<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<div>
<div>Good evening all,</div>
<div>Earlier today I updated InCommon metadata with a second certificate as ours is about to expire and it needed to be rekeyed anyway. Once the metadata was published, school IdPs failed to authenticate to our SP with a 500 error.</div>
<div>We went ahead and swapped the keys out in shibboleth and this fixed most schools. We still have one that is failing (after the metadata publication, both before and after changing our cert/key on the SP) with the following error in the logs:</div>
<div>ERROR: spAssertionConsumer.jsp: SSO failed.</div>
<div>com.sun.identity.saml2.common.SAML2Exception: Failed to decrypt the secret key.</div>
<div><br>
</div>
<div>This isn't our native shibboleth install, but rather our older implementation using OpenAM.</div>
<div><br>
</div>
<div>1. I don't understand why two certs in metadata caused IdPs to use the new one.</div>
<div>2. Any pointers on correcting the above error is greatly appreciated.</div>
<div><br>
</div>
</div>
<div>OpenAM uses tomcat and java keystores in this implementation. Trust me, I definitely want to migrate the few schools we still have on this platform to native shibboleth.</div>
<div><br>
</div>
<div>Thanks in advance,</div>
<div>Izz</div>
<div>
<div>
<p class="MsoNormal" style="margin-top: 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New Roman', serif; ">
</p>
</div>
</div>
</body>
</html>