<div dir="ltr"><pre style="white-space:pre-wrap;color:rgb(0,0,0)">Posted it again.</pre><pre style="white-space:pre-wrap;color:rgb(0,0,0)">Hey guys,

Our customer using adfs renewed their cert. After updating the their idp
metadata, we received the following error messages:

shibd.log:2023-01-27 18:29:50 WARN XMLTooling.Decrypter [5] [default]:
XMLSecurity exception while decrypting key: OpenSSL:RSA privateKeyDecrypt -
Error removing OAEPadding
shibd.log:2023-01-27 18:29:50 WARN OpenSAML.SecurityPolicyRule.XMLSigning
[5] [default]: unable to verify message signature with supplied trust engine
shibd.log:2023-01-27 18:29:50 WARN Shibboleth.SSO.SAML2 [5] [default]:
detected a problem with assertion: Message was signed, but signature could
not be verified.
shibd.log:2023-01-27 18:29:50 WARN Shibboleth.SSO.SAML2 [5] [default]:
error processing incoming assertion: Message was signed, but signature
could not be verified.

We used the "explicit key" as the trust engine, our shibboleth SP
is version 3.2.3-3.1.
<br></pre><pre style="white-space:pre-wrap;color:rgb(0,0,0)">We also verified everything based on <a href="https://shibboleth.atlassian.net/wiki/spaces/SHIB2/pages/2577072495/NativeSPTroubleshootingCommonErrors#NativeSPTroubleshootingCommonErrors-Messagewassigned%2Cbutsignaturecouldnotbeverified">https://shibboleth.atlassian.net/wiki/spaces/SHIB2/pages/2577072495/NativeSPTroubleshootingCommonErrors#NativeSPTroubleshootingCommonErrors-Messagewassigned%2Cbutsignaturecouldnotbeverified</a>. Everything looks correct.</pre><pre style="white-space:pre-wrap;color:rgb(0,0,0)">We noticed that our customer's public cert has a size of 2237, all our
other adfs customer's cert size is less than 2k, we suspected that might be
an issue.


Any help is much appreciated.

Thanks
Terry</pre></div>