<div dir="ltr"><div>If I recall from our setup, Box does not expect to deal with encrypted assertions by default, but are capable of doing so. If I remember correctly, this was something I had to ask for from my Box account rep, they flipped a switch on their end, provided alternate metadata, and then we were off to the races.<br><br></div>-Rob<br><br> </div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Jun 11, 2015 at 1:15 PM, Rich Graves <span dir="ltr"><<a href="mailto:rgraves@carleton.edu" target="_blank">rgraves@carleton.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">When I turn off assertion encryption, it fails at "Not checking signature with configured verification cert 04:3B because it does not match the embeded certificate in the signature".<br>
<br>
The fragment "<ds:KeyInfo> <ds:X509Data> <ds:X509Certificate>MIIDujCCAqICCQCPaJ8ioTbhuDANBgkqhkiG9w0BAQUFADCBnjELMAkGA1UEBhMCVVMxEjAQBgNV" is the InCommon Federation Metadata Signing Key. What's that doing in there? I have pretty-printed the XML and *'d out signatures, otherwise this is what is echoed back to me by <a href="https://sso.services.box.net/sp/ACS.saml2" rel="noreferrer" target="_blank">https://sso.services.box.net/sp/ACS.saml2</a> after successful IdP authentication.<br>
<br>
Error - Single Sign-On<br>
<br>
Missing or invalid signature (UNVERIFIED commentary: [Not checking signature with configured verification cert 04:3B because it does not match the embeded certificate in the signature.]) on assertion (ID=_11822ead91053e4308987c3f8a660ff3). All assertions must have valid signatures because the Response was not signed or the system is configured to require a signed assertion from urn:mace:incommon:<a href="http://carleton.edu" rel="noreferrer" target="_blank">carleton.edu</a>. InMessageContext XML:<br>
<br>
<?xml version="1.0"?><br>
<saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="<a href="https://sso.services.box.net/sp/ACS.saml2" rel="noreferrer" target="_blank">https://sso.services.box.net/sp/ACS.saml2</a>" ID="_a94b91185ca73a9071c0c966932acb7c" InResponseTo="U7OpDG8_.Lp8bQkLkfFbRJ6AY9i" IssueInstant="2015-06-11T16:52:58.101Z" Version="2.0"><br>
<saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">urn:mace:incommon:<a href="http://carleton.edu" rel="noreferrer" target="_blank">carleton.edu</a></saml2:Issuer><br>
<saml2p:Status><br>
    <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/><br>
</saml2p:Status><br>
<saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:xs="<a href="http://www.w3.org/2001/XMLSchema" rel="noreferrer" target="_blank">http://www.w3.org/2001/XMLSchema</a>" ID="_11822ead91053e4308987c3f8a660ff3" IssueInstant="2015-06-11T16:52:58.101Z" Version="2.0"><br>
<saml2:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">urn:mace:incommon:<a href="http://carleton.edu" rel="noreferrer" target="_blank">carleton.edu</a></saml2:Issuer><br>
<ds:Signature xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#" rel="noreferrer" target="_blank">http://www.w3.org/2000/09/xmldsig#</a>"><br>
<ds:SignedInfo><br>
    <ds:CanonicalizationMethod Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#" rel="noreferrer" target="_blank">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/><br>
    <ds:SignatureMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#rsa-sha1" rel="noreferrer" target="_blank">http://www.w3.org/2000/09/xmldsig#rsa-sha1</a>"/><br>
