<div dir="ltr">Ben,&nbsp;<br><br>I had same issue before and as far as I remember, we resolved it by releasing transientID ( ** ) in this trust relationship.&nbsp;<br>Also, SAML2SSO Profile should be configured where &quot;encryptAssertions&quot; should be &quot;never&quot;.&nbsp;<br>

<br>You can try this.&nbsp;<br><br>( ** )&nbsp;<br><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/ResolverTransientIDAttributeDefinition">https://wiki.shibboleth.net/confluence/display/SHIB2/ResolverTransientIDAttributeDefinition</a><br>

<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPTransientNameIdentifier">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPTransientNameIdentifier</a><br></div><div class="gmail_extra"><br><br><div class="gmail_quote">

On Wed, Aug 6, 2014 at 2:20 PM, Ben Branch <span dir="ltr">&lt;<a href="mailto:BBranch@uco.edu" target="_blank">BBranch@uco.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">







<div lang="EN-US" link="blue" vlink="purple">
<div>
<p class="MsoNormal">All,<u></u><u></u></p>
<p class="MsoNormal"><u></u>&nbsp;<u></u></p>
<p class="MsoNormal">I&rsquo;ve spent most of my day today trying to configure Salesforce to use Shibboleth and I&rsquo;ve ran into nothing but problems.<u></u><u></u></p>
<p class="MsoNormal"><u></u>&nbsp;<u></u></p>
<p class="MsoNormal">Currently, when I use the SAML Validator I get this failure on Item #11:<u></u><u></u></p>
<p class="MsoNormal"><u></u>&nbsp;<u></u></p>
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="padding:.75pt .75pt .75pt .75pt">
<p class="MsoNormal"><b><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;">11. Validating the Signature</span></b><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;"><u></u><u></u></span></p>


</td>
</tr>
<tr>
<td style="padding:.75pt .75pt .75pt .75pt">
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;">&nbsp;&nbsp;<span style="color:green">Is the response signed? false</span><u></u><u></u></span></p>
</td>
</tr>
<tr>
<td style="padding:.75pt .75pt .75pt .75pt">
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;">&nbsp;&nbsp;<span style="color:green">Is the assertion signed? true</span><u></u><u></u></span></p>
</td>
</tr>
<tr>
<td style="padding:.75pt .75pt .75pt .75pt">
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;">&nbsp;&nbsp;<span style="color:green">The reference in the assertion signature is valid</span><u></u><u></u></span></p>
</td>
</tr>
<tr>
<td style="padding:.75pt .75pt .75pt .75pt">
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;">&nbsp;&nbsp;<span style="color:green">Is the correct certificate supplied in the keyinfo? true</span><u></u><u></u></span></p>


</td>
</tr>
<tr>
<td style="padding:.75pt .75pt .75pt .75pt">
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;">&nbsp;&nbsp;<span style="color:maroon">Signature or certificate problems</span><u></u><u></u></span></p>
</td>
</tr>
<tr>
<td style="padding:.75pt .75pt .75pt .75pt">
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;">&nbsp;&nbsp;<span style="color:maroon">The signature in the assertion is not valid<u></u><u></u></span></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;color:maroon"><u></u>&nbsp;<u></u></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;color:maroon"><u></u>&nbsp;<u></u></span></p>
<p class="MsoNormal">I&rsquo;ve double checked the certificate that I&rsquo;ve uploaded and it matches what I have in my metadata file, and both of those match the .crt file I have on my server.&nbsp; I&rsquo;ve double checked the SP Metadata, and it is correct.&nbsp; When I login I get
 this error:&nbsp; <u></u><u></u></p>
<p class="MsoNormal"><u></u>&nbsp;<u></u></p>
<p class="MsoNormal"><strong><span style="font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;">Login Error</span></strong><span>
</span><br>
<span>Your login attempt using single sign-on with an identity provider certificate has failed. Please contact your <a href="http://salesforce.com" target="_blank">salesforce.com</a> administrator for more information.<u></u><u></u></span></p>


<p class="MsoNormal"><span><u></u>&nbsp;<u></u></span></p>
<p class="MsoNormal"><span>Everything else in the SAML Validator checks out fine.&nbsp; I am at a complete loss as to where I need to start looking on how to resolve this issue.&nbsp; Any help would be greatly appreciated.
</span><span style="font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;"><u></u><u></u></span></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal"><u></u>&nbsp;<u></u></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Verdana&quot;,&quot;sans-serif&quot;;color:black">Ben Branch<br>
UNIX/Linux Administrator</span><span style="color:black"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Verdana&quot;,&quot;sans-serif&quot;;color:black">University of Central Oklahoma</span><span style="color:black"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Verdana&quot;,&quot;sans-serif&quot;;color:black">ITIL Foundation v3, Network+, RHCSA<br>
<br>
100 N. University Drive, Box 122<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Verdana&quot;,&quot;sans-serif&quot;;color:black">Edmond, OK 73034</span><span style="color:black"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Verdana&quot;,&quot;sans-serif&quot;;color:black">D: 405.974.2649 | M: 405.550.6804 |
</span><u><span style="font-size:10.0pt;font-family:&quot;Verdana&quot;,&quot;sans-serif&quot;;color:blue"><a href="mailto:bbranch@uco." target="_blank"><span style="color:blue">bbranch@uco.</span></a>edu</span></u><span style="font-size:10.0pt;font-family:&quot;Verdana&quot;,&quot;sans-serif&quot;;color:black">
 | <a href="http://www.uco.edu/" target="_blank"><span style="color:blue">www.uco.edu</span></a></span><span style="color:black"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Verdana&quot;,&quot;sans-serif&quot;;color:black">&nbsp;</span><span style="color:black"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Verdana&quot;,&quot;sans-serif&quot;;color:black">&ldquo;</span>I am wiser than this man, for neither of us appears to know anything great and good; but he fancies he knows something, although he knows nothing; whereas
 I, as I do not know anything, so I do not fancy I do. In this trifling particular, then, I appear to be wiser than he, because I do not fancy I know what I do not know.<span style="font-size:10.0pt;font-family:&quot;Verdana&quot;,&quot;sans-serif&quot;;color:black">&rdquo;&nbsp;&nbsp;- Socrates</span><span style="color:black"><u></u><u></u></span></p>


<p class="MsoNormal"><u></u>&nbsp;<u></u></p>
</div>
<b>**Bronze+Blue=Green**</b> The University of Central Oklahoma is Bronze, Blue, and Green! Please print this e-mail only if absolutely necessary!
<br>
<br>
<b>**CONFIDENTIALITY**</b> -This e-mail (including any attachments) may contain confidential, proprietary and privileged information. Any unauthorized disclosure or use of this information is prohibited.
</div>

<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br><br clear="all"><div><br></div>-- <br>Best,<br>Zico
</div>