<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif; ">
<div>
<div>
<div>The problem was with the Tomcat 6 configuration. After I cloned the production Tomcat 5 configuration, everything works.</div>
<div>
<div><br>
</div>
<font face="Calibri,Verdana,Helvetica,Arial"><span style="font-size:11pt"><b>Mike Muzinich<br>
Network Security Administrator<br>
Los Rios Community College District<br>
<a href="mike.muzinich@losrios.edu">mike.muzinich@losrios.edu</a><br>
(916)568-3013</b></span></font></div>
</div>
</div>
<div><br>
</div>
<span id="OLK_SRC_BODY_SECTION">
<div style="font-family:Calibri; font-size:11pt; text-align:left; color:black; BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
<span style="font-weight:bold">From: </span><Cantor>, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>><br>
<span style="font-weight:bold">Reply-To: </span>Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<span style="font-weight:bold">Date: </span>Thursday, April 26, 2012 6:50 AM<br>
<span style="font-weight:bold">To: </span>Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<span style="font-weight:bold">Subject: </span>Re: Possible problem with key exchange<br>
</div>
<div><br>
</div>
<div>
<div>
<div>On 4/25/12 5:32 PM, "Muzinich, Mike" <<a href="mailto:MuziniM@losrios.edu">MuziniM@losrios.edu</a>> wrote:</div>
<div><br>
</div>
<blockquote id="MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style="BORDER-LEFT: #b5c4df 5 solid; PADDING:0 0 0 5; MARGIN:0 0 0 5;">
<div>I brought over the entire /opt/shibboleth-idp directory structure from a</div>
<div>functional system and thought I had Tomcat and Apache configured</div>
<div>correctly but obviously have something configured incorrectly.</div>
</blockquote>
<div><br>
</div>
<div>The only place that would matter is the IdP itself, what credential it's</div>
<div>using to sign. There's no TLS involved. But I have no idea what Google</div>
<div>does to evaluate the key. If it does a public key compare, it should work.</div>
<div>If it does more with the cert...</div>
<div><br>
</div>
<blockquote id="MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style="BORDER-LEFT: #b5c4df 5 solid; PADDING:0 0 0 5; MARGIN:0 0 0 5;">
<div> Incidentally, the FQDN in the Shibboleth configuration</div>
<div>is a CNAME which I change to go from our production system to the new</div>
<div>system.</div>
</blockquote>
<div><br>
</div>
<div>That suggests they are doing more with the cert.</div>
<div><br>
</div>
<div>-- Scott</div>
<div><br>
</div>
<div>--</div>
<div>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a></div>
<div><br>
</div>
</div>
</div>
</span>
</body>
</html>