<html><body><div style="color:#000; background-color:#fff; font-family:arial, helvetica, sans-serif;font-size:12pt"><div><span>Well, that issue magically resolved itself...</span></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;"><span><br></span></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;"><span>Now it looks like a cert issue...</span></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;"><span><br></span></div><blockquote style="border: none; padding: 0px;"><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;"><span><div class="MsoNormal" style="color: rgb(34, 34,
 34); font-family: arial, sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">We run shibboleth 2.3.0</span></div><div class="MsoNormal" style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">&nbsp;</span></div><div class="MsoNormal" style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">The ‘instant expiration’ error seems to have gone away and now we are seeing the following error:</span></div><div class="MsoNormal" style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">&nbsp;</span></div><div class="MsoNormal" style="color: rgb(34, 34,
 34); font-family: arial, sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">08:11:09.982 - WARN [org.opensaml.common.binding.<wbr>security.<wbr>BaseSAMLSimpleSignatureSecurit<wbr>yPolicyRule:195] - Simple signature validation (with no request-derived credentials) failed</span></div><div class="MsoNormal" style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">08:11:09.982 - WARN [org.opensaml.common.binding.<wbr>security.<wbr>BaseSAMLSimpleSignatureSecurit<wbr>yPolicyRule:138] - Validation of request simple signature failed for context issuer:<a href="https://shib.lynda.com/shibboleth-sp" target="_blank" style="color: rgb(17, 85, 204);">https://shib.lynda.com/<wbr>shibboleth-sp</a></span></div><div class="MsoNormal" style="color: rgb(34, 34, 34); font-family: arial,
 sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">08:11:09.984 - WARN [edu.internet2.middleware.<wbr>shibboleth.idp.profile.saml2.<wbr>SSOProfileHandler:348] - Message did not meet security requirements</span></div><div class="im" style="color: rgb(80, 0, 80); font-family: arial, sans-serif; font-size: 13px;"><div class="MsoNormal"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">org.opensaml.ws.security.<wbr>SecurityPolicyException: Validation of request simple signature failed for context issuer</span></div><div class="MsoNormal"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">&nbsp;</span></div></div><div class="MsoNormal" style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">I have
 checked that metadata is up to date and that Lynda.com is listed as a SP.</span></div><div class="MsoNormal" style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">&nbsp;</span></div><div class="MsoNormal" style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">No issues have been reported as far as using AAF federated resources. I’m not sure if anyone here has used an overseas SP.</span></div></span></div></blockquote><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;"><span><br></span></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style:
 normal;"><span>We joined the AAF and as part of that process, the AAF required that we create a new cert that used our entityID instead of our base domain. &nbsp;So, I created a new one:</span></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;"><span><br></span></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;"><span>







<div class="p1"><span class="s1">&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;</span><span class="s2">&lt;</span>CredentialResolver <span class="s3">type</span><span class="s1">=</span><span class="s2">"Chaining"&gt;</span></div>
<div class="p2">&nbsp; &nbsp; &nbsp; &nbsp; <span class="s4">&lt;!--&nbsp;</span></div>
<div class="p3">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Certificate/Private key pairs are read in sequence.</div>
<div class="p3">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Unless specificially defined only the first&nbsp;</div>
<div class="p3">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; CredentialResolver is used for attribute requests.</div>
<div class="p3">&nbsp; &nbsp; &nbsp; &nbsp; --&gt;</div>
<div class="p4"><span class="s1">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; </span>&lt;<span class="s5">CredentialResolver </span><span class="s3">type</span><span class="s1">=</span>"File" <span class="s3">keyName</span><span class="s1">=</span>"Active" <span class="s3">use</span><span class="s1">=</span>"encryption"</div>
<div class="p4">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class="s3">key</span><span class="s1">=</span>"C:\opt\shibboleth-sp\etc\shibboleth\sp-key-2011.pem"&nbsp;</div>
<div class="p4">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class="s3">certificate</span><span class="s1">=</span>"C:\opt\shibboleth-sp\etc\shibboleth\sp-cert-2011.pem"<span class="s1">/</span>&gt;</div>
<div class="p1"><span class="s1">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; </span><span class="s2">&lt;</span>CredentialResolver <span class="s3">type</span><span class="s1">=</span><span class="s2">"File" </span><span class="s3">keyName</span><span class="s1">=</span><span class="s2">"Standby"&nbsp;</span></div>
<div class="p4">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class="s3">key</span><span class="s1">=</span>"C:\opt\shibboleth-sp\etc\shibboleth\sp-key.pem"&nbsp;</div>
<div class="p4">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class="s3">certificate</span><span class="s1">=</span>"C:\opt\shibboleth-sp\etc\shibboleth\sp-cert.pem"<span class="s1">/</span>&gt;</div>
<div class="p1"><span style="font-weight: bold;"><span class="s1">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; </span><span class="s2">&lt;</span>CredentialResolver <span class="s3">type</span><span class="s1">=</span><span class="s2">"File" </span><span class="s3">keyName</span><span class="s1">=</span><span class="s2">"AAF"&nbsp;</span></span></div>
<div class="p4"><span style="font-weight: bold;">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class="s3">key</span><span class="s1">=</span>"C:\opt\shibboleth-sp\etc\shibboleth\sp-key-AAF.pem"&nbsp;</span></div>
<div class="p4"><span style="font-weight: bold;">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class="s3">certificate</span><span class="s1">=</span>"C:\opt\shibboleth-sp\etc\shibboleth\sp-cert-AAF.pem"<span class="s1">/</span>&gt;</span></div>
<div class="p1"><span style="font-weight: bold;"><span class="s1">&nbsp; &nbsp; &nbsp; &nbsp; </span><span class="s2">&lt;/</span>CredentialResolver<span class="s2">&gt;</span></span></div></span></div><div><br></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;">Regenerated my metadata and gave that to the AAF. &nbsp;Got theirs and their cert. Load em up, no problem.&nbsp;</div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;"><br></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;">Obviously the cert is my first suspect in this - Anyone care to venture what to look at? &nbsp;I have verified that my metadata has the correct AAF cert in it. &nbsp;The AAF also has mine
 correctly. &nbsp;Where else can I look?</div>  <div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"> <div style="font-family: 'times new roman', 'new york', times, serif; font-size: 12pt;"> <div dir="ltr"> <font size="2" face="Arial"> <hr size="1">  <b><span style="font-weight:bold;">From:</span></b> "Cantor, Scott" &lt;cantor.2@osu.edu&gt;<br> <b><span style="font-weight: bold;">To:</span></b> Shib Users &lt;users@shibboleth.net&gt; <br> <b><span style="font-weight: bold;">Sent:</span></b> Tuesday, January 22, 2013 11:36 AM<br> <b><span style="font-weight: bold;">Subject:</span></b> Re: Internation dateline issue<br> </font> </div> <br>
On 1/22/13 2:30 PM, "Mike Flynn" &lt;<a ymailto="mailto:shibbolethlynda@yahoo.com" href="mailto:shibbolethlynda@yahoo.com">shibbolethlynda@yahoo.com</a>&gt; wrote:<br><br>&gt;And just to clarify - On the SP side, my setting of clockSkew="180" is<br>&gt;just to allow a 3 minute variance in the UTC for inbound only, correct?<br>&gt;No impact on outbound?<br><br>Yes, has nothing to do with what you generate.<br><br>-- Scott<br><br><br>--<br>To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br><br><br> </div> </div>  </div></body></html>