<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=ISO-8859-1">
</head>
<body bgcolor="#FFFFFF" text="#000000">
Hi,<br>
<br>
It is already a year now that I've setup the Shibboleth Centralized
DS and it has been working well so far.<br>
<br>
We are now encountering some problems with new SP connecting to our
federation.<br>
<br>
The problematic SP have a <ds:signature> section in their
metadata; while syntactically correct, their metadata is rejected by
the DS with following messages in the log :<br>
<br>
-8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<-<br>
10:36:15.630 - WARN
[org.apache.xml.security.signature.XMLSignature:-1] - Signature
verification failed.<br>
10:36:15.630 - DEBUG
[org.opensaml.xml.signature.SignatureValidator:77] - Signature did
not validate against the credential's key<br>
10:36:15.631 - DEBUG
[org.opensaml.xml.signature.impl.BaseSignatureTrustEngine:144] -
Signature validation using candidate validation credential failed<br>
org.opensaml.xml.validation.ValidationException: Signature did not
validate against the credential's key<br>
at
org.opensaml.xml.signature.SignatureValidator.validate(SignatureValidator.java:79)<br>
...<br>
10:36:15.631 - DEBUG
[org.opensaml.xml.signature.impl.ExplicitKeySignatureTrustEngine:115]
- Failed to verify signature using either KeyInfo-derived or
directly trusted credentials<br>
10:36:15.631 - ERROR
[org.opensaml.saml2.metadata.provider.SignatureValidationFilter:311]
- Signature trust establishment failed for metadata entry
<a class="moz-txt-link-freetext" href="https://secure.nature.com/shibboleth">https://secure.nature.com/shibboleth</a><br>
10:36:15.632 - ERROR
[org.opensaml.saml2.metadata.provider.SignatureValidationFilter:254]
- EntityDescriptor '<a class="moz-txt-link-freetext" href="https://secure.nature.com/shibboleth">https://secure.nature.com/shibboleth</a>' failed
signature verification, removing from metadata provider<br>
10:36:15.634 - DEBUG
[org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:264]
- Error occurred while attempting to refresh metadata from '{}'<br>
..<br>
-8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<--8<-<br>
<br>
<br>
I know that the certificate present in their metadata is a
self-signed. Is that the cause of the problem ?<br>
<br>
Is there a tool in the Shibboleth stuff to help me verify the
signature of the metadata "by hand" (I mean using command line...) ?<br>
<br>
This problem is critical as if the error is triggered, the DS stops
to process the remaining of the metadata file and, doesn't start up
anymore.<br>
<br>
Any help would be appreciated... ;)<br>
<br>
Pascal<br>
<div class="moz-signature">-- <br>
<b><font size="2" color="#0092D2" face="arial">Pascal Panneels</font></b><font
size="2" color="#0092D2" face="arial"><br>
Project Manager<br>
Belnet • Services</font>
<font size="2" color="#8B8E8D" face="arial"><br>
Louizalaan 231 Avenue Louise<br>
Brussel 1050 Bruxelles
<br>
België • Belgique<br>
T: +32 2 790 33 33
<br>
<b><a href="http://www.belnet.be"
style="text-decoration:none;color:#0092D2">www.belnet.be</a></b><br>
</font></div>
</body>
</html>