So I completed setting up my IdP for the bilateral trust with Box using the metadata file they provided "as is" and i've asked Box to enable SSO for us, but upon initial testing, I'm now having a problem. After authenticating at our IdP, their SP is returning the following:<br>
<br>Error - Single Sign-On<br>Nonsuccess Response status: urn:oasis:names:tc:SAML:2.0:status:Responder Status Message: Unable to encrypt assertion<br>Partner: <a href="https://prdidp.uncg.edu/idp/shibboleth">https://prdidp.uncg.edu/idp/shibboleth</a><br>
Target Resource: <a href="https://uncg.box.com/sso/ping_federate">https://uncg.box.com/sso/ping_federate</a><br><br>my idp-process.log shows:<br>09:55:13.304 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:966] - Could not resolve a key encryption credential for peer entity: <a href="http://box.net">box.net</a><br>
09:55:13.305 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:276] - Unable to construct encrypter<br>org.opensaml.xml.security.SecurityException: Could not resolve key encryption credential<br>
<br>Is this something on my end? or perhaps I didn't provide my IdP's metadata correctly to them or something was lost in translation? <a href="https://prdidp.uncg.edu/idp/shibboleth">https://prdidp.uncg.edu/idp/shibboleth</a> being displayed by them as the "Partner" is my correct entityID.<br>
<br>Thanks<br>-Rob<br><br clear="all"><br>-- <br><div>Robert W. Gorrell<br>Middleware Engineer, Identity and Access Management</div>
<div>University of NC at Greensboro<br>336-334-5954</div>