<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
Or, I suppose the message could be getting mangled somehow in one of the network/IdP hosting configurations, causing the signature to legitimately fail verification. Still, the SP's shibd.log should allow you to determine where, if not why, things are broken.
<div>
<div><br>
<div>
<div>
<div>On Jun 3, 2013, at 13:44 , Nate Klingenstein wrote:</div>
<br class="Apple-interchange-newline">
<blockquote type="cite">
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
<div>
<blockquote type="cite"><span class="Apple-style-span" style="border-collapse: separate; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; font-size: medium; ">1)
Assertion signing is disabled on both the IdP and SP so I don't know why<br>
the SP is even checking the signature right now<br>
</span></blockquote>
<div><br>
</div>
<div>The response(as opposed to the assertion) might be getting signed too. Have you looked at the inbound assertion to inspect for signatures? The SP will log the response and the decrypted assertion with shibd.logger on DEBUG.</div>
<br>
<blockquote type="cite"><span class="Apple-style-span" style="border-collapse: separate; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; font-size: medium; ">2)
It actually works within the network the IdP and SP reside on, but when<br>
accessed from an external network it throws this error.</span></blockquote>
</div>
<br>
<div>My guess would be the IdP's are using different signature keys, and a user is being assigned to an IdP based on network location.</div>
<div><br>
</div>
<div>But yes, I agree, this is probably an IdP problem.</div>
</div>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a></blockquote>
</div>
<br>
</div>
</div>
</div>
</body>
</html>