<html><body><div style="color:#000; background-color:#fff; font-family:arial, helvetica, sans-serif;font-size:12pt"><div><span>Well, that issue magically resolved itself...</span></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;"><span><br></span></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;"><span>Now it looks like a cert issue...</span></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;"><span><br></span></div><blockquote style="border: none; padding: 0px;"><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;"><span><div class="MsoNormal" style="color: rgb(34, 34,
34); font-family: arial, sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">We run shibboleth 2.3.0</span></div><div class="MsoNormal" style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);"> </span></div><div class="MsoNormal" style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">The ‘instant expiration’ error seems to have gone away and now we are seeing the following error:</span></div><div class="MsoNormal" style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);"> </span></div><div class="MsoNormal" style="color: rgb(34, 34,
34); font-family: arial, sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">08:11:09.982 - WARN [org.opensaml.common.binding.<wbr>security.<wbr>BaseSAMLSimpleSignatureSecurit<wbr>yPolicyRule:195] - Simple signature validation (with no request-derived credentials) failed</span></div><div class="MsoNormal" style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">08:11:09.982 - WARN [org.opensaml.common.binding.<wbr>security.<wbr>BaseSAMLSimpleSignatureSecurit<wbr>yPolicyRule:138] - Validation of request simple signature failed for context issuer:<a href="https://shib.lynda.com/shibboleth-sp" target="_blank" style="color: rgb(17, 85, 204);">https://shib.lynda.com/<wbr>shibboleth-sp</a></span></div><div class="MsoNormal" style="color: rgb(34, 34, 34); font-family: arial,
sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">08:11:09.984 - WARN [edu.internet2.middleware.<wbr>shibboleth.idp.profile.saml2.<wbr>SSOProfileHandler:348] - Message did not meet security requirements</span></div><div class="im" style="color: rgb(80, 0, 80); font-family: arial, sans-serif; font-size: 13px;"><div class="MsoNormal"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">org.opensaml.ws.security.<wbr>SecurityPolicyException: Validation of request simple signature failed for context issuer</span></div><div class="MsoNormal"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);"> </span></div></div><div class="MsoNormal" style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">I have
checked that metadata is up to date and that Lynda.com is listed as a SP.</span></div><div class="MsoNormal" style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);"> </span></div><div class="MsoNormal" style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px;"><span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125);">No issues have been reported as far as using AAF federated resources. I’m not sure if anyone here has used an overseas SP.</span></div></span></div></blockquote><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;"><span><br></span></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style:
normal;"><span>We joined the AAF and as part of that process, the AAF required that we create a new cert that used our entityID instead of our base domain. So, I created a new one:</span></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;"><span><br></span></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;"><span>
<div class="p1"><span class="s1"> </span><span class="s2"><</span>CredentialResolver <span class="s3">type</span><span class="s1">=</span><span class="s2">"Chaining"></span></div>
<div class="p2"> <span class="s4"><!-- </span></div>
<div class="p3"> Certificate/Private key pairs are read in sequence.</div>
<div class="p3"> Unless specificially defined only the first </div>
<div class="p3"> CredentialResolver is used for attribute requests.</div>
<div class="p3"> --></div>
<div class="p4"><span class="s1"> </span><<span class="s5">CredentialResolver </span><span class="s3">type</span><span class="s1">=</span>"File" <span class="s3">keyName</span><span class="s1">=</span>"Active" <span class="s3">use</span><span class="s1">=</span>"encryption"</div>
<div class="p4"> <span class="s3">key</span><span class="s1">=</span>"C:\opt\shibboleth-sp\etc\shibboleth\sp-key-2011.pem" </div>
<div class="p4"> <span class="s3">certificate</span><span class="s1">=</span>"C:\opt\shibboleth-sp\etc\shibboleth\sp-cert-2011.pem"<span class="s1">/</span>></div>
<div class="p1"><span class="s1"> </span><span class="s2"><</span>CredentialResolver <span class="s3">type</span><span class="s1">=</span><span class="s2">"File" </span><span class="s3">keyName</span><span class="s1">=</span><span class="s2">"Standby" </span></div>
<div class="p4"> <span class="s3">key</span><span class="s1">=</span>"C:\opt\shibboleth-sp\etc\shibboleth\sp-key.pem" </div>
<div class="p4"> <span class="s3">certificate</span><span class="s1">=</span>"C:\opt\shibboleth-sp\etc\shibboleth\sp-cert.pem"<span class="s1">/</span>></div>
<div class="p1"><span style="font-weight: bold;"><span class="s1"> </span><span class="s2"><</span>CredentialResolver <span class="s3">type</span><span class="s1">=</span><span class="s2">"File" </span><span class="s3">keyName</span><span class="s1">=</span><span class="s2">"AAF" </span></span></div>
<div class="p4"><span style="font-weight: bold;"> <span class="s3">key</span><span class="s1">=</span>"C:\opt\shibboleth-sp\etc\shibboleth\sp-key-AAF.pem" </span></div>
<div class="p4"><span style="font-weight: bold;"> <span class="s3">certificate</span><span class="s1">=</span>"C:\opt\shibboleth-sp\etc\shibboleth\sp-cert-AAF.pem"<span class="s1">/</span>></span></div>
<div class="p1"><span style="font-weight: bold;"><span class="s1"> </span><span class="s2"></</span>CredentialResolver<span class="s2">></span></span></div></span></div><div><br></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;">Regenerated my metadata and gave that to the AAF. Got theirs and their cert. Load em up, no problem. </div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;"><br></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;">Obviously the cert is my first suspect in this - Anyone care to venture what to look at? I have verified that my metadata has the correct AAF cert in it. The AAF also has mine
correctly. Where else can I look?</div> <div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"> <div style="font-family: 'times new roman', 'new york', times, serif; font-size: 12pt;"> <div dir="ltr"> <font size="2" face="Arial"> <hr size="1"> <b><span style="font-weight:bold;">From:</span></b> "Cantor, Scott" <cantor.2@osu.edu><br> <b><span style="font-weight: bold;">To:</span></b> Shib Users <users@shibboleth.net> <br> <b><span style="font-weight: bold;">Sent:</span></b> Tuesday, January 22, 2013 11:36 AM<br> <b><span style="font-weight: bold;">Subject:</span></b> Re: Internation dateline issue<br> </font> </div> <br>
On 1/22/13 2:30 PM, "Mike Flynn" <<a ymailto="mailto:shibbolethlynda@yahoo.com" href="mailto:shibbolethlynda@yahoo.com">shibbolethlynda@yahoo.com</a>> wrote:<br><br>>And just to clarify - On the SP side, my setting of clockSkew="180" is<br>>just to allow a 3 minute variance in the UTC for inbound only, correct?<br>>No impact on outbound?<br><br>Yes, has nothing to do with what you generate.<br><br>-- Scott<br><br><br>--<br>To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br><br><br> </div> </div> </div></body></html>