<div dir="ltr"><div><div><div>Thought to share - as it was unique case.<br><br></div>Setting NTP on the Windows2012R2 and rebooting - resolved it.<br><br></div>It was hosted on blade VM cluster - there may have been a shared filesystem with another sp-cert.pem file - if there was, it was not found, and the shibboleth2.xml explicitly pointed to PEM file which was imported to IdP.<br><br></div>Puzzled....working now!<br><div> <br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On 11 July 2015 at 14:18, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 7/10/15, 8:05 PM, "users on behalf of Joel Leibovitz" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:joelleobovitz@gmail.com">joelleobovitz@gmail.com</a>> wrote:<br>
<br>
>SP: Latest Shibboleth version on Windows 2012R2 64 bit<br>
>IdP: V2.4x - has over 300 SPs integrated without any issues.<br>
<br>
</span>If they're both Shibboleth, then the issue is the metadata, plain and simple.<br>
<span class=""><br>
>I have made doubly sure the 'sp-cert.pem' was entered correctly in the IdP (as we had done countless of other times) - but no go.<br>
<br>
</span>Then that in fact is not true. You probably are modifying the wrong metadata or it isn't being successfully loaded. Or there's a duplicate metadata entry for the SP trumping the one you're changing. This is a metadata issue.<br>
<div class="HOEnZb"><div class="h5"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>