<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=utf-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <p>Dear Shibboleth Users,<br>
    </p>
    <p>I am facing a problem while I am trying to get attributes from
      the IdP (v3). While I can see that the IdP is releasing at least
      one attribute:</p>
    <p><tt>POST|_6a18595480acc7732cc155b38baf04dd|</tt><tt><font
          size="+1"><b>beninim</b></font></tt><tt>|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport||AAdzZWNyZXQxVubTawtXwku1NN5e6g4/a8G2OR/kTTWyO7evLRjzrqv9ShT83hplDT3Xt7UlQwzUNd2eQO9n4G4K7u5FF1qwO5LO3U40S47dRkWiDziFijfIjCp7c+rfQ5fAm+pppI1pNH3BCQ/K|_6ea41de9c990</tt><tt><br>
      </tt><tt>3c38409e3118715a04b5|</tt></p>
    <p><br>
    </p>
    <p>On the SP side I got this error:</p>
    <p><tt>2016-11-21 14:41:33 ERROR XMLTooling.SOAPTransport.CURL [1]:
        supplied TrustEngine failed to validate SSL/TLS server
        certificate</tt><tt><br>
      </tt><tt>2016-11-21 14:41:33 ERROR XMLTooling.SOAPTransport.CURL
        [1]: Certificate:</tt><tt><br>
      </tt><tt>    Data:</tt><tt><br>
      </tt><tt>        Version: 3 (0x2)</tt><tt><br>
      </tt><tt>        Serial Number:</tt><tt><br>
      </tt><tt>           
        38:59:cb:29:3b:01:66:d3:14:12:6d:ca:31:cf:cf:91:ce:38:8d:cb</tt><tt><br>
      </tt><tt>    Signature Algorithm: sha256WithRSAEncryption</tt><tt><br>
      </tt><tt>        Issuer: C=BM, O=QuoVadis Limited, CN=QuoVadis
        Global SSL ICA G2</tt><tt><br>
      </tt><tt>        Validity</tt><tt><br>
      </tt><tt>            Not Before: Nov  9 07:50:12 2016 GMT</tt><tt><br>
      </tt><tt>            Not After : Nov  9 07:50:09 2018 GMT</tt><tt><br>
      </tt><tt>        Subject: C=CH, ST=Zuerich, L=Zuerich, O=ETH
        Zuerich, OU=CSCS, CN=idp.cscs.ch</tt><tt><br>
      </tt><tt>        Subject Public Key Info:</tt><tt><br>
      </tt><tt>            Public Key Algorithm: rsaEncryption</tt><tt><br>
      </tt><tt>                Public-Key: (2048 bit)</tt><tt><br>
      </tt><tt>                Modulus:</tt><tt><br>
      </tt></p>
    <p><tt>.......<br>
      </tt></p>
    <p><tt>2016-11-21 14:41:33 ERROR Shibboleth.AttributeResolver.Query
        [1]: exception during SAML query to
        <a class="moz-txt-link-freetext" href="https://idp.cscs.ch/idp/profile/SAML2/SOAP/AttributeQuery">https://idp.cscs.ch/idp/profile/SAML2/SOAP/AttributeQuery</a>:
        CURLSOAPTransport failed while contacting SOAP endpoint
        (<a class="moz-txt-link-freetext" href="https://idp.cscs.ch/idp/profile/SAML2/SOAP/AttributeQuery">https://idp.cscs.ch/idp/profile/SAML2/SOAP/AttributeQuery</a>): SSL
        certificate problem: application verification failure</tt><tt><br>
      </tt><tt>2016-11-21 14:41:33 ERROR
        Shibboleth.AttributeResolver.Query [1]: unable to obtain a SAML
        response from attribute authority</tt></p>
    For me the certificate provided in the metadata is correct, the
    issuer and the subjects are OK. Can you please help me to detect
    where is the problem?<br>
    <br>
    Thanks<br>
    <br>
    Massimo<tt><br>
    </tt>
    <p><tt></tt><br>
    </p>
    <p><br>
    </p>
    <p><br>
    </p>
  </body>
</html>