<div dir="ltr">We're migrating from in-house hosted service to vendor-hosting. The vendor appears to be using Shibboleth SP, but is unable to verify signed assertions from our IdP. They provided the following excerpt from their logs:<div><br></div><div><blockquote style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" class="gmail_quote"><span style="font-family:Calibri,sans-serif;color:rgb(31,73,125)">2017-05-20 13:29:45 DEBUG OpenSAML.MessageDecoder.SAML2 [1]: extracting issuer from SAML 2.0 protocol message<br></span><span style="font-family:Calibri,sans-serif;color:rgb(31,73,125)">2017-05-20 13:29:45 DEBUG OpenSAML.MessageDecoder.SAML2 [1]: message from (urn:mace:incommon:<a href="http://alaska.edu/" target="_blank">alaska.edu</a>)<br></span><span style="font-family:Calibri,sans-serif;color:rgb(31,73,125)">2017-05-20 13:29:45 DEBUG OpenSAML.MessageDecoder.SAML2 [1]: searching metadata for message issuer...<br></span><span style="font-family:Calibri,sans-serif;color:rgb(31,73,125)">2017-05-20 13:29:45 DEBUG OpenSAML.SecurityPolicyRule.<wbr>MessageFlow [1]: evaluating message flow policy (replay checking on, expiration 60)<br></span><span style="font-family:Calibri,sans-serif;color:rgb(31,73,125)">2017-05-20 13:29:45 DEBUG XMLTooling.StorageService [1]: inserted record (_<wbr>f1db1a5bc3a248790476a36a027abc<wbr>1f) in context (MessageFlow) with expiration (1495301616)<br></span><span style="font-family:Calibri,sans-serif;color:rgb(31,73,125)">2017-05-20 13:29:45 DEBUG OpenSAML.SecurityPolicyRule.<wbr>XMLSigning [1]: validating signature profile<br></span><span style="font-family:Calibri,sans-serif;color:rgb(31,73,125)">2017-05-20 13:29:45 DEBUG XMLTooling.CredentialCriteria [1]: keys didn't match<br></span><span style="font-family:Calibri,sans-serif;color:rgb(31,73,125)">2017-05-20 13:29:45 DEBUG XMLTooling.CredentialCriteria [1]: keys didn't match<br></span><span style="font-family:Calibri,sans-serif;color:rgb(31,73,125)">2017-05-20 13:29:45 DEBUG XMLTooling.TrustEngine.<wbr>ExplicitKey [1]: unable to validate signature, no credentials available from peer<br></span><span style="font-family:Calibri,sans-serif;color:rgb(31,73,125)">2017-05-20 13:29:45 DEBUG XMLTooling.TrustEngine.PKIX [1]: validating signature using certificate from within the signature<br></span><span style="font-family:Calibri,sans-serif;color:rgb(31,73,125)">2017-05-20 13:29:45 DEBUG XMLTooling.TrustEngine.PKIX [1]: signature verified with key inside signature, attempting certificate validation...<br></span><span style="font-family:Calibri,sans-serif;color:rgb(31,73,125)">2017-05-20 13:29:45 DEBUG XMLTooling.TrustEngine.PKIX [1]: checking that the certificate name is acceptable<br></span><span style="font-family:Calibri,sans-serif;color:rgb(31,73,125)">2017-05-20 13:29:45 DEBUG XMLTooling.TrustEngine.PKIX [1]: adding to list of trusted names (urn:mace:incommon:<a href="http://alaska.edu/" target="_blank">alaska.edu</a>)<br></span><span style="font-family:Calibri,sans-serif;color:rgb(31,73,125)">2017-05-20 13:29:45 DEBUG XMLTooling.TrustEngine.PKIX [1]: certificate subject: CN=<a href="http://idp.alaska.edu/" target="_blank">idp.alaska.edu<br></a></span><span style="font-family:Calibri,sans-serif;color:rgb(31,73,125)">2017-05-20 13:29:45 DEBUG XMLTooling.TrustEngine.PKIX [1]: unable to match DN, trying TLS subjectAltName match<br></span><span style="font-family:Calibri,sans-serif;color:rgb(31,73,125)">2017-05-20 13:29:45 DEBUG XMLTooling.TrustEngine.PKIX [1]: unable to match subjectAltName, trying TLS CN match<br></span><span style="font-family:Calibri,sans-serif;color:rgb(31,73,125)">2017-05-20 13:29:45 ERROR XMLTooling.TrustEngine.PKIX [1]: certificate name was not acceptable<br></span><span style="font-family:Calibri,sans-serif;color:rgb(31,73,125)">2017-05-20 13:29:45 ERROR OpenSAML.SecurityPolicyRule.<wbr>XMLSigning [1]: unable to verify message signature with supplied trust engine</span></blockquote><div><br></div><div>It looks as though they're using incorrect metadata for our IdP.<br>What else might cause this? </div></div><div><br></div><div>David Bantz</div><div>UA OIT IAM</div></div>