<div dir="ltr"><span style="font-size:12.8000001907349px">I&#39;ve seen this error on a few occasions looking back through Google and the resolution has often been certificate regeneration, or entityID mis-match etc.</span><div style="font-size:12.8000001907349px"><br></div><div style="font-size:12.8000001907349px">This is my second setup - having configured correctly using my local machine, but moving to an Amazon AWS instance I cannot get past this issue. Log entries: </div><div style="font-size:12.8000001907349px"><br></div><div style="font-size:12.8000001907349px"><pre style="white-space:pre-wrap;color:rgb(0,0,0);word-wrap:break-word">06:00:47.357 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:927] - Could not resolve a key encryption credential for peer entity: <a href="https://jci.projectcue.technology/shibboleth" target="_blank">https://jci.projectcue.technology/shibboleth</a>
06:00:47.357 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:289] - Unable to construct encrypter
org.opensaml.xml.security.SecurityException: Could not resolve key encryption credential
        at edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler.getEncrypter(AbstractSAML2ProfileHandler.java:928) ~[shibboleth-identityprovider-2.4.0.jar:na]</pre><pre style="white-space:pre-wrap;color:rgb(0,0,0);word-wrap:break-word"><span style="color:rgb(34,34,34);font-family:arial,sans-serif;white-space:normal"><br></span></pre><pre style="white-space:pre-wrap;color:rgb(0,0,0);word-wrap:break-word"><span style="color:rgb(34,34,34);font-family:arial,sans-serif;white-space:normal">And metadata uploaded to testshib:</span><br></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><pre style="white-space:pre-wrap;word-wrap:break-word"><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal"><br></span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">&lt;md:EntityDescriptor xmlns:md=&quot;urn:oasis:names:tc:SAML:2.0:metadata&quot; ID=&quot;_d515bcc288e5df92e95c5973cee5fd2d4a302d4f&quot; entityID=&quot;<a href="https://jci.projectcue.technology/shibboleth" target="_blank">https://jci.projectcue.technology/shibboleth</a>&quot;&gt;</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">  &lt;md:Extensions xmlns:alg=&quot;urn:oasis:names:tc:SAML:metadata:algsupport&quot;&gt;</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">    &lt;alg:DigestMethod Algorithm=&quot;<a href="http://www.w3.org/2001/04/xmlenc#sha512" target="_blank">http://www.w3.org/2001/04/xmlenc#sha512</a>&quot;/&gt;</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><span style="white-space:normal;font-family:monospace,monospace">...</span></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><span style="white-space:normal;font-family:monospace,monospace">    &lt;alg:SigningMethod Algorithm=&quot;<a href="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512" target="_blank">http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512</a>&quot;/&gt;</span><br></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">...</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">  &lt;/md:Extensions&gt;</span></font><font face="monospace, monospace"><span style="white-space:normal"><br></span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">  &lt;md:SPSSODescriptor protocolSupportEnumeration=&quot;urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol&quot;&gt;</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">    &lt;md:Extensions&gt;</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">      &lt;init:RequestInitiator xmlns:init=&quot;urn:oasis:names:tc:SAML:profiles:SSO:request-init&quot; Binding=&quot;urn:oasis:names:tc:SAML:profiles:SSO:request-init&quot; Location=&quot;<a href="https://jci.projectcue.technology/Shibboleth.sso/Login" target="_blank">https://jci.projectcue.technology/Shibboleth.sso/Login</a>&quot;/&gt;</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">    &lt;/md:Extensions&gt;</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">    &lt;md:KeyDescriptor&gt;</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">      &lt;ds:KeyInfo xmlns:ds=&quot;<a href="http://www.w3.org/2000/09/xmldsig#" target="_blank">http://www.w3.org/2000/09/xmldsig#</a>&quot;&gt;</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">        &lt;ds:KeyName&gt;ip-172-31-13-44.us-west-2.compute.internal&lt;/ds:KeyName&gt;</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">        &lt;ds:X509Data&gt;</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">          &lt;ds:X509SubjectName&gt;CN=ip-172-31-13-44.us-west-2.compute.internal&lt;/ds:X509SubjectName&gt;</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">          &lt;ds:X509Certificate&gt;MIIDRTCCAi2gAw</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">...</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">&lt;/ds:X509Certificate&gt;</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">        &lt;/ds:X509Data&gt;</span></font></pre><pre style="white-space:pre-wrap;word-wrap:break-word"><font face="monospace, monospace"><span style="white-space:normal">      &lt;/ds:KeyInfo&gt;</span></font></pre></pre><div style="font-family:arial,sans-serif;white-space:normal">gives me the Unable to encrypt Assertion response.</div><div style="font-family:arial,sans-serif;white-space:normal"><br></div><div style="font-family:arial,sans-serif;white-space:normal">Can anyone shed any light on why the MetadataCredentialResolver can&#39;t resolve a credential for my entityID?</div><div style="font-family:arial,sans-serif;white-space:normal"><br></div><div style="font-family:arial,sans-serif;white-space:normal"><br></div><div style="font-family:arial,sans-serif;white-space:normal">Chris</div></pre></div>
</div>