<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<div>We are running into an issue with our Shibboleth IDP installation.</div>
<div><br>
</div>
<div>We are using a Windows server for our current IDP 3.2.1 called Shib1</div>
<div>We are working on replacing this server with a Linux one also running IDP 3.2.1 called ShibA.</div>
<div>We are using the same metadata and certificates, and when we are ready to make the switch ShibA will be changed to Shib1 to replace it.</div>
<div>We are in the testing phase now and we are running into the following issue.</div>
<div><br>
</div>
<div>On the webpage on the SP after logging in successfully on the idp I receive the following message:</div>
<div>Message was signed, but signature could not be verified.</div>
<div><br>
</div>
<div>The logs on the SP show:</div>
<div>ERROR XMLTooling.TrustEngine.PKIX [1]: certificate name was not acceptable</div>
<div><br>
</div>
<div>I am positive that the IDP and the SP are using the same metadata, but it is the metadata from Shib1. We are using Shib1's metadata so we won't have to push out a new metadata file to all of our SP's after we make the switch. We want this to be as seamless
 as possible.</div>
<div><br>
</div>
<div>Any help with this would be greatly appreciated.</div>
<div><br>
</div>
<div>Thanks,</div>
<div>Bill</div>
</body>
</html>