So I completed setting up my IdP for the bilateral trust with Box using the metadata file they provided &quot;as is&quot; and i&#39;ve asked Box to enable SSO for us, but upon initial testing, I&#39;m now having a problem. After authenticating at our IdP, their SP is returning the following:<br>

<br>Error - Single Sign-On<br>Nonsuccess Response status: urn:oasis:names:tc:SAML:2.0:status:Responder Status Message: Unable to encrypt assertion<br>Partner: <a href="https://prdidp.uncg.edu/idp/shibboleth">https://prdidp.uncg.edu/idp/shibboleth</a><br>

Target Resource: <a href="https://uncg.box.com/sso/ping_federate">https://uncg.box.com/sso/ping_federate</a><br><br>my idp-process.log shows:<br>09:55:13.304 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:966] - Could not resolve a key encryption credential for peer entity: <a href="http://box.net">box.net</a><br>

09:55:13.305 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:276] - Unable to construct encrypter<br>org.opensaml.xml.security.SecurityException: Could not resolve key encryption credential<br>

<br>Is this something on my end? or perhaps I didn&#39;t provide my IdP&#39;s metadata correctly to them or something was lost in translation? <a href="https://prdidp.uncg.edu/idp/shibboleth">https://prdidp.uncg.edu/idp/shibboleth</a> being displayed by them as the &quot;Partner&quot; is my correct entityID.<br>

<br>Thanks<br>-Rob<br><br clear="all"><br>-- <br><div>Robert W. Gorrell<br>Middleware Engineer, Identity and Access Management</div>
<div>University of NC at Greensboro<br>336-334-5954</div>