
URL: <http://shibboleth.net/pipermail/users/attachments/20240517/10f927f5/attachment.bin>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <http://shibboleth.net/pipermail/users/attachments/20240517/10f927f5/attachment.sig>


More information about the users mailing list