    <ds:Reference URI="#_11822ead91053e4308987c3f8a660ff3"><br>
        <ds:Transforms><br>
            <ds:Transform Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature" rel="noreferrer" target="_blank">http://www.w3.org/2000/09/xmldsig#enveloped-signature</a>"/><br>
            <ds:Transform Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#" rel="noreferrer" target="_blank">http://www.w3.org/2001/10/xml-exc-c14n#</a>"><br>
            <ec:InclusiveNamespaces xmlns:ec="<a href="http://www.w3.org/2001/10/xml-exc-c14n#" rel="noreferrer" target="_blank">http://www.w3.org/2001/10/xml-exc-c14n#</a>" PrefixList="xs"/><br>
        </ds:Transform><br>
    </ds:Transforms><br>
    <ds:DigestMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#sha1" rel="noreferrer" target="_blank">http://www.w3.org/2000/09/xmldsig#sha1</a>"/><br>
    <ds:DigestValue>BtA9Aqir/t4FN0ojzRc1pyv4hmM=</ds:DigestValue><br>
</ds:Reference><br>
</ds:SignedInfo><br>
<ds:SignatureValue>BdGZ+tUISGxAZMf/0/**+qIhLWh9/icDj7XiAcESMK9bDkn3pKb/JQCe9rWokXz9cZehMiyIgvRC1S/vpnkxTAbY3Ib41Y2skiO6ePpgvyAET+0JRwwOHorPr3IRDavFBOCpt2k8HFyuA8RPiwssuLI4MMnYEbrhTupLZtsmeEm/X+mX3FVtotb/BD68rwLDaDUkyoK63bVdoilBoJf52AumJU+RUW0o/6KUQpcEO3gHm1tBsb+F10kSgWhiAayAPYbR1hdMC4olxpF10CamO4dXX6hdSDO3CWJXC4Trw==</ds:SignatureValue><br>
<ds:KeyInfo><br>
    <ds:X509Data><br>
        <ds:X509Certificate>MIIDujCCAqICCQCPaJ8ioTbhuDANBgkqhkiG9w0BAQUFADCBnjELMAkGA1UEBhMCVVMxEjAQBgNV BAgTCU1pbm5lc290YTETMBEGA1UEBxMKTm9ydGhmaWVsZDEZMBcGA1UEChMQQ2FybGV0b24gQ29s bGVnZTEMMAoGA1UECxMDSVRTMRswGQYDVQQDExJsb2dpbi5jYXJsZXRvbi5lZHUxIDAeBgkqhkiG 9w0BCQEWEXdsZWVAY2FybGV0b24uZWR1MB4XDTEzMDIyMTIxNTEyMloXDTIzMDIxOTIxNTEyMlow gZ4xCzAJBgNVBAYTAlVTMRIwEAYDVQQIEwlNaW5uZXNvdGExEzARBgNVBAcTCk5vcnRoZmllbGQx GTAXBgNVBAoTEENhcmxldG9uIENvbGxlZ2UxDDAKBgNVBAsTA0lUUzEbMBkGA1UEAxMSbG9naW4u Y2FybGV0b24uZWR1MSAwHgYJKoZIhvcNAQkBFhF3bGVlQGNhcmxldG9uLmVkdTCCASIwDQYJKoZI hvcNAQEBBQADggEPADCCAQoCggEBAJJR4aGU0T4Rs+raiaCBqBp75XUZ+W0rnXVuP4oainijV8oe pLVo0trGRjYgIHhNKufhtuFtvxkgsq/QqaSR6mmCgKU8YH32gGggjwLBRbMn7aNiJu2PNi03g+Nx FW+k3iz/qcuyrkb9CGO5QcqMlWznphotRXXXscm94+SBmJ9aeTL4XIUXfEIOdeDdNqZRjjvuKck8 3Mbqn/4t69uZcrOM0BFQFhJOE5vgJ9kOEBnsS+3dYbEndfK1dXnxp88gLaWY/4GvvOUwQTubsuvy 9/hlyLUpNz/sZFNM7KekQUjKv2/qu3hi+gvl4Dl5LuEbug38XKZDQ75pZOm5PROnhKMCAwEAATAN BgkqhkiG9w0BAQUFAAOCAQEAdTupllJ0sDvllI+4Jgn+Dw<br>
 PTlzOM5I7Y2MVkHtodZCyrT6qRaP4o X369LVG0S3vQbChVi1gW0CljeUl9e616nkaNJ89UhUhN3r9t5412qQ8/Lyq+LX1912yUyCuW8JMQ XFbVlMS0b/FvJmXPYlLpFIf1DGbJW/HYJ07x+5V7hONXUmEvh8SZo+JXmTO37hLOBGSyteXbWJv7 VptIm/fD6411cYLejujXijfbVj38Ijcucjrel7dJ2Zl8nnmkn3VlRFdEuRScuWudI+7rS6Ux+Dwc 25Ls34lI9+W9mXyA7ix0qDjNmpRccdkzLcvfTgYC7q5VGzyToU4S2u7AZvcxeA==</ds:X509Certificate><br>
    </ds:X509Data><br>
</ds:KeyInfo><br>
</ds:Signature><br>
<saml2:Subject><br>
    <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" NameQualifier="urn:mace:incommon:<a href="http://carleton.edu" rel="noreferrer" target="_blank">carleton.edu</a>" SPNameQualifier="<a href="https://services.box.com/sp" rel="noreferrer" target="_blank">https://services.box.com/sp</a>">_ae9e30e7df39432335f58006eeda7130</saml2:NameID><br>
    <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><br>
        <saml2:SubjectConfirmationData Address="**" InResponseTo="U7OpDG8_.Lp8bQkLkfFbRJ6AY9i" NotOnOrAfter="2015-06-11T16:57:58.101Z" Recipient="<a href="https://sso.services.box.net/sp/ACS.saml2" rel="noreferrer" target="_blank">https://sso.services.box.net/sp/ACS.saml2</a>"/><br>
