Thanks for the reply. I put the sp and idp in the same PC. And the sp was based on Apache while the idp was deployed on Tomcat. I generated a new keystore for tomcat's https port 8443, and the password is just "123456". I have specified the crt and key identical to the one in the metadata given to the sp just as below. <div>
<div> </div><div> <security:Credential id="IdPCredential" xsi:type="security:X509Filesystem"></div><div> <security:PrivateKey>/home/orbbyrp/shibboleth-idp/install/credentials/idp.key</security:PrivateKey></div>
<div> <security:Certificate>/home/orbbyrp/shibboleth-idp/install/credentials/idp.crt</security:Certificate></div><div> </security:Credential></div><div><br></div><div>
<div><br></div>-- <br><font color="#999999">Rupeng Yang</font><div><font color="#999999">Email: <a href="mailto:orbbyrp@gmail.com" target="_blank">orbbyrp@gmail.com</a></font></div><div><font color="#999999">site: <a href="http://orbbyrp.com" target="_blank">orbbyrp.com</a></font></div>
<div><span style="font-size:13px;font-family:arial,sans-serif"><font color="#cccccc"><div><font>School of Computer Science and Technology, <font>Shandong University</font></font></div><div>
<font>No.1500, Middle of Shunhua Road</font></div><div><font>Jinan 250101, Shandong, P.R.China</font></div></font></span></div><br>
</div>
</div>