<div dir="ltr"><div dir="ltr"><div dir="ltr" class="gmail_signature"><div dir="ltr"><div dir="ltr"><div>HI,</div><div><br></div><div>We are running a Shibboleth 3.3 Service provider and connecting to a remote IDP.</div><div>All has been working well until we update the certificate on the service provider.</div><div><div>The certificate and key have been checked.</div><div><br></div></div><div>On starting the Shibboleth service on a windows server there are no errors in the shibboleth logs.</div><div>Users logging in appear to redirect from the IDP before seeing the opensaml::FatalProfileException message.</div><div><br></div><div>We are receiving the below errors in the logs.</div><div><br></div><div><br></div><div>2022-02-14 17:21:37 WARN XMLTooling.Decrypter [1] [default]: XMLSecurity exception while decrypting key: OpenSSL:RSA privateKeyDecrypt - Error removing OAEPadding<br>2022-02-14 17:21:37 WARN XMLTooling.Decrypter [1] [default]: unable to decrypt key, generating random key for defensive purposes<br>2022-02-14 17:21:37 ERROR Shibboleth.SSO.SAML2 [1] [default]: failed to decrypt assertion: XMLSecurity exception while decrypting: Errors occurred during de-serialisation of decrypted element content<br>2022-02-14 17:21:37 WARN Shibboleth.SSO.SAML2 [1] [default]: error processing incoming assertion: A valid authentication statement was not found in the incoming message.<br><br></div><div> I am not sure what other information is relevant to give and would like any pointers to help resolve.<br class="gmail-Apple-interchange-newline"></div><div><br></div><div>Thanks</div><div><br></div></div></div></div></div></div>