<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=ISO-8859-15">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-text-flowed" style="font-family: -moz-fixed;
      font-size: 14px;" lang="x-western">Hello everyone
      <br>
      it's been a while since my last post, i've read throught many
      threads and searched on google but couldn't find anything
      specifically related to this issue, so i'm begging for your help.
      <br>
      <br>
      here is the point:
      <br>
      <br>
      i'm following instructions provided an IdP service to set up
      shibboleth to use the IdP for single sign on purposes.
      <br>
      <br>
      i've followed everything accordingly but when it comes to login i
      get this error in the debug log:
      <br>
      <br>
      2012-03-16 02:10:26 DEBUG OpenSAML.MessageDecoder.SAML1 [1]:
      extracting issuer from SAML 1.x Response
      <br>
      2012-03-16 02:10:26 DEBUG OpenSAML.MessageDecoder.SAML1 [1]:
      response from (<a class="moz-txt-link-freetext"
        href="https://idpcrl.crs.lombardia.it//scauth">https://idpcrl.crs.lombardia.it//scauth</a>)
      <br>
      2012-03-16 02:10:26 DEBUG OpenSAML.MessageDecoder.SAML1 [1]:
      searching metadata for response issuer...
      <br>
      2012-03-16 02:10:26 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow
      [1]: evaluating message flow policy (replay checking on,
      expiration 60)
      <br>
      2012-03-16 02:10:26 DEBUG XMLTooling.StorageService [1]: inserted
      record (_6419ffa3b558fbe3ccc83eed7a39910b) in context
      (MessageFlow)
      <br>
      2012-03-16 02:10:26 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning
      [1]: validating signature profile
      <br>
      2012-03-16 02:10:26 ERROR XMLTooling.KeyInfoResolver.Inline [1]:
      caught XML-Security exception loading certificate: OpenSSL:X509 -
      Error transating Base64 DER encoding into OpenSSL X509 structure
      <br>
      2012-03-16 02:10:26 ERROR XMLTooling.TrustEngine.PKIX [1]:
      certificate name was not acceptable
      <br>
      2012-03-16 02:10:26 ERROR OpenSAML.SecurityPolicyRule.XMLSigning
      [1]: unable to verify message signature with supplied trust engine
      <br>
      <br>
      <br>
      they say to specify the SAML file as follows: (used pastebin to
      prevent flooding)
      <br>
      <br>
      <a class="moz-txt-link-freetext"
        href="http://pastebin.com/dpr00fcJ">http://pastebin.com/dpr00fcJ</a>
      <br>
      <br>
      am i doing something wrong?
      <br>
      it's always been a pain with certificates and this IdP, and now
      recently they decided it was time to chance up a bunch of things
      and write their own documentation on how to set it up properly..
      and obviously everything messed up <span class="moz-smiley-s2"
        title=":("></span>
      <br>
      <br>
      as i can understand there is something wrong in the trust engine?
      maybe i have to set up something in shibboleth2.xml too?
      <br>
      <br>
      thanks in advice for the help
      <br>
      best regards
      <br>
      Francesco
      <br>
    </div>
  </body>
</html>