<div dir="ltr">They are processing the response and triggering the error, so the SP is "up" to some extent.<div><br></div><div>It is a good thought, as the problem started around the same time as AWS S3 issue today;</div><div>but it persists now hours after AWS restoration of services.</div><div><br></div><div>David</div><div><br></div><div><br><div><br></div><div><br></div></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Feb 28, 2017 at 4:25 PM, Tom Poage <span dir="ltr"><<a href="mailto:tfpoage@ucdavis.edu" target="_blank">tfpoage@ucdavis.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Are they hosted on Amazon? ;-)<br>
<br>
Cf. today's outage. It affected us.<br>
<br>
<a href="https://status.aws.amazon.com" rel="noreferrer" target="_blank">https://status.aws.amazon.com</a><br>
<div class="HOEnZb"><div class="h5"><br>
<br>
> On Feb 28, 2017, at 5:11 PM, IAM David Bantz <<a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a>> wrote:<br>
><br>
> Currently used certs expire 2034.<br>
><br>
> I still have certs that expired in 2014 in the IdP metadata for SPs that never consumed the new metadata with new certs in 2014.<br>
><br>
> But that hasn't changed since 2014.<br>
><br>
> David<br>
><br>
><br>
><br>
> On Tue, Feb 28, 2017 at 4:05 PM, Tom Poage <<a href="mailto:tfpoage@ucdavis.edu">tfpoage@ucdavis.edu</a>> wrote:<br>
> Is your signing certificate expired? I've seen some vendors (erroneously) check the expiration date.<br>
><br>
> Tom.<br>
><br>
> > On Feb 28, 2017, at 4:24 PM, IAM David Bantz <<a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a>> wrote:<br>
> ><br>
> > An SP we've had integrated and working for years (OrigamiRisk) is now rejecting assertions from my IdP with the message "SAML response signature is not valid."<br>
> ><br>
> > Their error logs contain a seemingly complete copy of my IdP's signed response immediately after that message.<br>
> ><br>
> > The logged outgoing SAML from my IdP asserts success and includes requested attributes. The outgoing assertion is not encrypted. None of my other SPs appear to be affected.<br>
> ><br>
> > I want to say it must be the SP's problem, but if you can think of something further for me to look at in my IdP, I will appreciate it!<br>
> ><br>
> > Thanks,<br>
> ><br>
> ><br>
> > David Bantz<br>
> > UA OIT IAM<br>
> > --<br>
> > To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
><br>
> --<br>
> To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
><br>
> --<br>
> To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div></div></blockquote></div><br></div>