<html><head><meta http-equiv="Content-Type" content="text/html charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><div class="">I have two version 3 IDP servers setup. One works when evaluating a signing credential from a local SP, and the other does not. One was done as an upgrade from v2 -> v3, while the other was a regular install. Here is the log from the working version (the upgrade)…</div><div class=""><br class=""></div><div class=""><div style="margin: 0px; font-size: 10px; line-height: normal; font-family: Monaco; background-color: rgb(255, 255, 255);" class=""><span style="font-variant-ligatures: no-common-ligatures" class="">2016-12-20 22:31:29,571 - DEBUG [org.opensaml.saml.saml2.binding.security.impl.SAML2HTTPRedirectDeflateSignatureSecurityHandler:59] - Constructing signed content string from URL query string SAMLRequest=jZJPU8IwEMW%2FSid3GhKklAztTIWDzKAwt</span></div><div style="margin: 0px; font-size: 10px; line-height: normal; font-family: Monaco; background-color: rgb(255, 255, 255);" class=""><span style="font-variant-ligatures: no-common-ligatures" class="">Hrw4oR2kYwhqdlU5dtb%2FsiAB8dz%0AXt57%2B9sdodzqWmSN35glvDeAPvjaaoPi8JCQxhlhJSoURm4BhS9Fnt3PBA%2B7%0AonbW29JqEmSI4LyyZmwNNltwObgPVcLjcpaQjfc1Ckpxo1YdrFlYSm3Ah2zI%0A4nAF7g007EKoGpq3ipXV4DchoqX7IE4X87wgwaRtpozcZ%2FxyrM6GV16qqmlb%0AcK00nIyWUCk</span></div><div style="margin: 0px; font-size: 10px; line-height: normal; font-family: Monaco; background-color: rgb(255, 255, 255);" class=""><span style="font-variant-ligatures: no-common-ligatures" class="">Hpad5PifBdJKQl8EglrIqGV9ziNeDqKygB%2FHwpr%2BOIugPeStD%0AbGBq0EvjE8K7LOow3uGs6EaixwSPn0mwOHG4VaZS5vVvaKujCMVdUSw6x%2BGe%0AwOFhsFZA0tEevTgEu4tl%2FG0rfzZA0v%2FzxjPvVjeiF7nHErV4aIOmk4XVqtwF%0Amdb2c%2BxAekgIIzQ9frk%2Bn%2FQb%0A&RelayState=cooki</span></div><div style="margin: 0px; font-size: 10px; line-height: normal; font-family: Monaco; background-color: rgb(255, 255, 255);" class=""><span style="font-variant-ligatures: no-common-ligatures" class="">e%3Abe45c348&SigAlg=http%3A%2F%<a href="http://2Fwww.w3.org" class="">2Fwww.w3.org</a>%2F2000%2F09%2Fxmldsig%23rsa-sha1&Signature=bxVBVx4JDggBYmQcmYlOe3oe9G7Beq61KWki6K3uky5ZW6fd12bd0dpIbkGMnVGNhbtiliHLle2Bneu6zs%2BQm0d3lwYVNVg0nhN6FQr0AaUyCnOWSEbqQf9bnxE%2Bvn7yU9IIdzZkDjL7GdpLeYV</span></div><div style="margin: 0px; font-size: 10px; line-height: normal; font-family: Monaco; background-color: rgb(255, 255, 255);" class=""><span style="font-variant-ligatures: no-common-ligatures" class="">raIUvUtQfxZNTR9NGRvcynwOzxgjk%2F%2FS7Nvc4TdMV68O8KMjDIi4aHfQYrHshg%2FAOovLesQkngIlAXTh8qSvKiTVX3NjkazbjsgxnNVCDjKeVG0mbQJ5A%2B8o0ILEqq8%2BGSxzFwRBpNcmvtZ05pUmqCzJvM9Bd%2BrvBXxFvH97Apy4w6SepBjh7aTX453txlmHDCQ%3D%3D</span></div><div style="margin: 0px; font-size: 10px; line-height: normal; font-family: Monaco; background-color: rgb(255, 255, 255);" class=""><span style="font-variant-ligatures: no-common-ligatures" class="">2016-12-20 22:31:29,571 - DEBUG [org.opensaml.saml.saml2.binding.security.impl.SAML2HTTPRedirectDeflateSignatureSecurityHandler:66] - Constructed signed content string for HTTP-Redirect DEFLATE SAMLRequest=jZJPU8IwEMW%2FSid3GhKklAztTIWDzK</span></div><div style="margin: 0px; font-size: 10px; line-height: normal; font-family: Monaco; background-color: rgb(255, 255, 255);" class=""><span style="font-variant-ligatures: no-common-ligatures" class="">AwtHrw4oR2kYwhqdlU5dtb%2FsiAB8dz%0AXt57%2B9sdodzqWmSN35glvDeAPvjaaoPi8JCQxhlhJSoURm4BhS9Fnt3PBA%2B7%0AonbW29JqEmSI4LyyZmwNNltwObgPVcLjcpaQjfc1Ckpxo1YdrFlYSm3Ah2zI%0A4nAF7g007EKoGpq3ipXV4DchoqX7IE4X87wgwaRtpozcZ%2FxyrM6GV16qqmlb%0AcK00nIyW</span></div><div style="margin: 0px; font-size: 10px; line-height: normal; font-family: Monaco; background-color: rgb(255, 255, 255);" class=""><span style="font-variant-ligatures: no-common-ligatures" class="">UCkHpad5PifBdJKQl8EglrIqGV9ziNeDqKygB%2FHwpr%2BOIugPeStD%0AbGBq0EvjE8K7LOow3uGs6EaixwSPn0mwOHG4VaZS5vVvaKujCMVdUSw6x%2BGe%0AwOFhsFZA0tEevTgEu4tl%2FG0rfzZA0v%2FzxjPvVjeiF7nHErV4aIOmk4XVqtwF%0Amdb2c%2BxAekgIIzQ9frk%2Bn%2FQb%0A&RelayState=co</span></div><div style="margin: 0px; font-size: 10px; line-height: normal; font-family: Monaco; background-color: rgb(255, 255, 255);" class=""><span style="font-variant-ligatures: no-common-ligatures" class="">okie%3Abe45c348&SigAlg=http%3A%2F%<a href="http://2Fwww.w3.org" class="">2Fwww.w3.org</a>%2F2000%2F09%2Fxmldsig%23rsa-sha1</span></div><div style="margin: 0px; font-size: 10px; line-height: normal; font-family: Monaco; background-color: rgb(255, 255, 255);" class=""><span style="font-variant-ligatures: