<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
pre
        {mso-style-priority:99;
        mso-style-link:"HTML Preformatted Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
span.HTMLPreformattedChar
        {mso-style-name:"HTML Preformatted Char";
        mso-style-priority:99;
        mso-style-link:"HTML Preformatted";
        font-family:"Courier New";}
.MsoChpDefault
        {mso-style-type:export-only;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">Hello,<o:p></o:p></p>
<p class="MsoNormal"> This is my first time setting up Shibboleth and I’m running into an error when attempting to test authentication on testshib. To provide some background, I’m running Shibboleth IdP 2.4.3 linked to Active Directory. I’m
also using the self-signed SSL certificate that was generated during the installation but have created a separate keystore for Tomcat to eliminate certificate errors on the login page.
<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">On testshib, I’m able to plug in our URL and get to the login page but when entering valid login credentials am presented with an “opensaml::FatalProfileException at (<a href="https://sp.testshib.org/Shibboleth.sso/SAML2/POST">https://sp.testshib.org/Shibboleth.sso/SAML2/POST</a>)”
error. If I enter invalid login credentials, however, I do get a ‘Login has failed’ message which seems to indicate that Shibboleth is communicating successfully with our AD. Below are the last few lines of the shibd.log. If anyone has any suggestions or
pointers on where to look next it would be greatly appreciated.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New"">2014-12-31 16:51:15 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [5]: validating signature profile<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New"">2014-12-31 16:51:15 DEBUG XMLTooling.CredentialCriteria [5]: keys didn't match<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New"">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.ExplicitKey [5]: unable to validate signature, no credentials available from peer<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New"">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: validating signature using certificate from within the signature<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New"">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: signature verified with key inside signature, attempting certificate validation...<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New"">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: checking that the certificate name is acceptable<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New"">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: adding to list of trusted names (https://shibboleth.nsc.edu/idp/shibboleth)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New"">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: certificate subject: CN=shibboleth.nsc.edu<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New"">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: unable to match DN, trying TLS subjectAltName match<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New"">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: matched DNS/URI subjectAltName to a key name (https://shibboleth.nsc.edu/idp/shibboleth)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New"">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: performing certificate path validation...<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New"">2014-12-31 16:51:15 DEBUG XMLTooling.TrustEngine.PKIX [5]: failed to validate certificate chain using supplied PKIX information<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New"">2014-12-31 16:51:15 ERROR OpenSAML.SecurityPolicyRule.XMLSigning [5]: unable to verify message signature with supplied trust engine<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New"">2014-12-31 16:51:15 WARN Shibboleth.SSO.SAML2 [5]: detected a problem with assertion: Message was signed, but signature could not be verified.<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thanks,<o:p></o:p></p>
<p class="MsoNormal">Brian<o:p></o:p></p>
</div>
</body>
</html>