<div dir="ltr"><div dir="ltr"><div><div dir="ltr" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div>Thanks Alan,<br>you were right, the IDP was misconfigured.<br><br>The data was encrypted using the new cert on one end and the attempt to decrypt,<br>using the new cert resulted in the error.<br>The IDP was redirecting correctly but so appeared it was working on their side.</div><div><br>Message: 1<br>Date: Tue, 15 Feb 2022 12:00:07 +0000<br>From: Alan Buxey <<a href="mailto:alan.buxey@myunidays.com" target="_blank">alan.buxey@myunidays.com</a>><br>To: Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>Subject: Re:<br>Message-ID:<br> <<a href="mailto:CAObj%2BSXkNYVGVos8yBdF%2BTHeS09%2BJPhsOZxnCSj38rBcNQ0OSw@mail.gmail.com" target="_blank">CAObj+SXkNYVGVos8yBdF+THeS09+JPhsOZxnCSj38rBcNQ0OSw@mail.gmail.com</a>><br>Content-Type: text/plain; charset="UTF-8"<br><br>hi,<br><br>has the IdP updated their metadata to use the new certificate of the SP ?<br><br>alan <br></div></div></div></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, Feb 14, 2022 at 5:47 PM Hemi Taka <<a href="mailto:hemi@atlasmd.com" target="_blank">hemi@atlasmd.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div>HI,</div><div><br></div><div>We are running a Shibboleth 3.3 Service provider and connecting to a remote IDP.</div><div>All has been working well until we update the certificate on the service provider.</div><div><div>The certificate and key have been checked.</div><div><br></div></div><div>On starting the Shibboleth service on a windows server there are no errors in the shibboleth logs.</div><div>Users logging in appear to redirect from the IDP before seeing the opensaml::FatalProfileException message.</div><div><br></div><div>We are receiving the below errors in the logs.</div><div><br></div><div><br></div><div>2022-02-14 17:21:37 WARN XMLTooling.Decrypter [1] [default]: XMLSecurity exception while decrypting key: OpenSSL:RSA privateKeyDecrypt - Error removing OAEPadding<br>2022-02-14 17:21:37 WARN XMLTooling.Decrypter [1] [default]: unable to decrypt key, generating random key for defensive purposes<br>2022-02-14 17:21:37 ERROR Shibboleth.SSO.SAML2 [1] [default]: failed to decrypt assertion: XMLSecurity exception while decrypting: Errors occurred during de-serialisation of decrypted element content<br>2022-02-14 17:21:37 WARN Shibboleth.SSO.SAML2 [1] [default]: error processing incoming assertion: A valid authentication statement was not found in the incoming message.<br><br></div><div> I am not sure what other information is relevant to give and would like any pointers to help resolve.<br></div><div><br></div><div>Thanks</div><div><br></div></div></div></div></div></div>
</blockquote></div>
</div>