<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=utf-8">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<p>Dear Shibboleth Users,<br>
</p>
<p>I am facing a problem while I am trying to get attributes from
the IdP (v3). While I can see that the IdP is releasing at least
one attribute:</p>
<p><tt>POST|_6a18595480acc7732cc155b38baf04dd|</tt><tt><font
size="+1"><b>beninim</b></font></tt><tt>|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport||AAdzZWNyZXQxVubTawtXwku1NN5e6g4/a8G2OR/kTTWyO7evLRjzrqv9ShT83hplDT3Xt7UlQwzUNd2eQO9n4G4K7u5FF1qwO5LO3U40S47dRkWiDziFijfIjCp7c+rfQ5fAm+pppI1pNH3BCQ/K|_6ea41de9c990</tt><tt><br>
</tt><tt>3c38409e3118715a04b5|</tt></p>
<p><br>
</p>
<p>On the SP side I got this error:</p>
<p><tt>2016-11-21 14:41:33 ERROR XMLTooling.SOAPTransport.CURL [1]:
supplied TrustEngine failed to validate SSL/TLS server
certificate</tt><tt><br>
</tt><tt>2016-11-21 14:41:33 ERROR XMLTooling.SOAPTransport.CURL
[1]: Certificate:</tt><tt><br>
</tt><tt> Data:</tt><tt><br>
</tt><tt> Version: 3 (0x2)</tt><tt><br>
</tt><tt> Serial Number:</tt><tt><br>
</tt><tt>
38:59:cb:29:3b:01:66:d3:14:12:6d:ca:31:cf:cf:91:ce:38:8d:cb</tt><tt><br>
</tt><tt> Signature Algorithm: sha256WithRSAEncryption</tt><tt><br>
</tt><tt> Issuer: C=BM, O=QuoVadis Limited, CN=QuoVadis
Global SSL ICA G2</tt><tt><br>
</tt><tt> Validity</tt><tt><br>
</tt><tt> Not Before: Nov 9 07:50:12 2016 GMT</tt><tt><br>
</tt><tt> Not After : Nov 9 07:50:09 2018 GMT</tt><tt><br>
</tt><tt> Subject: C=CH, ST=Zuerich, L=Zuerich, O=ETH
Zuerich, OU=CSCS, CN=idp.cscs.ch</tt><tt><br>
</tt><tt> Subject Public Key Info:</tt><tt><br>
</tt><tt> Public Key Algorithm: rsaEncryption</tt><tt><br>
</tt><tt> Public-Key: (2048 bit)</tt><tt><br>
</tt><tt> Modulus:</tt><tt><br>
</tt></p>
<p><tt>.......<br>
</tt></p>
<p><tt>2016-11-21 14:41:33 ERROR Shibboleth.AttributeResolver.Query
[1]: exception during SAML query to
<a class="moz-txt-link-freetext" href="https://idp.cscs.ch/idp/profile/SAML2/SOAP/AttributeQuery">https://idp.cscs.ch/idp/profile/SAML2/SOAP/AttributeQuery</a>:
CURLSOAPTransport failed while contacting SOAP endpoint
(<a class="moz-txt-link-freetext" href="https://idp.cscs.ch/idp/profile/SAML2/SOAP/AttributeQuery">https://idp.cscs.ch/idp/profile/SAML2/SOAP/AttributeQuery</a>): SSL
certificate problem: application verification failure</tt><tt><br>
</tt><tt>2016-11-21 14:41:33 ERROR
Shibboleth.AttributeResolver.Query [1]: unable to obtain a SAML
response from attribute authority</tt></p>
For me the certificate provided in the metadata is correct, the
issuer and the subjects are OK. Can you please help me to detect
where is the problem?<br>
<br>
Thanks<br>
<br>
Massimo<tt><br>
</tt>
<p><tt></tt><br>
</p>
<p><br>
</p>
<p><br>
</p>
</body>
</html>