<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
pre
        {mso-style-priority:99;
        mso-style-link:"HTML Preformatted Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
span.HTMLPreformattedChar
        {mso-style-name:"HTML Preformatted Char";
        mso-style-priority:99;
        mso-style-link:"HTML Preformatted";
        font-family:"Courier New";}
.MsoChpDefault
        {mso-style-type:export-only;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">Hello,<o:p></o:p></p>
<p class="MsoNormal">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; This is my first time setting up Shibboleth and I&#8217;m running into an error when attempting to test authentication on testshib.&nbsp; To provide some background, I&#8217;m running Shibboleth IdP 2.4.3 linked to Active Directory.&nbsp; I&#8217;m
 also using the self-signed SSL certificate that was generated during the installation but have created a separate keystore for Tomcat to eliminate certificate errors on the login page.&nbsp;
<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">On testshib, I&#8217;m able to plug in our URL and get to the login page but when entering valid login credentials am presented with an &#8220;opensaml::FatalProfileException at (<a href="https://sp.testshib.org/Shibboleth.sso/SAML2/POST">https://sp.testshib.org/Shibboleth.sso/SAML2/POST</a>)&#8221;
 error.&nbsp; If I enter invalid login credentials, however, I do get a &#8216;Login has failed&#8217; message which seems to indicate that Shibboleth is communicating successfully with our AD.&nbsp; Below are the last few lines of the shibd.log.&nbsp; If anyone has any suggestions or
 pointers on where to look next it would be greatly appreciated.<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Courier New&quot;">2014-12-31 16:51:15 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [5]: validating signature profile<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Courier New&quot;">2014-12-31 16:51:15 DEBUG XMLTooling.CredentialCriteria [5]: keys didn't match<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Courier New&quot;">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.ExplicitKey [5]: unable to validate signature, no credentials available from peer<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Courier New&quot;">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: validating signature using certificate from within the signature<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Courier New&quot;">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: signature verified with key inside signature, attempting certificate validation...<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Courier New&quot;">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: checking that the certificate name is acceptable<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Courier New&quot;">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: adding to list of trusted names (https://shibboleth.nsc.edu/idp/shibboleth)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Courier New&quot;">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: certificate subject: CN=shibboleth.nsc.edu<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Courier New&quot;">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: unable to match DN, trying TLS subjectAltName match<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Courier New&quot;">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: matched DNS/URI subjectAltName to a key name (https://shibboleth.nsc.edu/idp/shibboleth)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Courier New&quot;">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: performing certificate path validation...<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Courier New&quot;">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: failed to validate certificate chain using supplied PKIX information<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Courier New&quot;">2014-12-31 16:51:15 ERROR OpenSAML.SecurityPolicyRule.XMLSigning [5]: unable to verify message signature with supplied trust engine<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:&quot;Courier New&quot;">2014-12-31 16:51:15 WARN Shibboleth.SSO.SAML2 [5]: detected a problem with assertion: Message was signed, but signature could not be verified.<o:p></o:p></span></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">Thanks,<o:p></o:p></p>
<p class="MsoNormal">Brian<o:p></o:p></p>
</div>
</body>
</html>