<div dir="ltr">The metadata file is shared between IdP v3.2 and v3.3 so it shouldn't be a metadata issue.<br>Unsolicited authentication works fine. </div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Mar 10, 2017 at 3:39 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> We have a third party vendor which is sending a signed authentication<br>
> request but with SHA1. IdP v3.3 is rejecting the request with<br>
<br>
</span>The failure isn't a SHA1 issue, we don't blacklist it. You just have the wrong metadata or they have the wrong key. Nothing mysterious, and the error in the log is telling you this outright (signature verification failed). Don't go looking for reasons, that is the reason.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
</font></span></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><font size="2"><span title="yy27" style="padding:0px;border:0px none;list-style-type:none;color:rgb(0,0,0);font-family:verdana,arial,helvetica,sans-serif;line-height:16px"><span style="padding:0px;border:0px none;list-style-type:none">Yavor Yanakiev</span> </span><br style="padding:0px;border:0px none;list-style-type:none;color:rgb(0,0,0);font-family:verdana,arial,helvetica,sans-serif;line-height:16px"><span style="padding:0px;border:0px none;list-style-type:none;color:rgb(0,0,0);font-family:verdana,arial,helvetica,sans-serif;line-height:16px">Systems Developer for Identity Services</span></font><br><div>212-992-7585<br></div></div></div>
</div>