<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <p><br>
    </p>
    <br>
    <div class="moz-cite-prefix">On 8/7/18 3:23 PM, Brent Putman wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:43306d21-0263-8123-3e1e-a486b9cc70f8@georgetown.edu">
      <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
      <blockquote type="cite"
cite="mid:CAL9ddzKOaFpmEzEExdSoeU8sDEFjNF0+X0PUVToRFR9eiNCeVA@mail.gmail.com">
        <div dir="ltr">
          <div><br>
            <div>The dev has checked the code on their side and found no
              issues in the signature.</div>
          </div>
        </div>
      </blockquote>
      <br>
      Well, the digest at validation time is different than it was at
      signature time.  So that's the issue, period.  Either there is a
      bug in the signing code or the document really has been changed
      since it was signed.  Only you and/or your developer are in a
      position to diagnose the root cause there.  Quadruply so if your
      local developer is writing their own XML Signature code, or trying
      to implement a custom SP with a third-party XML Signature library.<br>
      <br>
      <br>
    </blockquote>
    <br>
    Just FYI, I forgot that we have some info in our wiki for
    troubleshooting signature problems (ignore the warning at top, we
    haven't moved content to OpenSAML 3 wiki):<br>
    <br>
<a class="moz-txt-link-freetext" href="https://wiki.shibboleth.net/confluence/display/OpenSAML/OSTwoUserManSigErrors">https://wiki.shibboleth.net/confluence/display/OpenSAML/OSTwoUserManSigErrors</a><br>
    <br>
    In particular look at # 4 and 5.  If your signature won't validate
    using one of the tools listed in #4, then the problem is on your
    side.<br>
    <br>
    For #5, you'd want to compare the "pre-digest" value from the Shib
    IdP with the same from your SP side prior to signing.<br>
    <br>
    <br>
  </body>
</html>