<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=iso-8859-15">
</head>
<body bgcolor="#FFFFFF" text="#000000">
I'm currently trying to check a ServiceProvider configuration
against testshib.org (using testshib.org as an IdP),<br>
but testshib.org si currently failing with the following traceback:<br>
<br>
<meta charset="utf-8">
12:07:04.650 - ERROR
[edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:927]
- Could not resolve a key encryption credential for peer entity:
<a class="moz-txt-link-freetext" href="https://localhost/sprovide.xml">https://localhost/sprovide.xml</a><br>
12:07:04.651 - ERROR
[edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:289]
- Unable to construct encrypter<br>
org.opensaml.xml.security.SecurityException: Could not resolve key
encryption credential<br>
at
edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler.getEncrypter(AbstractSAML2ProfileHandler.java:928)
~[shibboleth-identityprovider-2.4.0.jar:na]<br>
at
edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler.buildResponse(AbstractSAML2ProfileHandler.java:286)
~[shibboleth-identityprovider-2.4.0.jar:na]<br>
<br>
I'm able to get to the login page and login with the myself-myself
user, but then that traceback is produced when trying to send back
the answer to my application.<br>
Here is the service provider .xml file uploaded to
<a class="moz-txt-link-freetext" href="http://www.testshib.org/register.html">http://www.testshib.org/register.html</a><br>
<br>
<meta http-equiv="content-type" content="text/html;
charset=iso-8859-15">
<meta http-equiv="content-type" content="text/html;
charset=iso-8859-15">
<?xml version='1.0' encoding='UTF-8'?><br>
<ns0:EntityDescriptor
xmlns:ns0="urn:oasis:names:tc:SAML:2.0:metadata"
xmlns:xs=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2001/XMLSchema">"http://www.w3.org/2001/XMLSchema"</a><br>
xmlns:ns1="urn:oasis:names:tc:SAML:metadata:attribute"<br>
xmlns:ns2="urn:oasis:names:tc:SAML:2.0:assertion"
xmlns:ns4=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2000/09/xmldsig#">"http://www.w3.org/2000/09/xmldsig#"</a><br>
xmlns:xsi=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2001/XMLSchema-instance">"http://www.w3.org/2001/XMLSchema-instance"</a>
entityID=<a class="moz-txt-link-rfc2396E" href="https://localhost/sprovide.xml">"https://localhost/sprovide.xml"</a>><br>
<ns0:Extensions><br>
<ns1:EntityAttributes><br>
<ns2:Attribute
Name=<a class="moz-txt-link-rfc2396E" href="http://macedir.org/entity-category">"http://macedir.org/entity-category"</a><br>
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><br>
<ns2:AttributeValue
xsi:type="xs:string"><a class="moz-txt-link-freetext" href="http://www.geant.net/uri/dataprotection-code-of-conduct/v1">http://www.geant.net/uri/dataprotection-code-of-conduct/v1</a><br>
</ns2:AttributeValue><br>
</ns2:Attribute><br>
</ns1:EntityAttributes><br>
</ns0:Extensions><br>
<ns0:SPSSODescriptor AuthnRequestsSigned="false"
WantAssertionsSigned="true"<br>
protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"><br>
<ns0:KeyDescriptor use="signing"><br>
<ns4:KeyInfo><br>
<ns4:X509Data><br>
<ns4:X509Certificate>MIIC7zCCAdegAwIBAgIJAKNUFVpcL0KLMA0GCSqGSIb3DQEBBQUAMBIxEDAOBgNV<br>
BAMTB0xQdWxzYXIwHhcNMTUxMDA1MTYwNTAyWhcNMjUxMDAyMTYwNTAyWjASMRAw<br>
DgYDVQQDEwdMUHVsc2FyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA<br>
04Dvyk0OAmkcjFIzptAJyluGcfP8WsmdE01XOvIV0bi40Cc1c3SCfdXM+AU7kiz6<br>
Ew37m9kXz1FbIw9n9Zsv3ImJ7lqQ1/ZKUkzB/Aj49p85XsoqMwtRq8Zwun9sLAME<br>
+sjWh4+OyQH2Dr/Na7WnafuuYeIl72rFAoUg2IDEodZ5b204suKp1qi0GQwYm2Jp<br>
Ahh0f46RhXawcYVmTMPUS6XQjJ+WH95sDxxxV6Yjfw7d3uZNQ+cNAec7hFxSSAka<br>
nShkimm6KfC5x04jgjz1YA4iNXPoj2Pi2E0l3EBl16qBmhjXoppagriHfN+xIxcD<br>
hEggCSaYLui2Qm/8maeqQwIDAQABo0gwRjAlBgNVHREEHjAcggdMUHVsc2FyhhFo<br>
dHRwczovL2xvY2FsaG9zdDAdBgNVHQ4EFgQUQbbmEqIJlFT8GRdSPE56N+dGZi8w<br>
DQYJKoZIhvcNAQEFBQADggEBAC8jKuZWkHx/AhM1GL2vHq/h9SxHoHFcyYDipVyC<br>
Ql5VB5PjTaLdQ9RZCtJhlJa75DeVfW6hncDY5Q2phb7MwH2GfWm/bZwmPyfwsEeI<br>
uzOcfyWU24582ITtWBNGkaxkE3uI5cDRvmKfO6fTrAdvw+emtVzYOUcAxzqz0PAQ<br>
B5f2jLbg2sTLB6d4KawGPoq3JtVXPgagIANZ5IsR/dem3FIsZFj8nsztibFFTH/O<br>
ljUAfZledVW5KIfApmHMc4qLvAuSSOSmax6ksBjPE4LVZx/9iftHQOMsucW1O4Ob<br>
ykh4ttyYdRoNP1es5xuzTF3Qw2XRMK1N4ZgFsOQudlEexik=<br>
</ns4:X509Certificate><br>
</ns4:X509Data><br>
</ns4:KeyInfo><br>
</ns0:KeyDescriptor><br>
<ns0:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"<br>
Location=<a class="moz-txt-link-rfc2396E" href="https://localhost/slo/redirect">"https://localhost/slo/redirect"</a>/><br>
<ns0:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"<br>
Location=<a class="moz-txt-link-rfc2396E" href="https://localhost/slo/post">"https://localhost/slo/post"</a>/><br>
<ns0:AssertionConsumerService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"<br>
Location=<a class="moz-txt-link-rfc2396E" href="https://localhost/acs/post">"https://localhost/acs/post"</a> index="1"/><br>
</ns0:SPSSODescriptor><br>
</ns0:EntityDescriptor><br>
<br>
We are currently using PySAML2 which has also generated the previous
XML.<br>
It something wrong that I'm missing? The whole testshib.org
traceback is attached to the email<br>
<br>
<br>
<pre class="moz-signature" cols="72">--
Alessandro Molina
Chief Technical Officer & Director of Operations
Axant s.n.c. - <a class="moz-txt-link-freetext" href="http://www.axant.it">http://www.axant.it</a>
Phone: +39 346 739 9923
Fax: +39 011 412 1756</pre>
</body>
</html>