<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif; ">
<div>Thank you, Brent. &nbsp;That's where I was leaning too, but, it helps to have a more experienced set of eyes of validate my thinking. &nbsp; My metadata is up to date, so, I'm guessing the SP is using the wrong certificate.</div>
<div><br>
</div>
<div>Thanks again,</div>
<div><br>
</div>
<div>..Sean. &nbsp;&nbsp;&nbsp;</div>
<div><br>
</div>
<span id="OLK_SRC_BODY_SECTION">
<div style="font-family:Calibri; font-size:11pt; text-align:left; color:black; BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
<span style="font-weight:bold">From: </span>Brent Putman &lt;<a href="mailto:putmanb@georgetown.edu">putmanb@georgetown.edu</a>&gt;<br>
<span style="font-weight:bold">Reply-To: </span>Shib Users &lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br>
<span style="font-weight:bold">Date: </span>Wed, 9 Jan 2013 18:10:32 -0500<br>
<span style="font-weight:bold">To: </span>&lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br>
<span style="font-weight:bold">Subject: </span>Re: Client certificate authentication failed for context issuer entity ID<br>
</div>
<div><br>
</div>
<div>
<div bgcolor="#FFFFFF" text="#000000"><br>
<div class="moz-cite-prefix">On 1/9/13 5:50 PM, Sean R. McNamara wrote:<br>
</div>
<blockquote cite="mid:13DE6CDC5C02C040A962C8E7E553E54379BB853E@SN2PRD0310MB394.namprd03.prod.outlook.com" type="cite">
<div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif;
        font-size: 14px; ">
Hello all,</div>
<div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif;
        font-size: 14px; ">
<br>
</div>
<div><font face="Calibri,sans-serif">We're running the Shibboleth IdP 2.1.2 and are members of incommon. &nbsp; We've recently been trying to interoperate with a new SP and are running into issues with their attribute request. &nbsp; The end result is an exception &quot;</font><span style="color: rgb(0, 0, 0);
          font-family: Helvetica; font-size: 12px; ">Client
 certificate authentication failed for context issuer entity ID&quot;, but, it appears the real issue has to do with the line: &quot;</span><font face="Helvetica"><span style="font-size: 12px;">Failed to validate untrusted credential against trusted key&quot;
</span></font></div>
</blockquote>
<br>
Yes, exactly, that's the problem. <br>
<br>
<blockquote cite="mid:13DE6CDC5C02C040A962C8E7E553E54379BB853E@SN2PRD0310MB394.namprd03.prod.outlook.com" type="cite">
<div><br>
</div>
<div><br>
<p style="margin: 0px; font-size: 12px; font-family: Helvetica;
          ">16:47:23.754 - DEBUG [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:206] - Searching for entity descriptor with an entity ID of
<a class="moz-txt-link-freetext" href="https://Broken-SP/shibboleth">https://Broken-SP/shibboleth</a></p>
<br>
</div>
</blockquote>
<blockquote type="cite">
<p style="margin: 0px; font-size: 12px; font-family: Helvetica; ">16:47:23.755 - DEBUG [org.opensaml.xml.security.keyinfo.BasicProviderKeyInfoCredentialResolver:296] - Processing KeyInfo child {<a class="moz-txt-link-freetext" href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>}X509Data
 with provider org.opensaml.xml.security.keyinfo.provider.InlineX509DataProvider</p>
<p style="margin: 0px; font-size: 12px; font-family: Helvetica; ">16:47:23.756 - DEBUG [org.opensaml.xml.security.keyinfo.provider.InlineX509DataProvider:122] - Attempting to extract credential from an X509Data</p>
<p style="margin: 0px; font-size: 12px; font-family: Helvetica; ">16:47:23.763 - DEBUG [org.opensaml.xml.security.keyinfo.provider.InlineX509DataProvider:195] - Found 1 X509Certificates</p>
<p style="margin: 0px; font-size: 12px; font-family: Helvetica; ">16:47:23.763 - DEBUG [org.opensaml.xml.security.keyinfo.provider.InlineX509DataProvider:176] - Found 0 X509CRLs</p>
<p style="margin: 0px; font-size: 12px; font-family: Helvetica; ">16:47:23.763 - DEBUG [org.opensaml.xml.security.keyinfo.provider.InlineX509DataProvider:214] - Single certificate was present, treating as end-entity certificate</p>
</blockquote>
<br>
<blockquote cite="mid:13DE6CDC5C02C040A962C8E7E553E54379BB853E@SN2PRD0310MB394.namprd03.prod.outlook.com" type="cite">
<div>
<p style="margin: 0px; font-size: 12px; font-family: Helvetica;
          ">16:47:23.764 - DEBUG [org.opensaml.xml.security.keyinfo.BasicProviderKeyInfoCredentialResolver:301] - Credentials successfully extracted from child {<a class="moz-txt-link-freetext" href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>}X509Data
 by provider </p>
</div>
</blockquote>
<br>
<br>
<br>
Looks like the metadata you have for the Broken-SP has 1 certificate in metadata.<br>
<br>
<br>
<br>
<blockquote cite="mid:13DE6CDC5C02C040A962C8E7E553E54379BB853E@SN2PRD0310MB394.namprd03.prod.outlook.com" type="cite">
<div><br>
<p style="margin: 0px; font-size: 12px; font-family: Helvetica;
          ">16:47:23.766 - DEBUG [org.opensaml.xml.security.trust.ExplicitKeyTrustEvaluator:94] - Failed to validate untrusted credential against trusted key</p>
</div>
</blockquote>
<br>
<br>
This line however indicates that the metadata cert's public key does not match the public key in the client cert being presented during client TLS.&nbsp;
<br>
<br>
So, either the SP is using the wrong cert with your IdP, or the metadata is out-of-date.&nbsp; Take your pick, but that's the basic problem.&nbsp;
<br>
<br>
<br>
<br>
<br>
</div>
</div>
-- To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a></span>
</body>
</html>