<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=iso-8859-1"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";
color:black;
mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:#954F72;
text-decoration:underline;}
p
{mso-style-priority:99;
mso-margin-top-alt:auto;
margin-right:0cm;
mso-margin-bottom-alt:auto;
margin-left:0cm;
font-size:11.0pt;
font-family:"Calibri","sans-serif";
color:black;
mso-fareast-language:EN-US;}
span.EmailStyle18
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:windowtext;}
span.EmailStyle19
{mso-style-type:personal-reply;
font-family:"Calibri","sans-serif";
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:612.0pt 792.0pt;
margin:70.85pt 3.0cm 70.85pt 3.0cm;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body bgcolor=white lang=PT link="#0563C1" vlink="#954F72"><div class=WordSection1><p class=MsoNormal><span lang=EN-US style='color:#1F497D'>Thank you Brent and Scott.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='color:#1F497D'>The problem was, like Scott said, the public part of my IDP encryption key was no not correct on IDP Metadata.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='color:#1F497D'>As soon as I corrected, problem solved!<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='color:#1F497D'>Many thanks to both!<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US style='color:#1F497D'>Jose Ramalho<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='color:#1F497D'>Universidade de Aveiro, Portugal<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US style='color:#1F497D'><o:p> </o:p></span></p><div><div style='border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm 0cm 0cm'><p class=MsoNormal><b><span lang=EN-US style='color:windowtext;mso-fareast-language:PT'>From:</span></b><span lang=EN-US style='color:windowtext;mso-fareast-language:PT'> users [mailto:users-bounces@shibboleth.net] <b>On Behalf Of </b>Brent Putman<br><b>Sent:</b> 30 de março de 2017 18:22<br><b>To:</b> users@shibboleth.net<br><b>Subject:</b> Re: IDP 3 Logout error<o:p></o:p></span></p></div></div><p class=MsoNormal><o:p> </o:p></p><p><span style='font-size:12.0pt;mso-fareast-language:PT'><o:p> </o:p></span></p><p class=MsoNormal><o:p> </o:p></p><div><p class=MsoNormal>On 3/30/17 12:27 PM, José Ramalho wrote:<o:p></o:p></p></div><blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'><p class=MsoNormal><span lang=EN-US>2017-03-30 17:13:42,917 - WARN [org.opensaml.saml.saml2.profile.impl.DecryptNameIDs:99] - Profile Action DecryptNameIDs: Failure performing decryption</span><o:p></o:p></p><p class=MsoNormal><span lang=EN-US>org.opensaml.xmlsec.encryption.support.DecryptionException: Failed to decrypt EncryptedData</span><o:p></o:p></p><p class=MsoNormal><span style='font-size:12.0pt;font-family:"Times New Roman","serif";mso-fareast-language:PT'><o:p> </o:p></span></p></blockquote><p class=MsoNormal><span style='font-size:12.0pt;font-family:"Times New Roman","serif";mso-fareast-language:PT'><br>Looks like your logout request is sending an encrypted NameID. It seems it can't resolve the proper decryption key.<br><br>Offhand my first suggestion is to check the config you have in your conf/credentials.xml. Specifically the beans 'shibboleth.EncryptionCredentials' and 'shibboleth.DefaultEncryptionCredentials'. If you need a reference to an unmodified copy, see:<br><br><a href="https://git.shibboleth.net/view/?p=java-identity-provider.git;a=blob;f=idp-conf/src/main/resources/conf/credentials.xml;hb=refs/heads/master">https://git.shibboleth.net/view/?p=java-identity-provider.git;a=blob;f=idp-conf/src/main/resources/conf/credentials.xml;hb=refs/heads/master</a><br><br>Most importantly, make sure that whatever key(s) you are publishing in metadata and used by SPs to encrypt to you are included in those beans (lists of credentials). For example, if you have added additional keys to your published metadata that SPs have about your IdP, then those additional keys need to be added there as well. <br><br>A bit more info here: <a href="https://wiki.shibboleth.net/confluence/display/IDP30/SecurityConfiguration">https://wiki.shibboleth.net/confluence/display/IDP30/SecurityConfiguration</a><o:p></o:p></span></p></div></body></html>