<div dir="ltr">I have a FileBackedHTTPMetadataProvider that we do SignatureValidation on and requireSignedMetadata. Recently, after my IdP reloaded metadata from this federation, it decided not to load with the following fatal errors:<br><br clear="all"><div><div>11:02:00.519 - ERROR [org.opensaml.saml2.metadata.provider.SignatureValidationFilter:311] - Signature trust establishment failed for metadata entry <a href="https://odapilib.libraryreserve.com/FederatedAuthentication/saml/trust">https://odapilib.libraryreserve.com/FederatedAuthentication/saml/trust</a><br>11:02:00.520 - ERROR [org.opensaml.saml2.metadata.provider.SignatureValidationFilter:254] - EntityDescriptor '<a href="https://odapilib.libraryreserve.com/FederatedAuthentication/saml/trust">https://odapilib.libraryreserve.com/FederatedAuthentication/saml/trust</a>' failed signature verification, removing from metadata provider<br>11:02:00.540 - ERROR [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:411] - Metadata provider failed to properly initializing, halting<br>org.opensaml.saml2.metadata.provider.MetadataProviderException: java.lang.UnsupportedOperationException<br>11:02:00.546 - ERROR [edu.internet2.middleware.shibboleth.common.config.BaseService:188] - Configuration was not loaded for shibboleth.RelyingPartyConfigurationManager service, error creating components. The root cause of this error was: java.lang.UnsupportedOperationException: null<br><br></div><div>Obviously, there is an entity in the metadata that fails signature validation, but should that stop my IdP from loading? or simply omit that entity but continue on? What would control something like that?<br><br></div><div>I spoke to another member of this federation who receives the same two first errors about the failed signature validation, however, his IdP keeps trucking and doesn't fail with the last two errors that mine does. I'm trying to figure out if there is a setting that makes our IdP more stringent when it comes to encountering this type of error in downloaded metadata?<br><br></div><div>Thanks<br></div><div>-Rob<br><br></div><div>-- <br><div class="gmail_signature"><div dir="ltr"><div>Robert W. Gorrell<br>Systems Architect, Identity and Access Management </div>
<div>University of NC at Greensboro<br><span style="white-space:nowrap">336-334-5954</span><br>PGP Key ID B36DB0CA<br></div></div></div>
</div></div></div>