    </saml2:SubjectConfirmation><br>
</saml2:Subject><br>
<saml2:Conditions NotBefore="2015-06-11T16:52:58.101Z" NotOnOrAfter="2015-06-11T16:57:58.101Z"><br>
    <saml2:AudienceRestriction><br>
        <saml2:Audience><a href="https://services.box.com/sp" rel="noreferrer" target="_blank">https://services.box.com/sp</a></saml2:Audience><br>
    </saml2:AudienceRestriction><br>
</saml2:Conditions><br>
<saml2:AuthnStatement AuthnInstant="2015-06-11T16:49:44.586Z" SessionIndex="_edd04d9c807ec9584ced4afff65ba89f"><br>
    <saml2:SubjectLocality Address="**"/><br>
    <saml2:AuthnContext><br>
        <saml2:AuthnContextClassRef>duo</saml2:AuthnContextClassRef><br>
    </saml2:AuthnContext><br>
</saml2:AuthnStatement><br>
<saml2:AttributeStatement><br>
    <saml2:Attribute FriendlyName="sn" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><br>
        <saml2:AttributeValue xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance" rel="noreferrer" target="_blank">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xs:string">Graves</saml2:AttributeValue><br>
    </saml2:Attribute><br>
    <saml2:Attribute FriendlyName="givenName" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><br>
        <saml2:AttributeValue xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance" rel="noreferrer" target="_blank">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xs:string">Rich</saml2:AttributeValue><br>
    </saml2:Attribute><br>
    <saml2:Attribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><br>
        <saml2:AttributeValue xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance" rel="noreferrer" target="_blank">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xs:string"><a href="mailto:rgraves@carleton.edu">rgraves@carleton.edu</a></saml2:AttributeValue><br>
    </saml2:Attribute><br>
    <saml2:Attribute FriendlyName="organizationalUnit" Name="urn:oid:2.5.4.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><br>
        <saml2:AttributeValue xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance" rel="noreferrer" target="_blank">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xs:string">Information Technology Service</saml2:AttributeValue><br>
    </saml2:Attribute><br>
</saml2:AttributeStatement><br>
</saml2:Assertion><br>
</saml2p:Response><br>
<br>
 entityId: urn:mace:incommon:<a href="http://carleton.edu" rel="noreferrer" target="_blank">carleton.edu</a> (IDP) Binding: urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST relayState: Ir8tVTR5NDHyZkHoc3ubo2iXxIMitE SignatureStatus: NOT_PRESENT Binding says to sign: true<br>
<span class="im HOEnZb">Partner: urn:mace:incommon:<a href="http://carleton.edu" rel="noreferrer" target="_blank">carleton.edu</a><br>
Target Resource: <a href="https://app.box.com/sso/ping_federate" rel="noreferrer" target="_blank">https://app.box.com/sso/ping_federate</a><br>
</span><div class="HOEnZb"><div class="h5">--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br><br clear="all"><br>-- <br><div class="gmail_signature"><div dir="ltr"><div>Robert W. Gorrell<br>Systems Architect, Identity and Access Management </div>
<div>University of NC at Greensboro<br><span style="white-space:nowrap">336-334-5954</span><br>PGP Key ID B36DB0CA<br></div></div></div>
</div>