<div dir="ltr">Ben, <br><br>I had same issue before and as far as I remember, we resolved it by releasing transientID ( ** ) in this trust relationship. <br>Also, SAML2SSO Profile should be configured where "encryptAssertions" should be "never". <br>
<br>You can try this. <br><br>( ** ) <br><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/ResolverTransientIDAttributeDefinition">https://wiki.shibboleth.net/confluence/display/SHIB2/ResolverTransientIDAttributeDefinition</a><br>
<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPTransientNameIdentifier">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPTransientNameIdentifier</a><br></div><div class="gmail_extra"><br><br><div class="gmail_quote">
On Wed, Aug 6, 2014 at 2:20 PM, Ben Branch <span dir="ltr"><<a href="mailto:BBranch@uco.edu" target="_blank">BBranch@uco.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div lang="EN-US" link="blue" vlink="purple">
<div>
<p class="MsoNormal">All,<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">I’ve spent most of my day today trying to configure Salesforce to use Shibboleth and I’ve ran into nothing but problems.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Currently, when I use the SAML Validator I get this failure on Item #11:<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="padding:.75pt .75pt .75pt .75pt">
<p class="MsoNormal"><b><span style="font-size:12.0pt;font-family:"Times New Roman","serif"">11. Validating the Signature</span></b><span style="font-size:12.0pt;font-family:"Times New Roman","serif""><u></u><u></u></span></p>
</td>
</tr>
<tr>
<td style="padding:.75pt .75pt .75pt .75pt">
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Times New Roman","serif""> <span style="color:green">Is the response signed? false</span><u></u><u></u></span></p>
</td>
</tr>
<tr>
<td style="padding:.75pt .75pt .75pt .75pt">
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Times New Roman","serif""> <span style="color:green">Is the assertion signed? true</span><u></u><u></u></span></p>
</td>
</tr>
<tr>
<td style="padding:.75pt .75pt .75pt .75pt">
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Times New Roman","serif""> <span style="color:green">The reference in the assertion signature is valid</span><u></u><u></u></span></p>
</td>
</tr>
<tr>
<td style="padding:.75pt .75pt .75pt .75pt">
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Times New Roman","serif""> <span style="color:green">Is the correct certificate supplied in the keyinfo? true</span><u></u><u></u></span></p>
</td>
</tr>
<tr>
<td style="padding:.75pt .75pt .75pt .75pt">
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Times New Roman","serif""> <span style="color:maroon">Signature or certificate problems</span><u></u><u></u></span></p>
</td>
</tr>
<tr>
<td style="padding:.75pt .75pt .75pt .75pt">
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Times New Roman","serif""> <span style="color:maroon">The signature in the assertion is not valid<u></u><u></u></span></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Times New Roman","serif";color:maroon"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Times New Roman","serif";color:maroon"><u></u> <u></u></span></p>
<p class="MsoNormal">I’ve double checked the certificate that I’ve uploaded and it matches what I have in my metadata file, and both of those match the .crt file I have on my server. I’ve double checked the SP Metadata, and it is correct. When I login I get
this error: <u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><strong><span style="font-family:"Calibri","sans-serif"">Login Error</span></strong><span>
</span><br>
<span>Your login attempt using single sign-on with an identity provider certificate has failed. Please contact your <a href="http://salesforce.com" target="_blank">salesforce.com</a> administrator for more information.<u></u><u></u></span></p>
<p class="MsoNormal"><span><u></u> <u></u></span></p>
<p class="MsoNormal"><span>Everything else in the SAML Validator checks out fine. I am at a complete loss as to where I need to start looking on how to resolve this issue. Any help would be greatly appreciated.
</span><span style="font-size:12.0pt;font-family:"Times New Roman","serif""><u></u><u></u></span></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:black">Ben Branch<br>
UNIX/Linux Administrator</span><span style="color:black"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:black">University of Central Oklahoma</span><span style="color:black"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:black">ITIL Foundation v3, Network+, RHCSA<br>
<br>
100 N. University Drive, Box 122<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:black">Edmond, OK 73034</span><span style="color:black"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:black">D: 405.974.2649 | M: 405.550.6804 |
</span><u><span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:blue"><a href="mailto:bbranch@uco." target="_blank"><span style="color:blue">bbranch@uco.</span></a>edu</span></u><span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:black">
| <a href="http://www.uco.edu/" target="_blank"><span style="color:blue">www.uco.edu</span></a></span><span style="color:black"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:black"> </span><span style="color:black"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:black">“</span>I am wiser than this man, for neither of us appears to know anything great and good; but he fancies he knows something, although he knows nothing; whereas
I, as I do not know anything, so I do not fancy I do. In this trifling particular, then, I appear to be wiser than he, because I do not fancy I know what I do not know.<span style="font-size:10.0pt;font-family:"Verdana","sans-serif";color:black">” - Socrates</span><span style="color:black"><u></u><u></u></span></p>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<b>**Bronze+Blue=Green**</b> The University of Central Oklahoma is Bronze, Blue, and Green! Please print this e-mail only if absolutely necessary!
<br>
<br>
<b>**CONFIDENTIALITY**</b> -This e-mail (including any attachments) may contain confidential, proprietary and privileged information. Any unauthorized disclosure or use of this information is prohibited.
</div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br><br clear="all"><div><br></div>-- <br>Best,<br>Zico
</div>