<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=ISO-8859-1">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    Hi,<br>
    <br>
    It is already a year now that I've setup the Shibboleth Centralized
    DS and it has been working well so far.<br>
    <br>
    We are now encountering some problems with new SP connecting to our
    federation.<br>
    <br>
    The problematic SP have a &lt;ds:signature&gt; section in their
    metadata; while syntactically correct, their metadata is rejected by
    the DS with following messages in the log :<br>
    <br>
-8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;-<br>
    10:36:15.630 - WARN
    [org.apache.xml.security.signature.XMLSignature:-1] - Signature
    verification failed.<br>
    10:36:15.630 - DEBUG
    [org.opensaml.xml.signature.SignatureValidator:77] - Signature did
    not validate against the credential's key<br>
    10:36:15.631 - DEBUG
    [org.opensaml.xml.signature.impl.BaseSignatureTrustEngine:144] -
    Signature validation using candidate validation credential failed<br>
    org.opensaml.xml.validation.ValidationException: Signature did not
    validate against the credential's key<br>
    &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; at
org.opensaml.xml.signature.SignatureValidator.validate(SignatureValidator.java:79)<br>
    ...<br>
    10:36:15.631 - DEBUG
    [org.opensaml.xml.signature.impl.ExplicitKeySignatureTrustEngine:115]
    - Failed to verify signature using either KeyInfo-derived or
    directly trusted credentials<br>
    10:36:15.631 - ERROR
    [org.opensaml.saml2.metadata.provider.SignatureValidationFilter:311]
    - Signature trust establishment failed for metadata entry
    <a class="moz-txt-link-freetext" href="https://secure.nature.com/shibboleth">https://secure.nature.com/shibboleth</a><br>
    10:36:15.632 - ERROR
    [org.opensaml.saml2.metadata.provider.SignatureValidationFilter:254]
    - EntityDescriptor '<a class="moz-txt-link-freetext" href="https://secure.nature.com/shibboleth">https://secure.nature.com/shibboleth</a>' failed
    signature verification, removing from metadata provider<br>
    10:36:15.634 - DEBUG
    [org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:264]
    - Error occurred while attempting to refresh metadata from '{}'<br>
    ..<br>
-8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;--8&lt;-<br>
    <br>
    <br>
    I know that the certificate present in their metadata is a
    self-signed. Is that the cause of the problem ?<br>
    <br>
    Is there a tool in the Shibboleth stuff to help me verify the
    signature of the metadata "by hand" (I mean using command line...) ?<br>
    <br>
    This problem is critical as if the error is triggered, the DS stops
    to process the remaining of the metadata file and, doesn't start up
    anymore.<br>
    <br>
    Any help would be appreciated... ;)<br>
    <br>
    Pascal<br>
    <div class="moz-signature">-- <br>
      <b><font size="2" color="#0092D2" face="arial">Pascal Panneels</font></b><font
        size="2" color="#0092D2" face="arial"><br>
        Project Manager<br>
        Belnet &#8226; Services</font>
      <font size="2" color="#8B8E8D" face="arial"><br>
        Louizalaan 231 Avenue Louise<br>
        Brussel 1050 Bruxelles
        <br>
        Belgi&euml; &#8226; Belgique<br>
        T: +32 2 790 33 33
        <br>
        <b><a href="http://www.belnet.be"
            style="text-decoration:none;color:#0092D2">www.belnet.be</a></b><br>
      </font></div>
  </body>
</html>