<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body dir="auto">
<div>Marvin,</div>
<div>The vendor is not using the Shibboleth SP, but what appears to be homegrown SAML integration. &nbsp;It would not surprise me if they did not handle the new line properly on their end. &nbsp;My best chance for quick resolution would be to prevent it from being sent
 in the first place.&nbsp;<br>
- James</div>
<div><br>
On Mar 2, 2015, at 4:53 PM, Marvin Addison &lt;<a href="mailto:marvin.addison@gmail.com">marvin.addison@gmail.com</a>&gt; wrote:<br>
<br>
</div>
<blockquote type="cite">
<div>
<div dir="ltr">
<div class="gmail_quote">
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div>
<div style="direction:ltr;font-family:Tahoma;color:#000000;font-size:10pt">I've enabled SAML logging within both the IdP2 and IdP3 environment and have noticed that the IdP 3.0 assertion contains a &quot;&amp;#xD;&quot; after every line of the X509 certificate that is not
 present in the logs for the 2.0 IdP. Is it possible that this is throwing off the signature validation?<br>
</div>
</div>
</blockquote>
<div><br>
</div>
<div>I noticed the weird characters in the SP logs as well recently while troubleshooting an integration with our new IdPv3 instance. I worked through the problem eventually without changing certs on either endpoint, so I chalked it up to a logging artifact
 on the SP side. Still may be a bug, but not a signature validation bug afaict.</div>
<div><br>
</div>
<div>M</div>
<div><br>
</div>
</div>
</div>
</div>
</blockquote>
<blockquote type="cite">
<div><span>-- </span><br>
<span>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a></span></div>
</blockquote>
</body>
</html>