<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=ISO-8859-15">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<div class="moz-text-flowed" style="font-family: -moz-fixed;
font-size: 14px;" lang="x-western">Hello everyone
<br>
it's been a while since my last post, i've read throught many
threads and searched on google but couldn't find anything
specifically related to this issue, so i'm begging for your help.
<br>
<br>
here is the point:
<br>
<br>
i'm following instructions provided an IdP service to set up
shibboleth to use the IdP for single sign on purposes.
<br>
<br>
i've followed everything accordingly but when it comes to login i
get this error in the debug log:
<br>
<br>
2012-03-16 02:10:26 DEBUG OpenSAML.MessageDecoder.SAML1 [1]:
extracting issuer from SAML 1.x Response
<br>
2012-03-16 02:10:26 DEBUG OpenSAML.MessageDecoder.SAML1 [1]:
response from (<a class="moz-txt-link-freetext"
href="https://idpcrl.crs.lombardia.it//scauth">https://idpcrl.crs.lombardia.it//scauth</a>)
<br>
2012-03-16 02:10:26 DEBUG OpenSAML.MessageDecoder.SAML1 [1]:
searching metadata for response issuer...
<br>
2012-03-16 02:10:26 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow
[1]: evaluating message flow policy (replay checking on,
expiration 60)
<br>
2012-03-16 02:10:26 DEBUG XMLTooling.StorageService [1]: inserted
record (_6419ffa3b558fbe3ccc83eed7a39910b) in context
(MessageFlow)
<br>
2012-03-16 02:10:26 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning
[1]: validating signature profile
<br>
2012-03-16 02:10:26 ERROR XMLTooling.KeyInfoResolver.Inline [1]:
caught XML-Security exception loading certificate: OpenSSL:X509 -
Error transating Base64 DER encoding into OpenSSL X509 structure
<br>
2012-03-16 02:10:26 ERROR XMLTooling.TrustEngine.PKIX [1]:
certificate name was not acceptable
<br>
2012-03-16 02:10:26 ERROR OpenSAML.SecurityPolicyRule.XMLSigning
[1]: unable to verify message signature with supplied trust engine
<br>
<br>
<br>
they say to specify the SAML file as follows: (used pastebin to
prevent flooding)
<br>
<br>
<a class="moz-txt-link-freetext"
href="http://pastebin.com/dpr00fcJ">http://pastebin.com/dpr00fcJ</a>
<br>
<br>
am i doing something wrong?
<br>
it's always been a pain with certificates and this IdP, and now
recently they decided it was time to chance up a bunch of things
and write their own documentation on how to set it up properly..
and obviously everything messed up <span class="moz-smiley-s2"
title=":("></span>
<br>
<br>
as i can understand there is something wrong in the trust engine?
maybe i have to set up something in shibboleth2.xml too?
<br>
<br>
thanks in advice for the help
<br>
best regards
<br>
Francesco
<br>
</div>
</body>
</html>