<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif; ">
<div>
<div>
<div>We are in the process of upgrading our systems from Red Hat EL5 to EL6 but are having problems authenticating to Google Apps. The error we are receiving is "this account cannot be accessed because your credentials were not verified". This is supposedly
due to issues with "the private key used to sign the SAMLResponse does not match the public key certificate".</div>
<div><br>
</div>
<div>I brought over the entire /opt/shibboleth-idp directory structure from a functional system and thought I had Tomcat and Apache configured correctly but obviously have something configured incorrectly. Incidentally, the FQDN in the Shibboleth configuration
is a CNAME which I change to go from our production system to the new system. I re-uploaded the public key from the new system without success. Also when I changed the CNAME back to the production system everything worked correctly without having to upload
the public key.</div>
<div><br>
</div>
<div>Any ideas?</div>
<div>
<div><br>
</div>
<div><br>
</div>
<font face="Calibri,Verdana,Helvetica,Arial"><span style="font-size:11pt"><b>Mike Muzinich<br>
Network Security Administrator<br>
Los Rios Community College District<br>
<a href="mike.muzinich@losrios.edu">mike.muzinich@losrios.edu</a><br>
(916)568-3013</b></span></font></div>
</div>
</div>
</body>
</html>