<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif;">
<div>
<div>
<div>Hi</div>
</div>
</div>
<span id="OLK_SRC_BODY_SECTION">
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif;">
<div>
<div><br>
</div>
<div>I am getting an error  "unable to verify message signature with supplied trust engine" every once in a while with my shibboleth SP setup.  I currently have it sitting behind a F5 will SSL offloading however it is forwarding the 443 traffic for /Shibboleth.sso.
  I have copied the logs for both a working validation and a broken one.  I'm not sure what could be the issue due to the seemingly randomness of the error below.  As you can see below it worked 30 seconds before it didn't work.  Any ideas on how to troubleshoot
 or know of this issue?</div>
<div><br>
</div>
<div>Thanks</div>
<div>Jeff Milligan</div>
<div><br>
</div>
<div>
<div>2015-07-30 11:14:56 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [1]: evaluating message flow policy (replay checking on, expiration 60)</div>
<div>2015-07-30 11:14:56 DEBUG XMLTooling.StorageService [1]: inserted record (b124293104daaebbef7c8ce587229ed1) in context (MessageFlow) with expiration (1438269536)</div>
<div>2015-07-30 11:14:56 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [1]: validating signature profile</div>
<div>2015-07-30 11:14:56 DEBUG XMLTooling.TrustEngine.ExplicitKey [1]: attempting to validate signature with the peer's credentials</div>
<div><span style="background-color: rgb(255, 255, 0);">2015-07-30 11:14:56 DEBUG XMLTooling.TrustEngine.ExplicitKey [1]: public key did not validate signature: Digital signature does not validate with the supplied key.</span></div>
<div><span style="background-color: rgb(255, 255, 0);">2015-07-30 11:14:56 DEBUG XMLTooling.TrustEngine.ExplicitKey [1]: no peer credentials validated the signature</span></div>
<div><span style="background-color: rgb(255, 255, 0);">2015-07-30 11:14:56 ERROR XMLTooling.TrustEngine.PKIX [1]: unable to perform PKIX validation, signature does not contain any certificates</span></div>
<div><span style="background-color: rgb(255, 255, 0);">2015-07-30 11:14:56 ERROR OpenSAML.SecurityPolicyRule.XMLSigning [1]: unable to verify message signature with supplied trust engine</span></div>
<div>2015-07-30 11:14:56 DEBUG Shibboleth.Listener [1]: dispatching message (default/Login::run::SAML2SI)</div>
<div>2015-07-30 11:14:56 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1]: validating input</div>
<div>2015-07-30 11:14:56 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1]: marshalling, deflating, base64-encoding the message</div>
<div>2015-07-30 11:14:56 DEBUG XMLTooling.XMLObject [1]: starting to marshal samlp:AuthnRequest</div>
<div>2015-07-30 11:14:56 DEBUG XMLTooling.XMLObject [1]: creating root element to marshall</div>
<div>2015-07-30 11:14:56 DEBUG XMLTooling.XMLObject [1]: marshalling namespace attributes for XMLObject</div>
<div>2015-07-30 11:14:56 DEBUG XMLTooling.XMLObject [1]: marshalling text and child elements for XMLObject</div>
<div>2015-07-30 11:14:56 DEBUG XMLTooling.XMLObject [1]: starting to marshalling saml:Issuer</div>
<div>2015-07-30 11:14:56 DEBUG XMLTooling.XMLObject [1]: creating root element to marshall</div>
</div>
<div><br>
</div>
<div>
<div>2015-07-30 11:14:36 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [1]: evaluating message flow policy (replay checking on, expiration 60)</div>
