<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:#954F72;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri",sans-serif;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">Hi, I have questions related to setting up an SP with Shib to integrate with an external partner IDP (they are using ADFS, but not sure that matters).<o:p></o:p></p>
<p class="MsoNormal">We initially had issues with the AudienceRestriction, and had them update their relying party id to our entityid.
<o:p></o:p></p>
<p class="MsoNormal">Now the response is failing signature validation.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">The second message states “keys didn’t match”. Is this just comparing the public cert in the metadata to the one in the response. They look to be the same to us.<o:p></o:p></p>
<p class="MsoNormal">Can someone help point us to something specific that may be wrong in our config (or theirs)?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">FYI. This IDP shares the same metadata with many partners, so I’m inclined to think the problem is with our config, but we just don’t see it.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">OpenSAML.SecurityPolicyRule.XMLSigning [9]: validating signature profile<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">XMLTooling.CredentialCriteria [9]: keys didn't match<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">XMLTooling.TrustEngine.ExplicitKey [9]: attempting to validate signature with the peer's credentials<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">XMLTooling.TrustEngine.ExplicitKey [9]: public key did not validate signature: Digital signature does not validate with the supplied key.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">XMLTooling.TrustEngine.ExplicitKey [9]: no peer credentials validated the signature<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">XMLTooling.TrustEngine.PKIX [9]: validating signature using certificate from within the signature<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">XMLTooling.TrustEngine.PKIX [9]: Digital signature does not validate with the supplied key.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">XMLTooling.TrustEngine.PKIX [9]: failed to verify signature with embedded certificates<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">OpenSAML.SecurityPolicyRule.XMLSigning [9]: unable to verify message signature with supplied trust engine<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Shibboleth.SSO.SAML2 [9]: detected a problem with assertion: Message was signed, but signature could not be verified.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<p>************************************************************<br>
This communication, including attachments, is for the exclusive use of addressee and may contain proprietary, confidential and/or privileged information. If you are not the intended recipient, any use, copying, disclosure, dissemination or distribution is strictly prohibited. If you are not the intended recipient, please notify the sender immediately by return e-mail, delete this communication and destroy all copies.<br>
************************************************************</p></body>
</html>