<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>Within that <MetadataProvider> element you'll find a nested
      element like this:</p>
    <p>      <MetadataFilter xsi:type="SignatureValidation"
      requireSignedRoot="true"<br>
                   
      certificateFile="%{idp.home}/credentials/incommon.pem" /><br>
    </p>
    <p>It's having trouble loading that certificateFile.<br>
    </p>
    <div class="moz-cite-prefix">On 11/26/2019 5:02 PM, Scott Gilbert
      wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:CAPqdcyn=wEYzxTf4UESCMWpjZgnKN+azh5TQEvni8Bc_vKwVdw@mail.gmail.com">
      <meta http-equiv="content-type" content="text/html; charset=UTF-8">
      <div dir="ltr">Thanks for the reply.
        <div><br>
        </div>
        <div>So this metadata provider statement is not sufficient</div>
        <div><br>
        </div>
        <div>    <MetadataProvider id="INCOMMON"
          xsi:type="FileBackedHTTPMetadataProvider"<br>
              metadataURL="<a
            href="http://md.incommon.org/InCommon/InCommon-metadata.xml"
            moz-do-not-send="true">http://md.incommon.org/InCommon/InCommon-metadata.xml</a>"
          backingFile="%{idp.home}/metadata/incommon-metadata.xml"><br>
        </div>
        <div><br>
        </div>
        <div>as I recall there is some form of verification, so as not
          to spoof, it may be in the incommon docs.</div>
        <div><br>
        </div>
        <div>
          <div dir="ltr" class="gmail_signature"
            data-smartmail="gmail_signature">
            <div dir="ltr">
              <div>
                <div dir="ltr">
                  <div dir="ltr">
                    <div dir="ltr">
                      <div>Scott Gilbert</div>
                      <div>IAM System Admin</div>
                      <div>ETS Enterprise Technology Services</div>
                      <div>University of California Santa Barbara</div>
                      <div><br>
                      </div>
                    </div>
                  </div>
                </div>
              </div>
            </div>
          </div>
        </div>
        <br>
      </div>
      <br>
      <div class="gmail_quote">
        <div dir="ltr" class="gmail_attr">On Tue, Nov 26, 2019 at 2:44
          PM Christopher Bongaarts <<a href="mailto:cab@umn.edu"
            moz-do-not-send="true">cab@umn.edu</a>> wrote:<br>
        </div>
        <blockquote class="gmail_quote" style="margin:0px 0px 0px
          0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Check
          the contents and permissions of your InCommon metadata
          validation <br>
          certificate...<br>
          <br>
          On 11/26/2019 4:28 PM, Scott Gilbert wrote:<br>
          > Caused by:
          org.springframework.beans.factory.BeanCreationException: <br>
          > Error creating bean with name '(inner bean)#5ff6431a':
          Invocation of <br>
          > init method failed; nested exception is <br>
          > org.cryptacular.StreamException: IO error<br>
          > at <br>
          >
org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.initializeBean(AbstractAutowireCapableBeanFactory.java:1631)<br>
          > Caused by: org.cryptacular.StreamException: IO error<br>
          > at
          org.cryptacular.util.CertUtil.readCertificateChain(CertUtil.java:328)<br>
          > Caused by: java.io.IOException: Incomplete data<br>
          > at
          sun.security.provider.X509Factory.readOneBlock(X509Factory.java:612)<br>
          > 2019-11-26 14:07:11,867 -  - ERROR <br>
          >
[net.shibboleth.utilities.java.support.service.AbstractReloadableService:186]
          <br>
          > - Service 'shibboleth.MetadataResolverService': No
          further attempts <br>
          > will be made to reload<br>
          <br>
          -- <br>
          %%  Christopher A. Bongaarts   %%  <a
            href="mailto:cab@umn.edu" target="_blank"
            moz-do-not-send="true">cab@umn.edu</a>          %%<br>
          %%  OIT - Identity Management  %%  <a
            href="http://umn.edu/~cab" rel="noreferrer" target="_blank"
            moz-do-not-send="true">http://umn.edu/~cab</a>  %%<br>
          %%  University of Minnesota    %%  +1 (612) 625-1809    %%<br>
          <br>
          -- <br>
          For Consortium Member technical support, see <a
            href="https://wiki.shibboleth.net/confluence/x/coFAAg"
            rel="noreferrer" target="_blank" moz-do-not-send="true">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
          To unsubscribe from this list send an email to <a
            href="mailto:users-unsubscribe@shibboleth.net"
            target="_blank" moz-do-not-send="true">users-unsubscribe@shibboleth.net</a></blockquote>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
    </blockquote>
    <pre class="moz-signature" cols="72">-- 
%%  Christopher A. Bongaarts   %%  <a class="moz-txt-link-abbreviated" href="mailto:cab@umn.edu">cab@umn.edu</a>          %%
%%  OIT - Identity Management  %%  <a class="moz-txt-link-freetext" href="http://umn.edu/~cab">http://umn.edu/~cab</a>  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%
</pre>
  </body>
</html>