<div dir="ltr"><div><div><div>We currently deal with two separate federations that include the ProtectNetwork IdP (<a href="https://idp.protectnetwork.org/protectnetwork-idp">https://idp.protectnetwork.org/protectnetwork-idp</a>):<br><br></div>InCommon<br></div>UK Federation<br><br></div><div>The following comes from the ssl_access_log ...<br>10.242.0.145 - - [13/Nov/2014:08:47:41 +0000] &quot;GET /Shibboleth.sso/DS?SAMLDS=1&amp;target=https%3A%2F%<a href="http://2Fshibboleth-sp.prod.proquest.com">2Fshibboleth-sp.prod.proquest.com</a>%2FONE_SEARCH&amp;entityID=urn%3Amace%3Aincommon%<a href="http://3Aidp.protectnetwork.org">3Aidp.protectnetwork.org</a> HTTP/1.1&quot; 200 2060<br>10.242.0.145 - - [13/Nov/2014:08:47:42 +0000] &quot;POST /Shibboleth.sso/SAML2/POST HTTP/1.1&quot; 500 1000<br><br></div><div>But from the shibd.log I see the following ...<br>=================================================<br>2014-11-13 08:47:42 DEBUG OpenSAML.MessageDecoder.SAML2 [92]: extracting issuer from SAML 2.0 protocol message<br>2014-11-13 08:47:42 DEBUG OpenSAML.MessageDecoder.SAML2 [92]: message from (<a href="https://idp.protectnetwork.org/protectnetwork-idp">https://idp.protectnetwork.org/protectnetwork-idp</a>)<br>2014-11-13 08:47:42 DEBUG OpenSAML.MessageDecoder.SAML2 [92]: searching metadata for message issuer...<br>2014-11-13 08:47:42 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [92]: evaluating message flow policy (replay checking on, expiration 60)<br>2014-11-13 08:47:42 DEBUG XMLTooling.StorageService [92]: inserted record (_24617369cbd44218f0e5fa3e2acb5493) in context (MessageFlow) with expiration (1415868700)<br>2014-11-13 08:47:42 DEBUG Shibboleth.SSO.SAML2 [92]: processing message against SAML 2.0 SSO profile<br>2014-11-13 08:47:42 DEBUG XMLTooling.CredentialCriteria [92]: key algorithm didn&#39;t match (&#39;AES&#39; != &#39;RSA&#39;)<br>2014-11-13 08:47:42 DEBUG XMLTooling.CredentialCriteria [92]: key algorithm didn&#39;t match (&#39;AES&#39; != &#39;RSA&#39;)<br>2014-11-13 08:47:42 DEBUG XMLTooling.CredentialCriteria [92]: credential name(s) didn&#39;t overlap<br>2014-11-13 08:47:42 DEBUG Shibboleth.SSO.SAML2 [92]: decrypted Assertion: &lt;saml2:Assertion xmlns:saml2=&quot;urn:oasis:names:tc:SAML:2.0:assertion&quot; ID=&quot;_3cbe96a95c2a597c3c4df1bcced595ad&quot; IssueInstant=&quot;2014-11-13T08:47:40.964Z&quot; Version=&quot;2.0&quot; xmlns:xs=&quot;<a href="http://www.w3.org/2001/XMLSchema">http://www.w3.org/2001/XMLSchema</a>&quot;&gt;&lt;saml2:Issuer Format=&quot;urn:oasis:names:tc:SAML:2.0:nameid-format:entity&quot;&gt;<a href="https://idp.protectnetwork.org/protectnetwork-idp">https://idp.protectnetwork.org/protectnetwork-idp</a>&lt;/saml2:Issuer&gt;&lt;ds:Signature xmlns:ds=&quot;<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>&quot;&gt;&lt;ds:SignedInfo&gt;&lt;ds:CanonicalizationMethod Algorithm=&quot;<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>&quot;/&gt;&lt;ds:SignatureMethod Algorithm=&quot;<a href="http://www.w3.org/2000/09/xmldsig#rsa-sha1">http://www.w3.org/2000/09/xmldsig#rsa-sha1</a>&quot;/&gt;&lt;ds:Reference URI=&quot;#_3cbe96a95c2a597c3c4df1bcced595ad&quot;&gt;&lt;ds:Transforms&gt;&lt;ds:Transform