<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<div>
<div>Yeah, I found the link afterwards and saw the problem about introducing the new key to the SP first. </div>
<div>As for other keys in which the one IdP is still having issues, after "fixing" auth with the others and getting the key imported on our SP, I removed the old key pair, so there's only one left in the keystore. I was hoping this would resolve the issue with
 that IdP, but didn't. I'll have to troubleshoot Monday with them once they're available, but I began thinking that it's possible their IdP was using one cert, and with OpenAM only allowing you to specify a single pair, something in the assertion is wrong coming
 across (mixed usage of both certs?)...</div>
<div>Thanks for the reply. Luckily this won't need to be done again for 10 years. :)</div>
<div><br>
</div>
<div>Cheers,</div>
<div>Izz</div>
<div><br>
</div>
<div><br>
</div>
<div><span class="x_Apple-style-span" style="font-family:Tahoma,sans-serif; font-size:14px">-</span><span class="x_Apple-style-span" style="font-family:Tahoma,sans-serif; font-size:14px">-</span></div>
<div><b><i><span style="font-size:8pt; font-family:Tahoma,sans-serif">Izz</span></i></b></div>
<div><b><i><span style="font-size:8pt; font-family:Tahoma,sans-serif">Sent using Android™</span></i></b></div>
<div><b><i><span style="font-size:8pt; font-family:Tahoma,sans-serif"><br>
</span></i></b></div>
<div>
<div>
<p class="x_MsoNormal" style="margin-top:0in; margin-right:0in; margin-left:0in; margin-bottom:0.0001pt; font-size:12pt; font-family:'Times New Roman',serif">
</p>
</div>
</div>
<br>
<br>
<div>-------- Original message --------</div>
<div>From: Tom Scavo </div>
<div>Date:06/04/2016 9:24 AM (GMT-06:00) </div>
<div>To: Shib Users </div>
<div>Subject: Re: Cert rollover gone bad </div>
<div><br>
</div>
</div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText">On Sat, Jun 4, 2016 at 3:02 AM, Izz Noland <izz.noland@wepanow.com> wrote:<br>
><br>
> Earlier today I updated InCommon metadata with a second certificate as ours<br>
> is about to expire and it needed to be rekeyed anyway. Once the metadata was<br>
> published, school IdPs failed to authenticate to our SP with a 500 error.<br>
> We went ahead and swapped the keys out in shibboleth and this fixed most<br>
> schools.<br>
<br>
It's water under the bridge but for the archives you did that<br>
backwards. First you configure your SP with a second key and *then*<br>
you introduce a new certificate into metadata.<br>
<br>
NativeSPMultipleCredentials: <a href="https://wiki.shibboleth.net/confluence/x/KIFC">
https://wiki.shibboleth.net/confluence/x/KIFC</a><br>
SP Cert Migration: <a href="https://spaces.internet2.edu/x/dpiKAQ">https://spaces.internet2.edu/x/dpiKAQ</a><br>
<br>
> We still have one that is failing (after the metadata publication,<br>
> both before and after changing our cert/key on the SP) with the following<br>
> error in the logs:<br>
> ERROR: spAssertionConsumer.jsp: SSO failed.<br>
> com.sun.identity.saml2.common.SAML2Exception: Failed to decrypt the secret<br>
> key.<br>
<br>
Did you configure two decryption keys in your SP? My guess is the IdP<br>
used a encryption certificate in metadata that doesn't have a<br>
corresponding decryption key in the SP software.<br>
<br>
Tom<br>
-- <br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font>
</body>
</html>