<div>2015-07-30 11:14:36 DEBUG XMLTooling.StorageService [1]: inserted record (ff089c24c2bcadd242e5a58408bd5410) in context (MessageFlow) with expiration (1438269516)</div>
<div>2015-07-30 11:14:36 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [1]: validating signature profile</div>
<div>2015-07-30 11:14:36 DEBUG XMLTooling.TrustEngine.ExplicitKey [1]: attempting to validate signature with the peer's credentials</div>
<div><span style="background-color: rgb(255, 255, 0);">2015-07-30 11:14:36 DEBUG XMLTooling.TrustEngine.ExplicitKey [1]: signature validated with credential</span></div>
<div>2015-07-30 11:14:36 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [1]: signature verified against message issuer</div>
<div>2015-07-30 11:14:36 DEBUG Shibboleth.SSO.SAML2 [1]: processing message against SAML 2.0 SSO profile</div>
<div>2015-07-30 11:14:36 DEBUG Shibboleth.SSO.SAML2 [1]: extracting issuer from SAML 2.0 assertion</div>
<div>2015-07-30 11:14:36 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [1]: evaluating message flow policy (replay checking on, expiration 60)</div>
<div>2015-07-30 11:14:36 DEBUG XMLTooling.StorageService [1]: inserted record (bc11f189958a7959efc6a776176f2684) in context (MessageFlow) with expiration (1438269516)</div>
<div>2015-07-30 11:14:36 DEBUG OpenSAML.SecurityPolicyRule.BearerConfirmation [1]: assertion satisfied bearer confirmation requirements</div>
<div>2015-07-30 11:14:36 DEBUG Shibboleth.SSO.SAML2 [1]: SSO profile processing completed successfully</div>
<div>2015-07-30 11:14:36 DEBUG Shibboleth.SSO.SAML2 [1]: extracting pushed attributes...</div>
<div>2015-07-30 11:14:36 DEBUG Shibboleth.AttributeExtractor.XML [1]: unable to extract attributes, unknown XML object type: samlp:Response</div>
<div>2015-07-30 11:14:36 DEBUG Shibboleth.AttributeExtractor.XML [1]: skipping unmapped NameID with format (urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress)</div>
<div>2015-07-30 11:14:36 DEBUG Shibboleth.AttributeExtractor.XML [1]: unable to extract attributes, unknown XML object type: saml:AuthnStatement</div>
<div>2015-07-30 11:14:36 DEBUG Shibboleth.AttributeDecoder.String [1]: decoding SimpleAttribute (EmailID) from SAML 2 Attribute (EmailID) with 1 value(s)</div>
<div>2015-07-30 11:14:36 DEBUG Shibboleth.AttributeFilter [1]: filtering 1 attribute(s) from (<a href="http://fim.emc.com/idp/vcexact">http://fim.emc.com/idp/vcexact</a>)</div>
<div>2015-07-30 11:14:36 DEBUG Shibboleth.AttributeFilter [1]: applying filtering rule(s) for attribute (EmailID) from (<a href="http://fim.emc.com/idp/vcexact">http://fim.emc.com/idp/vcexact</a>)</div>
<div>2015-07-30 11:14:36 DEBUG Shibboleth.SSO.SAML2 [1]: resolving attributes...</div>
<div>2015-07-30 11:14:36 DEBUG Shibboleth.AttributeResolver.Query [1]: found AttributeStatement in input to new session, skipping query</div>
<div>2015-07-30 11:14:36 DEBUG Shibboleth.SessionCache [1]: creating new session</div>
</div>
<div><br>
</div>
<div><br>
</div>
<div><b>Here is the same problem with different log level and different time</b></div>
<div><br>
</div>
<div><br>
</div>
<div>
<div>2015-07-30 10:34:13 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [1]: validating signature profile</div>
<div><span style="background-color: rgb(255, 255, 0);">2015-07-30 10:34:13 DEBUG XMLTooling.KeyInfoResolver.Inline [1]: resolving ds:X509Certificate</span></div>
<div><span style="background-color: rgb(255, 255, 0);">2015-07-30 10:34:13 DEBUG XMLTooling.KeyInfoResolver.Inline [1]: resolved 1 certificate(s)</span></div>