Algorithm=&quot;<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature">http://www.w3.org/2000/09/xmldsig#enveloped-signature</a>&quot;/&gt;&lt;ds:Transform Algorithm=&quot;<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>&quot;&gt;&lt;ec:InclusiveNamespaces xmlns:ec=&quot;<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>&quot; PrefixList=&quot;xs&quot;/&gt;&lt;/ds:Transform&gt;&lt;/ds:Transforms&gt;&lt;ds:DigestMethod Algorithm=&quot;<a href="http://www.w3.org/2000/09/xmldsig#sha1">http://www.w3.org/2000/09/xmldsig#sha1</a>&quot;/&gt;&lt;ds:DigestValue&gt;ZC2yh72IgfUuaXW9XZ4Ua+KG4ys=&lt;/ds:DigestValue&gt;&lt;/ds:Reference&gt;&lt;/ds:SignedInfo&gt;&lt;ds:SignatureValue&gt;HoPm4J1Vf7Zn4YzEyftx9kLxtCx1hANsRDjR0Kz4m34W8y/3oAcfLpP9SCeiTSucfyc9fPZHLGTv9OY+NU23R/TRmORb3rtNFmxSlk9NIw10ZEucmAtEHgcreoV/tzDxVdmJ0FnBUfPvMSdjH/du98HegaMoQH5e9nWNvYstzGiPPW1tkFxEnFLkO0tcQeCPdNsRjLI/v8ME+JOMaN2XAo0V1BqauSGlYCI8oXq22hmBH1BkR4IlnrWFiOZC7yrydaAM6eFNOXE5NLdMCzCiEskPBNq/lfxEekmWREClPEqFrqDETcmw4pj9HmdzN21QdB3vq+JzF1SVmKKMoU0gwQ==&lt;/ds:SignatureValue&gt;&lt;ds:KeyInfo&gt;&lt;ds:X509Data&gt;&lt;ds:X509Certificate&gt;MIIEMDCCAxigAwIBAgIJALJxC01MGf/hMA0GCSqGSIb3DQEBBQUAMG0xCzAJBgNVBAYTAlVTMQ4w<br>DAYDVQQIEwVUZXhhczEPMA0GA1UEBxMGQXVzdGluMRcwFQYDVQQKEw5Qcm90ZWN0TmV0d29yazEk<br>MCIGA1UEAxMbdGNhcy1pZHAucHJvdGVjdG5ldHdvcmsub3JnMB4XDTExMDcyMTE2MzMxN1oXDTIx<br>MDcxODE2MzMxN1owbTELMAkGA1UEBhMCVVMxDjAMBgNVBAgTBVRleGFzMQ8wDQYDVQQHEwZBdXN0<br>aW4xFzAVBgNVBAoTDlByb3RlY3ROZXR3b3JrMSQwIgYDVQQDExt0Y2FzLWlkcC5wcm90ZWN0bmV0<br>d29yay5vcmcwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDWh2R4Tus8Thwl4Fnlmz6Q<br>rwL/imYN5di4q0gmWMJ03oBfIGireuZKfiI1FXeBsAq2p5XKZRQvWyKXJ1z2Z+FbG1Og5s6bZSzI<br>jq7bGac0FPtJ+0vgIy74RKJZDZNR2rzzlW2WCIe1zHUhbF0K1RVJZz8nbMDQ+H2Zf74Gi4dXwgQn<br>LCkkPV9ocinv3bq6Iq0H/ySgHGdmazzvvSW8C1Ny2WDfEqCWUkR9AKnTjyww3/f0PgHKuuvSKs6K<br>ArC00rD+v2hE+PT4M0oaTqSIbM5uu6f+Xfu10EQVG7O7Wmj2aAN0/D8/+Eeeh/8Se6XX81S7h/dN<br>RrQh7yKM6WIp2pPPAgMBAAGjgdIwgc8wHQYDVR0OBBYEFKWOH8Lch5mEhcxZR+E1w8nvx6HlMIGf<br>BgNVHSMEgZcwgZSAFKWOH8Lch5mEhcxZR+E1w8nvx6HloXGkbzBtMQswCQYDVQQGEwJVUzEOMAwG<br>A1UECBMFVGV4YXMxDzANBgNVBAcTBkF1c3RpbjEXMBUGA1UEChMOUHJvdGVjdE5ldHdvcmsxJDAi<br>BgNVBAMTG3RjYXMtaWRwLnByb3RlY3RuZXR3b3JrLm9yZ4IJALJxC01MGf/hMAwGA1UdEwQFMAMB<br>Af8wDQYJKoZIhvcNAQEFBQADggEBAACHlDYkgEzbaCatnF1IYcvy5j/T7dpOlvww+vJSK9Al3BlO<br>mESHrEIS46XO9vfk/PgNUM3oYG5prW+azSUJVDfJspSzH0d8IFCI95UlItC9Ivmxpuo1ZcH60fpI<br>M4Kb8fLeOfmsbpVZsxj8tSRByARlK4tzHf2+rLOn7jZRTsPcoxrxYIyesbbshhDyv2ZE+NoOehZX<br>aAYgZkB3PE0s6Ph+pUYIRSZ7bud1YNlx9QkUoYuwgR+hX895l19ZfouPZ1KljFoiTY8iwjRUUNV2<br>Lx2hZUsDHj/4Ea23TY+fc/7OSS4K0BIO4LmUQo1Zqg057Ao66R7RAwvB3jNS9ydAiNM=&lt;/ds:X509Certificate&gt;&lt;/ds:X509Data&gt;&lt;/ds:KeyInfo&gt;&lt;/ds:Signature&gt;&lt;saml2:Subject&gt;&lt;saml2:NameID Format=&quot;urn:oasis:names:tc:SAML:2.0:nameid-format:transient&quot; NameQualifier=&quot;<a href="https://idp.protectnetwork.org/protectnetwork-idp">https://idp.protectnetwork.org/protectnetwork-idp</a>&quot; SPNameQualifier=&quot;<a href="https://shibboleth-sp.prod.proquest.com/shibboleth">https://shibboleth-sp.prod.proquest.com/shibboleth</a>&quot;&gt;_9bb96ec9cfd8e577cd63bda7ece0dc84&lt;/saml2:NameID&gt;&lt;saml2:SubjectConfirmation