<div dir="ltr">Thanks for sanity check. Vendor made another change at their end (I think it may have just been restart of SP) after which the integration worked immediately. I do not know what SP implementation they use.<div><br></div><div>David Bantz</div></div><br><div class="gmail_quote"><div dir="ltr">On Wed, Oct 10, 2018 at 7:35 AM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">> I haven't seen this error previously. This is early processing of incoming<br>
> request; it seems to say checking a signed request failed, but refers to<br>
> "Credential" failed, providing a CN that makes no sense either Cherwell or to<br>
> me (subjectName='CN=<a href="http://ualaska.cherwellondemand.com" rel="noreferrer" target="_blank">ualaska.cherwellondemand.com</a><br>
> <<a href="http://wellondemand.com/" rel="noreferrer" target="_blank">http://wellondemand.com/</a>> ,OU=Domain Control Validated') Is that the CN<br>
> from a certificate? Not a certificate in the SP metadata!<br>
<br>
If it's not in the metadata then you know what the real problem is, same as it always is. The message is the usual "falls through into PKIX trust engine" result when the key isn't in the metadata. You're falling through from direct to indirect trust. SP 3 disables PKIX by default and IdP 4 will do the same.<br>
<br>
-- Scott<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>