<HTML><HEAD>
<META content="text/html; charset=utf-8" http-equiv=Content-Type>
<META name=GENERATOR content="MSHTML 9.00.8112.16447"></HEAD>
<BODY style="MARGIN: 4px 4px 1px; FONT: 10pt Segoe UI; WORD-WRAP: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space">
<DIV>Hello All</DIV>
<DIV>&nbsp;</DIV>
<DIV>I am in the process of renewing the Shibboleth certificate and at the end of the process I am&nbsp;getting this error message when I try to connect: "Message was signed, but signature could not be verified."<BR></DIV>
<DIV>The certificate is updated in my metadata and its location&nbsp;and &nbsp;the key are in&nbsp;the relying-party.xml file. I also see the saml2 assertion being sent with the correct certificate when I turn debugging on. Where did I go wrong?</DIV>
<DIV>The certificate was also successfully loaded in tomcat. Both tomcat and the IdP start w/o issues but when I try to authenticate I get the above message.&nbsp;</DIV>
<DIV>&nbsp;</DIV>
<DIV>Are there step by step guides to renewing the Shibboleth certificate? </DIV>
<DIV>&nbsp;</DIV>
<DIV>TIA</DIV>
<DIV>Wavyne Belance<BR></DIV>
<DIV>
<DIV><BR>&nbsp;</DIV>
<DIV>You can check the certificate that is being used by the IdP by looking at the certificate subelement of &lt;security:Credential id="IdPCredential" xsi:type="security:X509Filesystem"&gt; in relying-party.xml. &nbsp;You'll need to compare that certificate to the one in the metadata file you supplied to the PingFederate SP. &nbsp;You can make sure they match by updating one, the other, or both.</DIV></DIV>
<DIV><BR></DIV>
<DIV>Let us know if we can help further,</DIV>
<DIV>Nate.</DIV></BODY></HTML>