<html>
<head>
<meta content="text/html; charset=utf-8" http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<div class="moz-cite-prefix">Il 05/10/15 19:43, Kevin Foote ha
scritto:<br>
</div>
<blockquote
cite="mid:46A9D311-1487-4054-B21F-DC8DF82F8C9E@uoregon.edu"
type="cite">
<pre wrap="">
</pre>
<blockquote type="cite">
<pre wrap="">On Oct 5, 2015, at 1:12 PM, Krug, Jeff <a class="moz-txt-link-rfc2396E" href="mailto:Jeff.Krug@gtri.gatech.edu"><Jeff.Krug@gtri.gatech.edu></a> wrote:
The metadata posted has a single cert marked as a signing cert, so you do not have an encryption cert, so the error message looks correct. Either update your metadata to include an encryption cert or do something else so that testshib does not try to encrypt assertions sent to you (assuming it has that level of flexibility).
</pre>
</blockquote>
<pre wrap="">
Thanks Jeff,
More to Jeff’s point .. just remove the <ns0:KeyDescriptor use="signing”> tags around your cert and re-upload your metadata.
Please be sure to use the same file name though..
</pre>
</blockquote>
Uhm, thanks, looks like removing use="signing" made it work,<br>
I'm pretty sure I tried that previously, but well now it works.<br>
<br>
My final, working, ServiceProvider.xml is:<br>
<br>
<meta http-equiv="content-type" content="text/html; charset=utf-8">
<?xml version='1.0' encoding='UTF-8'?><br>
<ns0:EntityDescriptor
xmlns:ns0="urn:oasis:names:tc:SAML:2.0:metadata"
xmlns:xs=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2001/XMLSchema">"http://www.w3.org/2001/XMLSchema"</a><br>
xmlns:ns1="urn:oasis:names:tc:SAML:metadata:attribute"<br>
xmlns:ns2="urn:oasis:names:tc:SAML:2.0:assertion"
xmlns:ns4=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2000/09/xmldsig#">"http://www.w3.org/2000/09/xmldsig#"</a><br>
xmlns:xsi=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2001/XMLSchema-instance">"http://www.w3.org/2001/XMLSchema-instance"</a><br>
entityID=<a class="moz-txt-link-rfc2396E" href="https://asdrubale.co.uk/">"https://asdrubale.co.uk/"</a>><br>
<ns0:Extensions
xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport"><br>
<ns1:EntityAttributes><br>
<ns2:Attribute
Name=<a class="moz-txt-link-rfc2396E" href="http://macedir.org/entity-category">"http://macedir.org/entity-category"</a><br>
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><br>
<ns2:AttributeValue
xsi:type="xs:string"><a class="moz-txt-link-freetext" href="http://www.geant.net/uri/dataprotection-code-of-conduct/v1">http://www.geant.net/uri/dataprotection-code-of-conduct/v1</a><br>
</ns2:AttributeValue><br>
</ns2:Attribute><br>
</ns1:EntityAttributes><br>
</ns0:Extensions><br>
<ns0:SPSSODescriptor AuthnRequestsSigned="false"
WantAssertionsSigned="true"<br>
protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"><br>
<ns0:KeyDescriptor><br>
<ns4:KeyInfo><br>
<ns4:X509Data><br>
<ns4:X509Certificate>MIIC7zCCAdegAwIBAgIJAKNUFVpcL0KLMA0GCSqGSIb3DQEBBQUAMBIxEDAOBgNV<br>
BAMTB0xQdWxzYXIwHhcNMTUxMDA1MTYwNTAyWhcNMjUxMDAyMTYwNTAyWjASMRAw<br>
DgYDVQQDEwdMUHVsc2FyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA<br>
04Dvyk0OAmkcjFIzptAJyluGcfP8WsmdE01XOvIV0bi40Cc1c3SCfdXM+AU7kiz6<br>
Ew37m9kXz1FbIw9n9Zsv3ImJ7lqQ1/ZKUkzB/Aj49p85XsoqMwtRq8Zwun9sLAME<br>
+sjWh4+OyQH2Dr/Na7WnafuuYeIl72rFAoUg2IDEodZ5b204suKp1qi0GQwYm2Jp<br>
Ahh0f46RhXawcYVmTMPUS6XQjJ+WH95sDxxxV6Yjfw7d3uZNQ+cNAec7hFxSSAka<br>
nShkimm6KfC5x04jgjz1YA4iNXPoj2Pi2E0l3EBl16qBmhjXoppagriHfN+xIxcD<br>
hEggCSaYLui2Qm/8maeqQwIDAQABo0gwRjAlBgNVHREEHjAcggdMUHVsc2FyhhFo<br>
dHRwczovL2xvY2FsaG9zdDAdBgNVHQ4EFgQUQbbmEqIJlFT8GRdSPE56N+dGZi8w<br>
DQYJKoZIhvcNAQEFBQADggEBAC8jKuZWkHx/AhM1GL2vHq/h9SxHoHFcyYDipVyC<br>
Ql5VB5PjTaLdQ9RZCtJhlJa75DeVfW6hncDY5Q2phb7MwH2GfWm/bZwmPyfwsEeI<br>
uzOcfyWU24582ITtWBNGkaxkE3uI5cDRvmKfO6fTrAdvw+emtVzYOUcAxzqz0PAQ<br>
B5f2jLbg2sTLB6d4KawGPoq3JtVXPgagIANZ5IsR/dem3FIsZFj8nsztibFFTH/O<br>
ljUAfZledVW5KIfApmHMc4qLvAuSSOSmax6ksBjPE4LVZx/9iftHQOMsucW1O4Ob<br>
ykh4ttyYdRoNP1es5xuzTF3Qw2XRMK1N4ZgFsOQudlEexik=<br>
</ns4:X509Certificate><br>
</ns4:X509Data><br>
</ns4:KeyInfo><br>
</ns0:KeyDescriptor><br>
<ns0:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"<br>
Location=<a class="moz-txt-link-rfc2396E" href="http://localhost:8087/slo/redirect">"http://localhost:8087/slo/redirect"</a>/><br>
<ns0:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"<br>
Location=<a class="moz-txt-link-rfc2396E" href="http://localhost:8087/slo/post">"http://localhost:8087/slo/post"</a>/><br>
<ns0:AssertionConsumerService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"<br>
Location=<a class="moz-txt-link-rfc2396E" href="http://localhost:8087/acs/post">"http://localhost:8087/acs/post"</a> index="1"/><br>
</ns0:SPSSODescriptor><br>
</ns0:EntityDescriptor><br>
<br>
<br>
<pre class="moz-signature" cols="72">--
Alessandro Molina
Chief Technical Officer & Director of Operations
Axant s.n.c. - <a class="moz-txt-link-freetext" href="http://www.axant.it">http://www.axant.it</a>
Phone: +39 346 739 9923
Fax: +39 011 412 1756</pre>
</body>
</html>