no-common-ligatures" class="">2016-12-20 22:31:29,571 - DEBUG [org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:199] - Message Handler:  Attempting to validate SAML protocol message simple signature using context entityID: https://</span>mySP</div><div style="margin: 0px; font-size: 10px; line-height: normal; font-family: Monaco; background-color: rgb(255, 255, 255);" class=""><span style="font-variant-ligatures: no-common-ligatures" class="">2016-12-20 22:31:29,572 - DEBUG [org.opensaml.saml.security.impl.MetadataCredentialResolver:286] - Resolving credentials from metadata using entityID: <span style="font-variant-ligatures: no-common-ligatures;" class="">https://</span>mySP, role: {urn:oasis:names:tc:SAML</span></div><div style="margin: 0px; font-size: 10px; line-height: normal; font-family: Monaco; background-color: rgb(255, 255, 255);" class=""><span style="font-variant-ligatures: no-common-ligatures" class="">:2.0:metadata}SPSSODescriptor, protocol: urn:oasis:names:tc:SAML:2.0:protocol, usage: SIGNING</span></div><div style="margin: 0px; font-size: 10px; line-height: normal; font-family: Monaco; background-color: rgb(255, 255, 255);" class=""><span style="font-variant-ligatures: no-common-ligatures" class="">2016-12-20 22:31:29,572 - DEBUG [org.opensaml.saml.security.impl.MetadataCredentialResolver:435] - Retrieving role descriptor metadata for entity '<span style="font-variant-ligatures: no-common-ligatures;" class="">https://</span>mySP' in role '{urn:oasis:names:tc:SAML:</span></div><div style="margin: 0px; font-size: 10px; line-height: normal; font-family: Monaco; background-color: rgb(255, 255, 255);" class=""><span style="font-variant-ligatures: no-common-ligatures" class="">2.0:metadata}SPSSODescriptor' for protocol 'urn:oasis:names:tc:SAML:2.0:protocol’</span></div></div><div style="margin: 0px; font-size: 10px; line-height: normal; font-family: Monaco; background-color: rgb(255, 255, 255);" class=""><span style="font-variant-ligatures: no-common-ligatures" class="">2016-12-20 22:31:29,574 - DEBUG [org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:271] - Message Handler:  Simple signature validation (with no request-derived credentials) was successful</span></div><div class=""><span style="font-variant-ligatures: no-common-ligatures" class=""><br class=""></span></div><div class=""><br class=""></div><div class="">The non-working version is missing these two lines in the logs… </div><div class=""><br class=""></div><div class=""><div class=""><div style="margin: 0px; font-size: 10px; line-height: normal; font-family: Monaco; background-color: rgb(255, 255, 255);" class=""><span style="font-variant-ligatures: no-common-ligatures;" class="">2016-12-20 22:31:29,572 - DEBUG [org.opensaml.saml.security.impl.MetadataCredentialResolver:286] - Resolving credentials from metadata using entityID: <span style="font-variant-ligatures: no-common-ligatures;" class="">https://</span>mySP, role: {urn:oasis:names:tc:SAML</span></div><div style="margin: 0px; font-size: 10px; line-height: normal; font-family: Monaco; background-color: rgb(255, 255, 255);" class=""><span style="font-variant-ligatures: no-common-ligatures;" class="">:2.0:metadata}SPSSODescriptor, protocol: urn:oasis:names:tc:SAML:2.0:protocol, usage: SIGNING</span></div><div style="margin: 0px; font-size: 10px; line-height: normal; font-family: Monaco; background-color: rgb(255, 255, 255);" class=""><span style="font-variant-ligatures: no-common-ligatures;" class="">2016-12-20 22:31:29,572 - DEBUG [org.opensaml.saml.security.impl.MetadataCredentialResolver:435] - Retrieving role descriptor metadata for entity '<span style="font-variant-ligatures: no-common-ligatures;" class="">https://</span>mySP' in role '{urn:oasis:names:tc:SAML:</span></div><div style="margin: 0px; font-size: 10px; line-height: normal; font-family: Monaco; background-color: rgb(255, 255, 255);" class=""><span style="font-variant-ligatures: no-common-ligatures;" class="">2.0:metadata}SPSSODescriptor' for protocol 'urn:oasis:names:tc:SAML:2.0:protocol’</span></div></div></div><div class=""><span style="font-variant-ligatures: no-common-ligatures;" class=""><br class=""></span></div><div class=""><span style="font-variant-ligatures: no-common-ligatures;" class=""><br class=""></span></div><div class="">Is there a configuration setting that is driving this or something else? The SP and its metadata file are the same for both IDP servers.</div><div class=""><br class=""></div><div class="">Thanks,</div><div class="">Jeff</div></body></html>