Method=&quot;urn:oasis:names:tc:SAML:2.0:cm:bearer&quot;&gt;&lt;saml2:SubjectConfirmationData Address=&quot;165.215.165.5&quot; InResponseTo=&quot;_ed4ef80e9642b1cd552f9372de0a5875&quot; NotOnOrAfter=&quot;2014-11-13T08:52:40.964Z&quot; Recipient=&quot;<a href="https://shibboleth-sp.prod.proquest.com/Shibboleth.sso/SAML2/POST">https://shibboleth-sp.prod.proquest.com/Shibboleth.sso/SAML2/POST</a>&quot;/&gt;&lt;/saml2:SubjectConfirmation&gt;&lt;/saml2:Subject&gt;&lt;saml2:Conditions NotBefore=&quot;2014-11-13T08:47:40.964Z&quot; NotOnOrAfter=&quot;2014-11-13T08:52:40.964Z&quot;&gt;&lt;saml2:AudienceRestriction&gt;&lt;saml2:Audience&gt;<a href="https://shibboleth-sp.prod.proquest.com/shibboleth">https://shibboleth-sp.prod.proquest.com/shibboleth</a>&lt;/saml2:Audience&gt;&lt;/saml2:AudienceRestriction&gt;&lt;/saml2:Conditions&gt;&lt;saml2:AuthnStatement AuthnInstant=&quot;2014-11-13T08:38:11.807Z&quot; SessionIndex=&quot;6f5b00dba53cf5edb824e0193ebe45af60e741b3489c38162ce775a56210bc1f&quot;&gt;&lt;saml2:SubjectLocality Address=&quot;165.215.165.5&quot;/&gt;&lt;saml2:AuthnContext&gt;&lt;saml2:AuthnContextClassRef&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport&lt;/saml2:AuthnContextClassRef&gt;&lt;/saml2:AuthnContext&gt;&lt;/saml2:AuthnStatement&gt;&lt;saml2:AttributeStatement&gt;&lt;saml2:Attribute FriendlyName=&quot;eduPersonPrincipalName&quot; Name=&quot;urn:oid:1.3.6.1.4.1.5923.1.1.1.6&quot; NameFormat=&quot;urn:oasis:names:tc:SAML:2.0:attrname-format:uri&quot;&gt;&lt;saml2:AttributeValue xmlns:xsi=&quot;<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>&quot; xsi:type=&quot;xs:string&quot;&gt;<a href="mailto:cbsvq@idp.protectnetwork.org">cbsvq@idp.protectnetwork.org</a>&lt;/saml2:AttributeValue&gt;&lt;/saml2:Attribute&gt;&lt;saml2:Attribute FriendlyName=&quot;sn&quot; Name=&quot;urn:oid:2.5.4.4&quot; NameFormat=&quot;urn:oasis:names:tc:SAML:2.0:attrname-format:uri&quot;&gt;&lt;saml2:AttributeValue xmlns:xsi=&quot;<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>&quot; xsi:type=&quot;xs:string&quot;&gt;Blanca Sancho&lt;/saml2:AttributeValue&gt;&lt;/saml2:Attribute&gt;&lt;saml2:Attribute FriendlyName=&quot;givenName&quot; Name=&quot;urn:oid:2.5.4.42&quot; NameFormat=&quot;urn:oasis:names:tc:SAML:2.0:attrname-format:uri&quot;&gt;&lt;saml2:AttributeValue xmlns:xsi=&quot;<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>&quot; xsi:type=&quot;xs:string&quot;&gt;Cristina&lt;/saml2:AttributeValue&gt;&lt;/saml2:Attribute&gt;&lt;saml2:Attribute FriendlyName=&quot;eduPersonTargetedID&quot; Name=&quot;urn:oid:1.3.6.1.4.1.5923.1.1.1.10&quot; NameFormat=&quot;urn:oasis:names:tc:SAML:2.0:attrname-format:uri&quot;&gt;&lt;saml2:AttributeValue&gt;&lt;saml2:NameID Format=&quot;urn:oasis:names:tc:SAML:2.0:nameid-format:persistent&quot; NameQualifier=&quot;<a href="https://idp.protectnetwork.org/protectnetwork-idp">https://idp.protectnetwork.org/protectnetwork-idp</a>&quot; SPNameQualifier=&quot;<a href="https://shibboleth-sp.prod.proquest.com/shibboleth">https://shibboleth-sp.prod.proquest.com/shibboleth</a>&quot;&gt;ZZHp7U/oKEG/p3N8wO4qWB1PhqQ=&lt;/saml2:NameID&gt;&lt;/saml2:AttributeValue&gt;&lt;/saml2:Attribute&gt;&lt;saml2:Attribute