<html xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        font-size:10.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
span.EmailStyle19
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style>
</head>
<body lang="EN-US" link="blue" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt">Thanks for the reply.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">A bit of follow up information, I assumed the issue was due to the SP signing their authentication requests using a different key (I suggested they stop that), but I thought to prove my case I’ll attempt an
 IdP-initiated login and it turns out I still get an immediate exception. This time I see the following in the logs.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">No credentials could be extracted from KeyInfo child with QName (<a href="http://www.w3.org/2000/09/xmldsig#)x509Data">http://www.w3.org/2000/09/xmldsig#)x509Data</a> by any registered provider<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Validation failure: Failed to resolve both a data and a key encryption credential<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Profile Action PopulateEncryptionParameters: Resolver returned no EncryptionParameters<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">The only thing that seems different about this SP is they use sha512 instead of sha256, but I’m assuming Shib supports sha512 just fine. Thanks for any suggestions.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<div>
<div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">-- <o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Ryan Rumbaugh<o:p></o:p></span></p>
</div>
</div>
</div>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-bottom:12.0pt"><b><span style="font-size:12.0pt;color:black">From:
</span></b><span style="font-size:12.0pt;color:black">Cantor, Scott <cantor.2@osu.edu><br>
<b>Date: </b>Friday, March 25, 2022 at 10:39 AM<br>
<b>To: </b>Shib Users <users@shibboleth.net><br>
<b>Cc: </b>Ryan Rumbaugh <rrumbaugh@nebraska.edu><br>
<b>Subject: </b>Re: Error: Simple signature validation (with no request-derived credentials) failed<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-size:11.0pt">Non-NU Email<br>
<br>
On 3/25/22, 11:14 AM, "users on behalf of Ryan Rumbaugh via users" <users-bounces@shibboleth.net on behalf of users@shibboleth.net> wrote:<br>
<br>
>    Hi all, I’m working with a vendor (Critical Labs) to try and determine why I’m getting the following exception.<br>
> Searching the list, I think this occurs when a SP signs an authn request with a different key than what is in<br>
> metadata. According to the vendor that is not the case,<br>
<br>
I would assume the vendor's wrong.<br>
<br>
> and FWIW I used the SAML authn request validator at <a href="https://urldefense.com/v3/__https:/www.samltool.com/validate_authn_req.php__;!!PvXuogZ4sRB2p-tU!U3vKzdKQYi3_4OB3wtt5hXyLtHGXzGSCk_SSLaMvEuCso2-S-PkaUCyzOz_GnuUSO-Sx$">
https://urldefense.com/v3/__https://www.samltool.com/validate_authn_req.php__;!!PvXuogZ4sRB2p-tU!U3vKzdKQYi3_4OB3wtt5hXyLtHGXzGSCk_SSLaMvEuCso2-S-PkaUCyzOz_GnuUSO-Sx$</a>
<br>
> and it checks out.<br>
<br>
Perhaps the metadata is wrong but you're pulling the key artificially in some way for the test. Maybe it's marked use="encryption". Or maybe that's not the metadata the IdP is using.<br>
<br>
-- Scott<br>
<br>
<br>
<o:p></o:p></span></p>
</div>
</div>
</body>
</html>