<div><span style="background-color: rgb(255, 255, 0);">2015-07-30 10:34:13 DEBUG XMLTooling.KeyInfoResolver.Inline [1]: resolved 0 CRL(s)</span></div>
<div><span style="background-color: rgb(255, 255, 0);">2015-07-30 10:34:13 ERROR XMLTooling.TrustEngine.PKIX [1]: unable to perform PKIX validation, signature does not contain any certificates</span></div>
<div><span style="background-color: rgb(255, 255, 0);">2015-07-30 10:34:13 ERROR OpenSAML.SecurityPolicyRule.XMLSigning [1]: unable to verify message signature with supplied trust engine</span></div>
<div>2015-07-30 10:34:13 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1]: validating input</div>
<div>2015-07-30 10:34:13 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1]: marshalling, deflating, base64-encoding the message</div>
<div>2015-07-30 10:34:13 DEBUG XMLTooling.XMLObject [1]: starting to marshal samlp:AuthnRequest</div>
<div>2015-07-30 10:34:13 DEBUG XMLTooling.XMLObject [1]: creating root element to marshall</div>
<div>2015-07-30 10:34:13 DEBUG XMLTooling.XMLObject [1]: marshalling namespace attributes for XMLObject</div>
<div>2015-07-30 10:34:13 DEBUG XMLTooling.XMLObject [1]: marshalling text and child elements for XMLObject</div>
<div>2015-07-30 10:34:13 DEBUG XMLTooling.XMLObject [1]: starting to marshalling saml:Issuer</div>
<div>2015-07-30 10:34:13 DEBUG XMLTooling.XMLObject [1]: creating root element to marshall</div>
<div>2015-07-30 10:34:13 DEBUG XMLTooling.XMLObject [1]: marshalling namespace attributes for XMLObject</div>
<div>2015-07-30 10:34:13 DEBUG XMLTooling.XMLObject [1]: marshalling text and child elements for XMLObject</div>
<div>2015-07-30 10:34:13 DEBUG XMLTooling.XMLObject [1]: caching DOM for XMLObject</div>
</div>
<div><br>
</div>
<div>
<div>2015-07-30 10:50:57 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [1]: validating signature profile</div>
<div><span style="background-color: rgb(255, 255, 0);">2015-07-30 10:50:57 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [1]: signature verified against message issuer</span></div>
<div>2015-07-30 10:50:57 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [1]: evaluating message flow policy (replay checking on, expiration 60)</div>
<div>2015-07-30 10:50:57 DEBUG OpenSAML.SecurityPolicyRule.BearerConfirmation [1]: assertion satisfied bearer confirmation requirements</div>
<div>2015-07-30 10:50:57 DEBUG XMLTooling.XMLObject [1]: starting to marshal saml:NameID</div>
<div>2015-07-30 10:50:57 DEBUG XMLTooling.XMLObject [1]: XMLObject has a usable cached DOM, reusing it</div>
<div>2015-07-30 10:50:57 DEBUG XMLTooling.XMLObject [1]: releasing cached DOM representation for parent object with propagation set to true</div>
<div>2015-07-30 10:50:57 DEBUG XMLTooling.XMLObject [1]: releasing cached DOM representation for (saml:Subject)</div>
<div>2015-07-30 10:50:57 DEBUG XMLTooling.XMLObject [1]: releasing cached DOM representation for parent object with propagation set to true</div>
<div>2015-07-30 10:50:57 DEBUG XMLTooling.XMLObject [1]: releasing cached DOM representation for (saml:Assertion)</div>
<div>2015-07-30 10:50:57 DEBUG XMLTooling.XMLObject [1]: releasing cached DOM representation for parent object with propagation set to true</div>
<div>2015-07-30 10:50:57 DEBUG XMLTooling.XMLObject [1]: releasing cached DOM representation for (samlp:Response)</div>
<div>2015-07-30 10:50:57 DEBUG XMLTooling.XMLObject [1]: starting to marshal saml:Assertion</div>
</div>
</div>
<div>
<div id=""></div>
</div>
</div>
</span>
</body>
</html>