<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=us-ascii"><meta name=Generator content="Microsoft Word 14 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";
        mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";
        mso-fareast-language:EN-US;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-GB link=blue vlink=purple><div class=WordSection1><p class=MsoNormal>Trying to configure Shib SP on Windows / IIS 7.5 to read from our own certificate, for signing authn requests.<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>For our self-signed cert I can lay my hands on its .crt, .csr, .key and .pfx files.&nbsp; For its root I have ca.crt and ca.key files.<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>I have put the self-signed cert&#8217;s .crt and .key files on the server, and have set the following in shibboleth2.xml:-<o:p></o:p></p><p class=MsoNormal>&nbsp; &nbsp;&nbsp;&lt;CredentialResolver type=&quot;File&quot; key=&quot;C:\SamlCerts\revolutionsp.key&quot; certificate=&quot;C:\SamlCerts\revolutionsp.crt&quot; password=&quot;theCorrectPassword&quot;/&gt;<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>On restarting the Shibd Windows service I always get:-<o:p></o:p></p><p class=MsoNormal>2012-07-27 15:07:33 INFO XMLTooling.SecurityHelper : loading private key from file (C:\SamlCerts\revolutionsp.key)<o:p></o:p></p><p class=MsoNormal>2012-07-27 15:07:33 ERROR OpenSSL : error code: 101077092 in .\crypto\evp\evp_enc.c, line 467<o:p></o:p></p><p class=MsoNormal>2012-07-27 15:07:33 ERROR OpenSSL : error code: 151429221 in .\crypto\pem\pem_lib.c, line 476<o:p></o:p></p><p class=MsoNormal>2012-07-27 15:07:33 CRIT Shibboleth.Application : error building CredentialResolver: Unable to load private key from file (C:\SamlCerts\revolutionsp.key).<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>Any idea?&nbsp; Is there a way to get more meaningful messages from OpenSSL?&nbsp; Should I be referencing the ca.* files via chaining?&nbsp; Should be .pfx file be used?<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p></div><br><br>
<P>This message is private and confidential. If you have received this message in error, please notify us and remove it from your system. Any views or opinions presented in this email are solely those of the author and might not represent those of StatPro. Warning: Although StatPro has taken reasonable precautions to ensure no viruses are present in this email, the company cannot accept responsibility for any loss or damage arising from the use of this email or attachments.</P>
</body></html>