<div dir="ltr">I have Shibboleth 4.0.1 IdP installed locally and have verified it using <a href="http://samltest.id">samltest.id</a> as the SP.<br><br>I also have mod_auth_mellon on Apache httpd on another server which I would like to use as the SP.  I have verified that it works with <a href="http://samltest.id">samltest.id</a> as the IdP either with a both encryption and signing <KeyDescriptor> elements or only with a signing <KeyDescriptor>.<br><br>When I configure my SP to use my local Shibboleth installation as the IdP, it will work successfully if I only have the signing key.  But it does not work if I include the encryption key.<br><br>When using the encryption key in my SP metadata, it appears to login successfully but when redirected back to the AssertionConsumerService URL, I get a 400 Bad Request response from the SP with the following message in the logs:<br><br><blockquote style="margin:0 0 0 40px;border:none;padding:0px">[Thu Jul 30 07:04:45.374462 2020] [auth_mellon:error] [pid 29013] [client <a href="http://10.0.2.2:60010">10.0.2.2:60010</a>] Error processing authn response. Lasso error: [-427] When looking for an assertion we did not found it., SAML Response: StatusCode1="urn:oasis:names:tc:SAML:2.0:status:Success", StatusCode2="(null)", StatusMessage="(null)", referer: <a href="https://samldev.promergent.com:8443/idp/profile/SAML2/Redirect/SSO?execution=e2s3">https://samldev.promergent.com:8443/idp/profile/SAML2/Redirect/SSO?execution=e2s3</a><br></blockquote><br><div>The SP metadata:<br></div><div><br></div><div><blockquote style="margin:0 0 0 40px;border:none;padding:0px"><div><EntityDescriptor entityID="<a href="https://localhost/rayDevEntityID">https://localhost/rayDevEntityID</a>" xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"><br>  <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"><br>    <KeyDescriptor use="signing"><br>      <ds:KeyInfo xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"><br>        <ds:X509Data><br>          <ds:X509Certificate>MIICpDCCAYwCCQDKXGOSlGjvKTANBgkqhkiG9w0BAQsFADAUMRIwEAYDVQQDDAls<br>b2NhbGhvc3QwHhcNMjAwNzI4MTgwNTU5WhcNMzAwNzI4MTgwNTU5WjAUMRIwEAYD<br>VQQDDAlsb2NhbGhvc3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDf<br>cl7EEjxKo+ymMGKhQqnR9SBHdAriRcJf3Kl7prO8D1jjPtHjEopYhPyVntLVJWZs<br>ayZG5Y2R9gf9FQzMH/c1pe1lE5aci3lSCV0yhhkN3CHdecmazGfCXzAslMHMIIHc<br>y81MTRHTPE4LK6uXuEp1v9+X8ih4ep1Cb6Cp+5zPY8HqcfKxyEpdTr0I/L4L5azC<br>CLsRQtTc9I9MDzRz2dVkJCpd9gTz1r35PZbP/AdJvmVvz6Ie9yEJ1IOoY1kzFWGD<br>Yoat9KkVNkUDWkBuoghDgK1sRtrjbiwI6X1FJA/DpIc3H8he9u7gH5jPsLOptzTE<br>gybgUMC/wwoqpFM8quYdAgMBAAEwDQYJKoZIhvcNAQELBQADggEBAKeGvDpHoJK/<br>k+tTmy5bB/qwPQr9LgTt8xjzgpE95iteiVcMEJ2+YZogna1380kny6srNpSk0419<br>+Coyw3R1FgtS6v6NzlCTQoVlIJpsPILg5EDkacusieHOmtUD+4Bg4TEPZLde/YH/<br>zPQFUpli5oE2kQkHeKXc3IjYKDE4HVaKsSyGnDA+KjZ4aHtNObs8tYLmWENJuDER<br>yZRm9e1xqTISRxDV6RX1oxJxs36nuaKCA8gqnkxkn1kFneEjuAHk1f2n/mVhyFnj<br>KpfI8aH2fu3uLR8cH5OFFhIPr//7wxn/yeWwwS1RjqvMbRbIFQaME3uq80SP+4Vk<br>ab0lp8OoAXY=</ds:X509Certificate><br>        </ds:X509Data><br>      </ds:KeyInfo><br>    </KeyDescriptor><br>    <KeyDescriptor use="encryption"><br>      <ds:KeyInfo xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"><br>        <ds:X509Data><br>          <ds:X509Certificate>MIICpDCCAYwCCQDKXGOSlGjvKTANBgkqhkiG9w0BAQsFADAUMRIwEAYDVQQDDAls<br>b2NhbGhvc3QwHhcNMjAwNzI4MTgwNTU5WhcNMzAwNzI4MTgwNTU5WjAUMRIwEAYD<br>VQQDDAlsb2NhbGhvc3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDf<br>cl7EEjxKo+ymMGKhQqnR9SBHdAriRcJf3Kl7prO8D1jjPtHjEopYhPyVntLVJWZs<br>ayZG5Y2R9gf9FQzMH/c1pe1lE5aci3lSCV0yhhkN3CHdecmazGfCXzAslMHMIIHc<br>y81MTRHTPE4LK6uXuEp1v9+X8ih4ep1Cb6Cp+5zPY8HqcfKxyEpdTr0I/L4L5azC<br>CLsRQtTc9I9MDzRz2dVkJCpd9gTz1r35PZbP/AdJvmVvz6Ie9yEJ1IOoY1kzFWGD<br>Yoat9KkVNkUDWkBuoghDgK1sRtrjbiwI6X1FJA/DpIc3H8he9u7gH5jPsLOptzTE<br>gybgUMC/wwoqpFM8quYdAgMBAAEwDQYJKoZIhvcNAQELBQADggEBAKeGvDpHoJK/<br>k+tTmy5bB/qwPQr9LgTt8xjzgpE95iteiVcMEJ2+YZogna1380kny6srNpSk0419<br>+Coyw3R1FgtS6v6NzlCTQoVlIJpsPILg5EDkacusieHOmtUD+4Bg4TEPZLde/YH/<br>zPQFUpli5oE2kQkHeKXc3IjYKDE4HVaKsSyGnDA+KjZ4aHtNObs8tYLmWENJuDER<br>yZRm9e1xqTISRxDV6RX1oxJxs36nuaKCA8gqnkxkn1kFneEjuAHk1f2n/mVhyFnj<br>KpfI8aH2fu3uLR8cH5OFFhIPr//7wxn/yeWwwS1RjqvMbRbIFQaME3uq80SP+4Vk<br>ab0lp8OoAXY=</ds:X509Certificate><br>        </ds:X509Data><br>      </ds:KeyInfo><br>    </KeyDescriptor><br>    <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="<a href="https://localhost/mellon/logout">https://localhost/mellon/logout</a>"/><br>    <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://localhost/mellon/postResponse">https://localhost/mellon/postResponse</a>" index="0"/><br>  </SPSSODescriptor><br></EntityDescriptor><br></div></blockquote></div><div><br></div><div>The Shibboleth IdP metadata is the sample which comes with the install, updated for the expiration date and adding the port to the URLs.</div><div><br></div><div>I cranked up the logging on the IdP and have attached the results.</div><div><br></div><div>Thanks again,</div><div>Ray</div></div>