<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">I am trying to integrate with a SAML2 SP running in Weblogic on my local machine at the following endpoint:
<a href="http://sp.local.com:7001">http://sp.local.com:7001</a>. I initially got the following exception and turned off encryption for SAM2SSOProfile:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">org.opensaml.xml.security.SecurityException: Could not resolve key encryption credential<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">After updating the encryption, I still get a 403: Forbidden error at
<a href="http://sp.local.com:7001/saml2/sp/acs/post">http://sp.local.com:7001/saml2/sp/acs/post</a><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Looking into the idp_process.log, I see the following:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">09:31:25.673 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:599] - Signing assertion to relying party sp.local.com<o:p></o:p></p>
<p class="MsoNormal">09:31:25.695 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:331] - secondarily indexing user session by name identifier<o:p></o:p></p>
<p class="MsoNormal">09:31:25.695 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:796] - Encoding response to SAML request _0x6093c1a51bff748f4b3fe1572f199943 from relying party sp.local.com<o:p></o:p></p>
<p class="MsoNormal">09:31:25.700 - INFO [Shibboleth-Audit:1028] - 20141211T163125Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_0x6093c1a51bff748f4b3fe1572f199943|sp.local.com|urn:mace:shibboleth:2.0:profiles:saml2:sso|https://idp.local.com/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_a556db09c0e6bd3e5eda0021e491be29|tuser|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|transientId,userLogin,|_d23c758a0fe2ef293760d7f52f18ed5f|_474bac62b5e96e90bab1c44f5c66d87d,|<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Any ideas as to why this error is occurring?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>