<div dir="ltr"><span style="font-size:12.8000001907349px">I've seen this error on a few occasions looking back through Google and the resolution has often been certificate regeneration, or entityID mis-match etc.</span><div style="font-size:12.8000001907349px"><br></div><div style="font-size:12.8000001907349px">This is my second setup - having configured correctly using my local machine, but moving to an Amazon AWS instance I cannot get past this issue. Log entries: </div><div style="font-size:12.8000001907349px"><br></div><div style="font-size:12.8000001907349px"><pre style="white-space:pre-wrap;color:rgb(0,0,0);word-wrap:break-word">06:00:47.357 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:927] - Could not resolve a key encryption credential for peer entity: <a href="https://jci.projectcue.technology/shibboleth" target="_blank">https://jci.projectcue.technology/shibboleth</a>
06:00:47.357 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:289] - Unable to construct encrypter
org.opensaml.xml.security.SecurityException: Could not resolve key encryption credential
        at edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler.getEncrypter(AbstractSAML2ProfileHandler.java:928) ~[shibboleth-identityprovider-2.4.0.jar:na]</pre><pre style="white-space:pre-wrap;color:rgb(0,0,0);word-wrap:break-word"><span style="color:rgb(34,34,34);font-family:arial,sans-serif;white-space:normal"><br></span></pre><pre style="white-space:pre-wrap;color:rgb(0,0,0);word-wrap:break-word"><span style="color:rgb(34,34,34);font-family:arial,sans-serif;white-space:normal">And metadata uploaded to testshib:</span><br></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><pre style="white-space:pre-wrap;word-wrap:break-word"><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal"><br></span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal"><md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" ID="_d515bcc288e5df92e95c5973cee5fd2d4a302d4f" entityID="<a href="https://jci.projectcue.technology/shibboleth" target="_blank">https://jci.projectcue.technology/shibboleth</a>"></span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal"> <md:Extensions xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport"></span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal"> <alg:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#sha512" target="_blank">http://www.w3.org/2001/04/xmlenc#sha512</a>"/></span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><span style="white-space:normal;font-family:monospace,monospace">...</span></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><span style="white-space:normal;font-family:monospace,monospace"> <alg:SigningMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512" target="_blank">http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512</a>"/></span><br></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">...</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal"> </md:Extensions></span></font><font face="monospace, monospace"><span style="white-space:normal"><br></span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal"> <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol"></span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal"> <md:Extensions></span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal"> <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="<a href="https://jci.projectcue.technology/Shibboleth.sso/Login" target="_blank">https://jci.projectcue.technology/Shibboleth.sso/Login</a>"/></span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal"> </md:Extensions></span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal"> <md:KeyDescriptor></span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal"> <ds:KeyInfo xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#" target="_blank">http://www.w3.org/2000/09/xmldsig#</a>"></span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal"> <ds:KeyName>ip-172-31-13-44.us-west-2.compute.internal</ds:KeyName></span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal"> <ds:X509Data></span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal"> <ds:X509SubjectName>CN=ip-172-31-13-44.us-west-2.compute.internal</ds:X509SubjectName></span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal"> <ds:X509Certificate>MIIDRTCCAi2gAw</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">...</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal"></ds:X509Certificate></span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal"> </ds:X509Data></span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal"> </ds:KeyInfo></span></font></pre></pre><div style="font-family:arial,sans-serif;white-space:normal">gives me the Unable to encrypt Assertion response.</div><div style="font-family:arial,sans-serif;white-space:normal"><br></div><div style="font-family:arial,sans-serif;white-space:normal">Can anyone shed any light on why the MetadataCredentialResolver can't resolve a credential for my entityID?</div><div style="font-family:arial,sans-serif;white-space:normal"><br></div><div style="font-family:arial,sans-serif;white-space:normal"><br></div><div style="font-family:arial,sans-serif;white-space:normal">Chris</div></pre></div>
</div>