<html xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Verdana;
panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
{font-family:Menlo;
panose-1:2 11 6 9 3 8 4 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:10.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
span.EmailStyle19
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style>
</head>
<body lang="EN-US" link="blue" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt">There may be other things you can look at, such as HTTP method and signature "location" incompatibility.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">I've had to switch vendors over to our HTTP-POST login endpoint because they weren't able to move the signature from where their code put it. Sometimes it needs to be a parameter, sometimes it needs to be
embedded in the XML. I don't know the exact rules.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">- Steve<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-bottom:12.0pt"><b><span style="font-size:12.0pt;color:black">From:
</span></b><span style="font-size:12.0pt;color:black">users <users-bounces@shibboleth.net> on behalf of Steve Herrera via users <users@shibboleth.net><br>
<b>Date: </b>Wednesday, October 12, 2022 at 6:38 PM<br>
<b>To: </b>IAM David Bantz <dabantz@alaska.edu><br>
<b>Cc: </b>Steve Herrera <sherrera@fsmail.bradley.edu>, Shib Users <users@shibboleth.net><br>
<b>Subject: </b>Re: Simple signature validation<o:p></o:p></span></p>
</div>
<div>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-size:11.0pt">The SP has a portal where I submit the certificate and generate it's metadata. That's what I put in our IDP. There techs said that is the certificate used to sign the request. <o:p></o:p></span></p>
<div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">On Wed, Oct 12, 2022, 5:22 PM IAM David Bantz <<a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a>> wrote:<o:p></o:p></span></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">If I understand your description correctly, it kinda doubles down on the diagnosis that the signing cert in the SP’s metadata is not the cert with which they signed the request (hence preventing the use of
that cert to validate the signed request). You substituted a cert of your own in the metadata to produce “Same result”: that substituted cert certainly wasn’t used by the SP to sign the request, and that condition triggers exactly the error you document.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">Apologies if I misread your description.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">David<o:p></o:p></span></p>
</div>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">On 12Oct2022 at 13:57:13, Steve Herrera via users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>> wrote:<o:p></o:p></span></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">This is the first SP that we have come across error messages like this. <o:p></o:p></span></p>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<div>
<p style="margin:0in;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal">
<span style="font-size:8.5pt;font-family:Menlo;color:black">2022-10-12 16:42:06,582 - WARN [org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:275] - Message Handler: Simple signature validation (with no request-derived credentials)
failed<o:p></o:p></span></p>
<p style="margin:0in;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal">
<span style="font-size:8.5pt;font-family:Menlo;color:black"><br>
<br>
<o:p></o:p></span></p>
<p style="margin:0in;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal">
<span style="font-size:8.5pt;font-family:Menlo;color:black">2022-10-12 16:42:06,583 - WARN [org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:214] - Message Handler: Validation of request simple signature failed for context
issuer:<o:p></o:p></span></p>
<p style="margin:0in;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal">
<span style="font-size:8.5pt;font-family:Menlo;color:black"><br>
<br>
<o:p></o:p></span></p>
<p style="margin:0in"><span style="font-size:8.5pt;font-family:Menlo;color:black">2022-10-12 16:42:06,583 - WARN [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:197] - Profile Action WebFlowMessageHandlerAdaptor: Exception handling message<o:p></o:p></span></p>
<p style="margin:0in;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal">
<span style="font-size:8.5pt;font-family:Menlo;color:black">org.opensaml.messaging.handler.MessageHandlerException: Validation of request simple signature failed for context issuer<o:p></o:p></span></p>
<p style="margin:0in;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal">
<span style="font-size:8.5pt;font-family:Menlo;color:black"><br>
<br>
<o:p></o:p></span></p>
<p style="margin:0in;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal">
<span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#222222">I have searched the forum and one explanation was the certificate the SP provided was incorrect from the metadata received. I reviewed that and it is the same. I have the ability to
configure the certificate that this SP provides in their metadata and generated a new certificate. Same result. I worked with their SAML techs and they made some minor changes on their end. They said they are using OpenSAML 3.3.1 </span><span style="font-size:8.5pt;font-family:Menlo;color:black"><o:p></o:p></span></p>
<p style="margin:0in;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal">
<span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#222222"><br>
<br>
</span><span style="font-size:8.5pt;font-family:Menlo;color:black"><o:p></o:p></span></p>
<p style="margin:0in;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal">
<span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#222222">This is the error when going to the URL for the SP:</span><span style="font-size:8.5pt;font-family:Menlo;color:black"><o:p></o:p></span></p>
<p style="margin:0in;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal">
<span style="font-size:9.0pt;font-family:"Verdana",sans-serif;color:#717171">The request cannot be fulfilled because the message received does not meet the security requirements of the login service.</span><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#222222"> </span><span style="font-size:8.5pt;font-family:Menlo;color:black"><br>
<br>
<o:p></o:p></span></p>
<p style="margin:0in;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal">
<span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#222222"><br>
<br>
</span><span style="font-size:8.5pt;font-family:Menlo;color:black"><o:p></o:p></span></p>
<p style="margin:0in;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal">
<span style="font-family:"Arial",sans-serif;color:black">The logon page is never displayed. </span><span style="color:black"><o:p></o:p></span></p>
<p style="margin:0in;font-variant-numeric:normal;font-variant-east-asian:normal;font-stretch:normal">
<span style="font-size:8.5pt;font-family:Menlo;color:black"><br>
<br>
<o:p></o:p></span></p>
<div>
<div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
</div>
</div>
</div>
</div>
</div>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">-- <br>
For Consortium Member technical support, see <a href="https://urldefense.com/v3/__https:/shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!IBzWLUs!Uh8wFlfuc978oQXmKDKiX67R9IR7ITEq7a6VXdqacXXM_w0c0r2olxqLQ1Ig13ugysZOVEz1W5OEENUQ$" target="_blank">
https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a><o:p></o:p></span></p>
</div>
</div>
</blockquote>
</div>
</div>
</blockquote>
</div>
</div>
</div>
</div>
</body>
</html>