<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Verdana;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">All,<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">This is my very first Shibboleth installation and I had it working fine as of about 5 hours ago. I had it working against the Testshib.org website without any issues. I had been struggling to understand what people meant by “Updating
the Metadata”. I googled and googled till I finally found a site that discussed updating Idp metadata. So, I did the following:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Made a backup of the /opt/shibboleth-idp/metadata/idp-metadata.xml<o:p></o:p></p>
<p class="MsoNormal">Made backups of the /opt/shibboleth-idp/credentials files (idp.crt, idp.key, and idp,jks).
<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Used the following to create a new X509 certificate/key:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"># cat > idp-cert.cnf <<EOF<o:p></o:p></p>
<p class="MsoNormal">[req]<o:p></o:p></p>
<p class="MsoNormal">prompt=no<o:p></o:p></p>
<p class="MsoNormal">default_bits=2048<o:p></o:p></p>
<p class="MsoNormal">encrypt_key=no<o:p></o:p></p>
<p class="MsoNormal">default_md=sha1<o:p></o:p></p>
<p class="MsoNormal">distinguished_name=dn<o:p></o:p></p>
<p class="MsoNormal"># PrintableStrings only<o:p></o:p></p>
<p class="MsoNormal">string_mask=MASK:0002<o:p></o:p></p>
<p class="MsoNormal">x509_extensions=ext<o:p></o:p></p>
<p class="MsoNormal">[dn]<o:p></o:p></p>
<p class="MsoNormal">CN=casdev.uco.edu<o:p></o:p></p>
<p class="MsoNormal">[ext]<o:p></o:p></p>
<p class="MsoNormal">subjectAltName=DNS:casdev.uco.edu,URI:https://casdev.uco.edu/idp/shibboleth<o:p></o:p></p>
<p class="MsoNormal">subjectKeyIdentifier=hash<o:p></o:p></p>
<p class="MsoNormal">EOF<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">openssl req -config idp-cert.cnf -new -x509 -keyout idp.new.key -out idp.new.crt 2> /dev/null<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">After creating the new crt and key files, I copied them into the /opt/shibboleth-idp/credentials directory and renamed them to the right names and double checked ownership of the files. After renaming them, I did a “cat idp.crt” to get
the X509 key and put that into my /opt/shibboleth-idp/metadata/idp-metadata.xml. I then uploaded my metadata to testshib.org to test and see if my new certs are working and now I am getting the following error messages in their log:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><b>2014-07-08 14:29:42 ERROR OpenSAML.SecurityPolicyRule.XMLSigning [245]: unable to verify message signature with supplied trust engine<o:p></o:p></b></p>
<p class="MsoNormal"><b>2014-07-08 14:29:42 WARN Shibboleth.SSO.SAML2 [245]: detected a problem with assertion: Message was signed, but signature could not be verified.<o:p></o:p></b></p>
<p class="MsoNormal"><b><o:p> </o:p></b></p>
<p class="MsoNormal">Additionally, I used the ./install.sh renew-cert to do this exact same thing, and I am still getting the same error message from testshib.org and I have uploaded the metadata file multiple times now with no luck. Is there something I’m
missing? Or am I just being stupid and missing the obvious? <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:black">Ben Branch<br>
UNIX/Linux Administrator</span><span style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:black">University of Central Oklahoma</span><span style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:black">ITIL Foundation v3, Network+, RHCSA<br>
<br>
100 N. University Drive, Box 122<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:black">Edmond, OK 73034</span><span style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:black">D: 405.974.2649 | M: 405.550.6804 |
</span><u><span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:blue"><a href="mailto:bbranch@uco."><span style="color:blue">bbranch@uco.</span></a>edu</span></u><span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:black">
| <a href="http://www.uco.edu/"><span style="color:blue">www.uco.edu</span></a></span><span style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:black"> </span><span style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:black">“</span>I am wiser than this man, for neither of us appears to know anything great and good; but he fancies he knows something, although he knows nothing; whereas
I, as I do not know anything, so I do not fancy I do. In this trifling particular, then, I appear to be wiser than he, because I do not fancy I know what I do not know.<span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:black">” - Socrates</span><span style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<b>**Bronze+Blue=Green**</b> The University of Central Oklahoma is Bronze, Blue, and Green! Please print this e-mail only if absolutely necessary!
<br>
<br>
<b>**CONFIDENTIALITY**</b> -This e-mail (including any attachments) may contain confidential, proprietary and privileged information. Any unauthorized disclosure or use of this information is prohibited.
</body>
</html>