<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <br>
    <div class="moz-cite-prefix">On 1/12/15 3:18 PM, Hong Ye wrote:<br>
    </div>
    <blockquote
      cite="mid:71CE624E-A69C-49C6-9415-5A93BD292F25@cornell.edu"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html;
        charset=windows-1252">
      <div style="margin: 0px; font-size: 11px; font-family: Menlo;">bash-4.1$
        ls -l jdk/jre/lib/ext/</div>
      <br>
      <div><br>
      </div>
      <div>
        <blockquote type="cite">
          <div bgcolor="#FFFFFF" text="#000000"> jre/lib/security/java.security,</div>
        </blockquote>
        <br>
      </div>
    </blockquote>
    <br>
    Yep, those all look fine.  So I'm still baffled.  As Scott
    suggested, if the command-line stuff is working ok, then there's
    something about the Tomcat environment that is preventing the
    standard Java Security provider-based crypto stuff from working the
    way it should.<br>
    <br>
    As an additional debugging step, can you enable DEBUG logging for:<br>
    <br>
    <meta http-equiv="content-type" content="text/html;
      charset=windows-1252">
    org.opensaml.xmlsec.algorithm.
    <meta http-equiv="content-type" content="text/html;
      charset=windows-1252">
    AlgorithmRegistry<br>
    <br>
    and then restart the IdP?  With that, then fairly early in the IdP
    start up process, in the idp-process.log, you should see a lot of
    output (several dozen lines I think) from AlgorithmRegistry, on
    DEBUG, INFO, maybe WARN or ERROR.  Post here please.  It will be
    interesting to see what algorithms it shows as supported at runtime
    and which not.  That may give a hint as to what's going on.<br>
    <br>
    <br>
  </body>
</html>