<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif; ">
<div>Verify you've given Shib SP the correct metadata. That's either the public key is wrong or there's a time skew between the IdP and SP servers. The incoming SAML Response will have the public key embedded in it so you can compare it to what SP is loading.</div>
<div><br>
</div>
<div>Paul</div>
<div><br>
</div>
<span id="OLK_SRC_BODY_SECTION">
<div style="font-family:Calibri; font-size:11pt; text-align:left; color:black; BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
<span style="font-weight:bold">From: </span>Sam Agnew <<a href="mailto:saa2012@qatar-med.cornell.edu">saa2012@qatar-med.cornell.edu</a>><br>
<span style="font-weight:bold">Reply-To: </span>Shibboleth Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<span style="font-weight:bold">Date: </span>Wednesday, November 20, 2013 3:55 AM<br>
<span style="font-weight:bold">To: </span>Shibboleth Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<span style="font-weight:bold">Subject: </span>Re: Initial Setup -- Cannot Get SP and IDP Talking<br>
</div>
<div><br>
</div>
<div>What I am now getting after successful login on the loginpage (UserPassword auth via LDAP) is the following from the SP:</div>
<div><span class="Apple-style-span" style="font-family: Geneva, Arial, Helvetica, sans-serif; ">
<p class="error" style="font-size: 10pt; margin-top: 20px; margin-bottom: 20px; font-weight: bold; ">
opensaml::FatalProfileException at (<a href="https://unixadmin.qatar-med.cornell.edu/Shibboleth.sso/SAML2/POST">https://unixadmin.qatar-med.cornell.edu/Shibboleth.sso/SAML2/POST</a>)</p>
<p style="font-size: 10pt; margin-top: 20px; margin-bottom: 20px; ">Unable to establish security of incoming assertion.</p>
</span>
<div>
<div style="color: rgb(0, 0, 0); font-family: Calibri; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; ">
The shibd.log says:</div>
<div style="color: rgb(0, 0, 0); font-family: Calibri; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; ">
<div>2013-11-20 11:45:18 WARN Shibboleth.SSO.SAML2 [3]: detected a problem with assertion: Unable to establish security of incoming assertion.</div>
</div>
<br class="Apple-interchange-newline">
</div>
</div>
</span>
</body>
</html>