FriendlyName=&quot;displayName&quot; Name=&quot;urn:oid:2.16.840.1.113730.3.1.241&quot; NameFormat=&quot;urn:oasis:names:tc:SAML:2.0:attrname-format:uri&quot;&gt;&lt;saml2:AttributeValue xmlns:xsi=&quot;<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>&quot; xsi:type=&quot;xs:string&quot;&gt;Cristina Blanca Sancho&lt;/saml2:AttributeValue&gt;&lt;/saml2:Attribute&gt;&lt;/saml2:AttributeStatement&gt;&lt;/saml2:Assertion&gt;<br>2014-11-13 08:47:42 DEBUG Shibboleth.SSO.SAML2 [92]: extracting issuer from SAML 2.0 assertion<br>2014-11-13 08:47:42 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [92]: evaluating message flow policy (replay checking on, expiration 60)<br>2014-11-13 08:47:42 DEBUG XMLTooling.StorageService [92]: inserted record (_3cbe96a95c2a597c3c4df1bcced595ad) in context (MessageFlow) with expiration (1415868700)<br>2014-11-13 08:47:42 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [92]: validating signature profile<br>2014-11-13 08:47:42 DEBUG XMLTooling.CredentialCriteria [92]: keys didn&#39;t match<br>2014-11-13 08:47:42 DEBUG XMLTooling.TrustEngine.ExplicitKey [92]: unable to validate signature, no credentials available from peer<br>2014-11-13 08:47:42 DEBUG XMLTooling.TrustEngine.PKIX [92]: validating signature using certificate from within the signature<br>2014-11-13 08:47:42 DEBUG XMLTooling.TrustEngine.PKIX [92]: signature verified with key inside signature, attempting certificate validation...<br>2014-11-13 08:47:42 DEBUG XMLTooling.TrustEngine.PKIX [92]: checking that the certificate name is acceptable<br>2014-11-13 08:47:42 DEBUG XMLTooling.TrustEngine.PKIX [92]: adding to list of trusted names (<a href="https://idp.protectnetwork.org/protectnetwork-idp">https://idp.protectnetwork.org/protectnetwork-idp</a>)<br>2014-11-13 08:47:42 DEBUG XMLTooling.TrustEngine.PKIX [92]: certificate subject: CN=<a href="http://tcas-idp.protectnetwork.org">tcas-idp.protectnetwork.org</a>,O=ProtectNetwork,L=Austin,ST=Texas,C=US<br>2014-11-13 08:47:42 DEBUG XMLTooling.TrustEngine.PKIX [92]: unable to match DN, trying TLS subjectAltName match<br>2014-11-13 08:47:42 DEBUG XMLTooling.TrustEngine.PKIX [92]: unable to match subjectAltName, trying TLS CN match<br>2014-11-13 08:47:42 ERROR XMLTooling.TrustEngine.PKIX [92]: certificate name was not acceptable<br>2014-11-13 08:47:42 ERROR OpenSAML.SecurityPolicyRule.XMLSigning [92]: unable to verify message signature with supplied trust engine<br>2014-11-13 08:47:42 WARN Shibboleth.SSO.SAML2 [92]: detected a problem with assertion: Message was signed, but signature could not be verified.<br>=================================================<br><br></div><div>The line from above<br><br>2014-11-13 08:47:42 DEBUG XMLTooling.TrustEngine.PKIX [92]: certificate 
subject: 
CN=<a href="http://tcas-idp.protectnetwork.org">tcas-idp.protectnetwork.org</a>,O=ProtectNetwork,L=Austin,ST=Texas,C=US<br><br></div><div>I think is the ProtectNetwork IdP associated with the UK federation (which seems to have a different certificate).<br><br></div><div>At this point I am somewhat clueless as to why this happens.<br><br></div><div>Thanks<br></div><div>Paul Wilt<br></div><div><br></div><div><br></div><div><br></div></div>