<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif; ">
<div>
<div>
<div>We are in the process of upgrading our systems from Red Hat EL5 to EL6 but are having problems authenticating to Google Apps. &nbsp;The error we are receiving is &quot;this account cannot be accessed because your credentials were not verified&quot;. &nbsp;This is supposedly
 due to issues with &quot;the private key used to sign the SAMLResponse does not match the public key certificate&quot;.</div>
<div><br>
</div>
<div>I brought over the entire&nbsp;/opt/shibboleth-idp directory structure from a functional system and thought I had Tomcat and Apache configured correctly but obviously have something configured incorrectly. &nbsp;Incidentally, the FQDN in the Shibboleth configuration
 is a CNAME which I change to go from our production system to the new system. &nbsp;I re-uploaded the public key from the new system without success. &nbsp;Also when I changed the CNAME back to the production system everything worked correctly without having to upload
 the public key.</div>
<div><br>
</div>
<div>Any ideas?</div>
<div>
<div><br>
</div>
<div><br>
</div>
<font face="Calibri,Verdana,Helvetica,Arial"><span style="font-size:11pt"><b>Mike Muzinich<br>
Network Security Administrator<br>
Los Rios Community College District<br>
<a href="mike.muzinich@losrios.edu">mike.muzinich@losrios.edu</a><br>
(916)568-3013</b></span></font></div>
</div>
</div>
</body>
</html>