<html><head></head><body bgcolor="#FFFFFF"><div>Rob,</div><div><br></div><div>This error typically occurs when the certificate in their metadata is different from the certificate used to encrypt the assertion(will be in the DEBUG log). Can you compare the two to doublecheck?</div><div><br></div><div>Thanks,</div><div>Nate.<br><br>Semt frim mt iPone</div><div><br>On Jul 23, 2012, at 14:14, Rob Whitener <<a href="mailto:rob.whitener@audaxhealth.com">rob.whitener@audaxhealth.com</a>> wrote:<br><br></div><div></div><blockquote type="cite"><div>At Scott Cantor's suggestion, I asked our partner to encrypt the whole assertion, rather than just the attributes (they took it upon themselves to have the attributes remain encrypted as well, inside the already encrypted assertion? Seems like too much encryption to me).<div>
<br></div><div>Now, we are seeing errors like this in Syslog:</div><div><br></div><div>Jul 23 19:18:21 ip-10-90-230-192 shibboleth-sp: 1343071101 ERROR Shibboleth.Listener [24585] shib_check_user: remoted message returned an error: A valid authentication statement was not found in the incoming message.</div>
<div><br></div><div>And this in shibd.log:</div><div>2012-07-23 19:19:33 DEBUG XMLTooling.CredentialCriteria [16]: key algorithm didn't match ('AES' != 'RSA')</div><div><br></div><div>Is this something I can modify in our config? I am certain that their metadata told us they would be using RSA, and since those are two completely different encryption modes, it seems like this might be more them than us?</div>
<div><br></div><div>Thanks,</div><div><br></div><div>Rob</div><div><br><div class="gmail_quote">On Fri, Jul 20, 2012 at 3:59 PM, Rob Whitener <span dir="ltr"><<a href="mailto:rob.whitener@audaxhealth.com" target="_blank">rob.whitener@audaxhealth.com</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Yeah, I'm not blind, and just to double check I have looked through these logs several times and uncommented all the logging options. I am surprised that it would ignore the EcryptedAttribute element, since the docs specifically mention it:<div>
<br></div><div><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPAttributeExtractor" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPAttributeExtractor</a></div><div><br></div>
<div>I am on 2.3, so maybe that is the issue.</div><span class="HOEnZb"><font color="#888888">
<div><br></div><div>Rob</div></font></span><div class="HOEnZb"><div class="h5"><div><div><br><br><div class="gmail_quote">On Fri, Jul 20, 2012 at 3:56 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div>On 7/20/12 3:53 PM, "Rob Whitener" <<a href="mailto:rob.whitener@audaxhealth.com" target="_blank">rob.whitener@audaxhealth.com</a>> wrote:<br>
><br>
>Ah, got it, I misunderstood.<br>
<br>
</div>Code-wise, I also can verify that if it's not outright buggy and ignoring<br>
the element, the extractor will dump the decrypted XML on DEBUG, so that's<br>
all that should be needed to spot it doing that, or reporting an error.<br>
That strongly suggests to me it might be buggy or you're blind, and I<br>
doubt you're blind.<br>
<div><div><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div></div>
</div></div></blockquote></div><br></div>
</div></blockquote><blockquote type="cite"><div><span>--</span><br><span>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></span></div></blockquote></body></html>