detected a problem with assertion: Unable to establish security of incoming assertion.

George Maynard George.Maynard at ltimindtree.com
Mon Oct 7 20:18:03 UTC 2024


Thanks for the information, they had to change some of the settings on the IDP and I was able to get past the assertion issue. However now I am getting the below but there is nothing listed in the log and its set to debug

opensaml::SecurityPolicyException
The system encountered an error at Mon Oct 7 12:50:33 2024

To report this problem, please contact the site administrator at root at localhost.

Please include the following message in any email:

opensaml::SecurityPolicyException at (https://mysite.com/reports/asp/)

Attempt to spoof header (HTTP_SHIBSESSIONID:) was detected.

Regards & Thanks!

-----Original Message-----
From: Cantor, Scott <cantor.2 at osu.edu>
Sent: September 30, 2024 2:57 PM
To: Shib Users <users at shibboleth.net>
Cc: George Maynard <George.Maynard at ltimindtree.com>
Subject: Re: detected a problem with assertion: Unable to establish security of incoming assertion.

Caution - This email is from an external source. Please do not click on links or attachments if sender is unknown or from known person but the content is unusual. Never share your user ID or password under any circumstances.


> Thanks for the information, do you know what I should be looking for
> in the metadata?

Most likely it's the wrong public key in the metadata compared to whatever the IdP is actually signing with, but you don't have to guess. Look at the log.

In the extremely unlikely case that there's nothing else but a complaint about HTTP method in there, then the AssertionConsumerService element in the metadata could have the wrong binding constant, perhaps specifying HTTP-Redirect instead of HTTP-POST.

-- Scott



________________________________

The contents of this e-mail and any attachment(s) may contain confidential or privileged information for the intended recipient(s). Unintended recipients are prohibited from taking action on the basis of information in this e-mail and using or disseminating the information, and must notify the sender and delete it from their system. LTIMindtree will not accept responsibility or liability for the accuracy or completeness of, or the presence of any virus or disabling code in this e-mail.


More information about the users mailing list