<!DOCTYPE html><html><head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body>
    <font face="Helvetica, Arial, sans-serif">We have SP that we have a
      test and production instance. Several times during the year, our
      app admin follows vendor documentation that copy the production
      instance onto the test instance. Then they have to change the SSO
      config on the test instance, because it holds production instance
      config data. After which they export the update test instance
      metadata and all I have to do is replace the old metadata file on
      Shib with the new metadata file and reload the metadata provider
      module and SSO login now works for the test instance.<br>
      <br>
      They refer to this as a refresh. A prd to test refresh was done
      last week but SSL login is failing before landing on our Shib
      login page.<br>
      <br>
      In the id-process.log file from a SSO login attempt is the
      following:<br>
      <br>
      <font size="2">2024-03-21 12:01:13,784 - WARN
[org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:287]
        - Message Handler:  Simple signature validation (with no
        request-derived credentials) failed<br>
        <br>
        2024-03-21 12:01:13,784 - WARN
[org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:226]
        - Message Handler:  Validation of request simple signature
        failed for context issuer:
        <a class="moz-txt-link-freetext" href="https://acme--jmutest.sandbox.my.acme.com">https://acme--jmutest.sandbox.my.acme.com</a><br>
        <br>
        2024-03-21 12:01:13,784 - WARN
        [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:197]
        - Profile Action WebFlowMessageHandlerAdaptor: Exception
        handling message
        org.opensaml.messaging.handler.MessageHandlerException:
        Validation of request simple signature failed for context issuer
        at
org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler.doEvaluate(BaseSAMLSimpleSignatureSecurityHandler.java:228)<br>
      </font><br>
      The vendor is telling me that I have our IdP mis-configured, but
      can't explain why login to the prod instance log is successful.Our
      test and prod instance share the same relying-party.xml,
      attribute-filter.xml and saml-nameid.xml config file sections. <br>
      <br>
      What are my idp-process.log entries (above) telling me?<br>
      <br>
      thx,<br>
      Don<br>
    </font>
    <pre class="moz-signature" cols="72">-- 
D o n a l d   L o h r
I n f o r m a t i o n   S y s t e m s
J a m e s   M a d i s o n   U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
  </body>
</html>