<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from rtf -->
<style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<font face="Arial, sans-serif" size="2">
<div>Hi,</div>
<div><font face="FuturaA Bk BT, sans-serif" size="2">&nbsp;</font></div>
<div>I use this systems in a Shibooleth environment:</div>
<div><font face="FuturaA Bk BT, sans-serif" size="2">&nbsp;</font></div>
<div style="padding-left: 36pt; ">Shibooleth IDP 1.3 running in Solaris 10 server</div>
<div style="padding-left: 36pt; ">Shibooleth SP running in apache and RH 5.3 Linux</div>
<div><font face="FuturaA Bk BT, sans-serif" size="2">&nbsp;</font></div>
<div>Authentication and profile exchange between IDP and SP works fine, but time to time SP client refuse to accept IDP certificate: </div>
<div><font face="FuturaA Bk BT, sans-serif" size="2">&nbsp;</font></div>
<div>2012-06-26 12:29:49 DEBUG XMLTooling.SOAPTransport.CURL [91]: sending SOAP message to
<a href="https://10.122.4.76:7122/coi-idp/AA">https://10.122.4.76:7122/coi-idp/AA</a></div>
<div>2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: About to connect() to 10.122.4.76 port 7122</div>
<div>2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]:&nbsp;&nbsp; Trying 10.122.4.76... </div>
<div>2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: connected</div>
<div>2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: Connected to 10.122.4.76 (10.122.4.76) port 7122</div>
<div>2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: successfully set certificate verify locations:</div>
<div>2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]:&nbsp;&nbsp; CAfile: /etc/pki/tls/certs/ca-bundle.crt CApath: none</div>
<div>2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: SSL re-using session ID</div>
<div>2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: SSLv3, TLS handshake, Client hello (1):</div>
<div>2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: SSLv3, TLS handshake, Server hello (2):</div>
<div>2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: SSLv3, TLS handshake, CERT (11):</div>
<div>2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: <br>

2012-06-26 12:29:49 DEBUG XMLTooling.SOAPTransport.CURL [91]: invoking custom X.509 verify callback</div>
<div>2012-06-26 12:29:49 DEBUG XMLTooling.TrustEngine.ExplicitKey [91]: attempting to match credentials from peer with end-entity certificate</div>
<div>2012-06-26 12:29:49 DEBUG XMLTooling.TrustEngine.ExplicitKey [91]: no keys within this peer's key information matched the given end-entity certificate</div>
<div>2012-06-26 12:29:49 DEBUG XMLTooling.TrustEngine.PKIX [91]: performing certificate path validation...</div>
<div>2012-06-26 12:29:49 DEBUG XMLTooling.TrustEngine.PKIX [91]: failed to validate certificate chain using supplied PKIX information</div>
<div>2012-06-26 12:29:49 ERROR XMLTooling.SOAPTransport.CURL [91]: supplied TrustEngine failed to validate SSL/TLS server certificate</div>
<div>2012-06-26 12:29:49 DEBUG XMLTooling.libcurl [91]: SSLv3, TLS alert, Server hello (2):</div>
<div><font face="FuturaA Bk BT, sans-serif" size="2">&nbsp;</font></div>
<div><font face="FuturaA Bk BT, sans-serif" size="2">&nbsp;</font></div>
<div>I&#8217;m sure that certificate are ok, because most of the time SP accept it without any complains:</div>
<div>&nbsp;</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.SOAPTransport.CURL [86]: sending SOAP message to
<a href="https://10.122.4.76:7122/coi-idp/AA">https://10.122.4.76:7122/coi-idp/AA</a></div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: Connection 0 seems to be dead!</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: Closing connection #0</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: About to connect() to 10.122.4.76 port 7122</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]:&nbsp;&nbsp; Trying 10.122.4.76... </div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: connected</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: Connected to 10.122.4.76 (10.122.4.76) port 7122</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: successfully set certificate verify locations:</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]:&nbsp;&nbsp; CAfile: /etc/pki/tls/certs/ca-bundle.crt&nbsp; CApath: none</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSL re-using session ID</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS handshake, Client hello (1):</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS handshake, Server hello (2):</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS handshake, CERT (11):</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: <br>

2012-06-26 12:13:28 DEBUG XMLTooling.SOAPTransport.CURL [86]: invoking custom X.509 verify callback</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.TrustEngine.ExplicitKey [86]: attempting to match credentials from peer with end-entity certificate</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.TrustEngine.ExplicitKey [86]: end-entity certificate matches peer RSA key information</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS handshake, Server key exchange (12):</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: 2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS handshake, Server finished (14):</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS handshake, Client key exchange (16):</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS change cipher, Client hello (1):</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS handshake, Finished (20):</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS change cipher, Client hello (1):</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSLv3, TLS handshake, Finished (20):</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: SSL connection using DHE-RSA-AES256-SHA</div>
<div>2012-06-26 12:13:28 DEBUG XMLTooling.libcurl [86]: Server certificate:</div>
<div><font face="FuturaA Bk BT, sans-serif" size="2">&nbsp;</font></div>
<div>Both server use NTP server to avoid time differences between servers.</div>
<div>&nbsp;</div>
<div>Any idea about why SP randomly refuse to validate IDP certificate?</div>
<div>&nbsp;</div>
<div>Regards.</div>
<div><font face="FuturaA Bk BT, sans-serif" size="2">&nbsp;</font></div>
</font>
</body>
</html>