<html>
<head>
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<p><br>
</p>
<br>
<div class="moz-cite-prefix">On 3/30/17 12:27 PM, José Ramalho
wrote:<br>
</div>
<blockquote
cite="mid:9E182BE892626F4386CEB9558E4E915D01CE9F1091@CEDRO.ua.pt"
type="cite">
<meta http-equiv="Content-Type" content="text/html;
charset=windows-1252">
<meta name="Generator" content="Microsoft Word 15 (filtered
medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";
mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:#954F72;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri","sans-serif";
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri","sans-serif";
mso-fareast-language:EN-US;}
@page WordSection1
{size:612.0pt 792.0pt;
margin:70.85pt 3.0cm 70.85pt 3.0cm;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
<div class="WordSection1"><span lang="EN-US"><o:p></o:p></span><span
lang="EN-US"><o:p></o:p></span>
<p class="MsoNormal"><span lang="EN-US">2017-03-30 17:13:42,917
- WARN
[org.opensaml.saml.saml2.profile.impl.DecryptNameIDs:99] -
Profile Action DecryptNameIDs: Failure performing decryption<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">org.opensaml.xmlsec.encryption.support.DecryptionException:
Failed to decrypt EncryptedData<o:p></o:p></span></p>
<br>
</div>
</blockquote>
<br>
Looks like your logout request is sending an encrypted NameID. It
seems it can't resolve the proper decryption key.<br>
<br>
Offhand my first suggestion is to check the config you have in your
conf/credentials.xml. Specifically the beans
'shibboleth.EncryptionCredentials' and
'shibboleth.DefaultEncryptionCredentials'. If you need a reference
to an unmodified copy, see:<br>
<br>
<a class="moz-txt-link-freetext" href="https://git.shibboleth.net/view/?p=java-identity-provider.git;a=blob;f=idp-conf/src/main/resources/conf/credentials.xml;hb=refs/heads/master">https://git.shibboleth.net/view/?p=java-identity-provider.git;a=blob;f=idp-conf/src/main/resources/conf/credentials.xml;hb=refs/heads/master</a><br>
<br>
Most importantly, make sure that whatever key(s) you are publishing
in metadata and used by SPs to encrypt to you are included in those
beans (lists of credentials). For example, if you have added
additional keys to your published metadata that SPs have about your
IdP, then those additional keys need to be added there as well. <br>
<br>
A bit more info here:
<a class="moz-txt-link-freetext" href="https://wiki.shibboleth.net/confluence/display/IDP30/SecurityConfiguration">https://wiki.shibboleth.net/confluence/display/IDP30/SecurityConfiguration</a><br>
</body>
</html>