<html><head></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">One possible problem is that you are using http while sp is expecting https.<div><br><div><div>On 24 Apr 2012, at 10:15, 杨如鹏 wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite">Hello, everyone. I am really new to shibboleth, and now I am trying to configure a simple test system for &nbsp;shibboleth idp and sp. But there are some problems when the sp tries to get attribute from the idp. The related logs are here. The key in metadata to sp is the same as the content of idp.crt in idp. I do not how it comes. Can you help me? I will really appreciate of your help.&nbsp;<div>
Best wishes<br><div><br></div>
<div><div>2012-04-24 16:35:26 INFO Shibboleth.Application : building AttributeFilter of type XML...</div><div>2012-04-24 16:35:26 INFO Shibboleth.AttributeFilter : reload thread started...running when signaled</div><div>
2012-04-24 16:35:26 INFO Shibboleth.AttributeFilter : loaded XML resource (/home/orbbyrp/shibboleth-sp/etc/shibboleth/attribute-policy.xml)</div>
<div>2012-04-24 16:35:26 INFO Shibboleth.Application : building AttributeResolver of type Query...</div><div>2012-04-24 16:35:26 INFO Shibboleth.Application : building CredentialResolver of type File...</div><div>2012-04-24 16:35:26 INFO XMLTooling.SecurityHelper : loading private key from file (/home/orbbyrp/shibboleth-sp/etc/shibboleth/idp-key.pem)</div>

<div>2012-04-24 16:35:26 INFO XMLTooling.SecurityHelper : loading certificate(s) from file (/home/orbbyrp/shibboleth-sp/etc/shibboleth/idp-cert.pem)</div><div>2012-04-24 16:35:26 INFO Shibboleth.Listener : registered remoted message endpoint (default::getHeaders::Application)</div>

<div>2012-04-24 16:35:26 INFO Shibboleth.Listener : listener service starting</div><div>2012-04-24 16:35:38 ERROR XMLTooling.TrustEngine.PKIX [2]: certificate name was not acceptable</div><div>2012-04-24 16:35:38 ERROR XMLTooling.SOAPTransport.CURL [2]: supplied TrustEngine failed to validate SSL/TLS server certificate</div>

<div>2012-04-24 16:35:38 ERROR Shibboleth.AttributeResolver.Query [2]: exception during SAML query to <a href="https://example.com:8443/idp/profile/SAML2/SOAP/AttributeQuery" target="_blank">https://example.com:8443/idp/profile/SAML2/SOAP/AttributeQuery</a>: CURLSOAPTransport failed while contacting SOAP endpoint (<a href="https://example.com:8443/idp/profile/SAML2/SOAP/AttributeQuery" target="_blank">https://example.com:8443/idp/profile/SAML2/SOAP/AttributeQuery</a>): SSL certificate problem, verify that the CA cert is OK. Details:</div>

<div>error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed</div><div>2012-04-24 16:35:38 ERROR Shibboleth.AttributeResolver.Query [2]: unable to obtain a SAML response from attribute authority</div>

<div>2012-04-24 16:35:38 INFO Shibboleth.SessionCache [2]: new session created: ID (_2ae8bd4d424d19525b5edb52c78d2da5) IdP (<a href="https://example.com:8080/idp/shibboleth" target="_blank">https://example.com:8080/idp/shibboleth</a>) Protocol(urn:oasis:names:tc:SAML:2.0:protocol) Address (127.0.0.1)</div>

<div>2012-04-24 16:50:26 INFO XMLTooling.StorageService : purged 2 expired record(s) from storage</div>
<div><br></div>-- <br><font color="#999999">Rupeng Yang</font><div><font color="#999999">Email: <a href="mailto:orbbyrp@gmail.com" target="_blank">orbbyrp@gmail.com</a></font></div><div><font color="#999999">site: <a href="http://orbbyrp.com/" target="_blank">orbbyrp.com</a></font></div>



<div><span style="font-size:13px;font-family:arial,sans-serif"><font color="#cccccc"><div><font>School of Computer Science and Technology,&nbsp;<font>Shandong University</font></font></div><div>
<font>No.1500, Middle of Shunhua Road</font></div><div><font>Jinan 250101, Shandong, P.R.China</font></div></font></span></div><br>
</div>
</div>
--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></blockquote></div><br></div></body></html>