<div dir="ltr"><div><div><div><div>I have been working on this for past few hours - wondering if anyone has tips on what I could have missed.<br><br></div>SP: Latest Shibboleth version on Windows 2012R2 64 bit<br></div>IdP: V2.4x - has over 300 SPs integrated without any issues.<br><br></div>I have made doubly sure the 'sp-cert.pem' was entered correctly in the IdP (as we had done countless of other times) - but no go.<br><br></div>Exract from log file:<br><div><br>16:26:19.039 - DEBUG [org.opensaml.xml.security.credential.criteria.EvaluableCredentialCriteriaRegistry:75] - Registry located evaluable criteria class org.opensam<br>l.xml.security.credential.criteria.EvaluableKeyAlgorithmCredentialCriteria for criteria class org.opensaml.xml.security.criteria.KeyAlgorithmCriteria<br>16:26:19.040 - DEBUG [org.opensaml.xml.security.credential.criteria.EvaluableCredentialCriteriaRegistry:75] - Registry located evaluable criteria class org.opensam<br>l.xml.security.credential.criteria.EvaluableEntityIDCredentialCriteria for criteria class org.opensaml.xml.security.criteria.EntityIDCriteria<br>16:26:19.040 - DEBUG [org.opensaml.xml.security.credential.criteria.EvaluableCredentialCriteriaRegistry:106] - Registry could not locate evaluable criteria for cri<br>teria class org.opensaml.security.MetadataCriteria<br>16:26:19.040 - DEBUG [org.opensaml.xml.security.credential.criteria.EvaluableCredentialCriteriaRegistry:75] - Registry located evaluable criteria class org.opensam<br>l.xml.security.credential.criteria.EvaluableUsageCredentialCriteria for criteria class org.opensaml.xml.security.criteria.UsageCriteria<br>16:26:19.041 - DEBUG [org.opensaml.xml.signature.impl.ExplicitKeySignatureTrustEngine:153] - Attempting to verify signature using trusted credentials<br>16:26:19.041 - DEBUG [org.opensaml.xml.security.SigningUtil:238] - Verifying signature over input using public key of type RSA and JCA algorithm ID SHA1withRSA<br>16:26:19.043 - DEBUG [org.opensaml.xml.signature.impl.ExplicitKeySignatureTrustEngine:161] - Failed to verify signature using either supplied candidate credential <br>or directly trusted credentials<br>16:26:19.043 - DEBUG [org.opensaml.xml.signature.impl.PKIXSignatureTrustEngine:170] - Candidate credential was either not supplied or did not contain verification <br>key<br>16:26:19.043 - DEBUG [org.opensaml.xml.signature.impl.PKIXSignatureTrustEngine:171] - PKIX trust engine requires supplied key, skipping PKIX trust evaluation<br>16:26:19.044 - WARN [org.opensaml.common.binding.security.BaseSAMLSimpleSignatureSecurityPolicyRule:194] - Simple signature validation (with no request-derived cre<br>dentials) failed<br>16:26:19.044 - WARN [org.opensaml.common.binding.security.BaseSAMLSimpleSignatureSecurityPolicyRule:137] - Validation of request simple signature failed for contex<br>t issuer: <a href="https://sp.foobar.edu/shibboleth-sp">https://sp.foobar.edu/shibboleth-sp</a><br><div><br><br></div></div></div><div class="gmail_extra"><br><div class="gmail_quote">On 8 July 2015 at 17:36, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 7/8/15, 8:21 PM, "users on behalf of Joel Leibovitz" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:joelleobovitz@gmail.com">joelleobovitz@gmail.com</a>> wrote:<br>
<br>
<br>
<br>
>Is there to find value sent by the SP - either from logs or headers?<br>
<br>
</span>It isn't sent. That's why use of PKIX is impossible with that binding, you either know the key or you don't.<br>
<div class="HOEnZb"><div class="h5"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>