<!DOCTYPE html><html><head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<font face="Helvetica, Arial, sans-serif">We have SP that we have a
test and production instance. Several times during the year, our
app admin follows vendor documentation that copy the production
instance onto the test instance. Then they have to change the SSO
config on the test instance, because it holds production instance
config data. After which they export the update test instance
metadata and all I have to do is replace the old metadata file on
Shib with the new metadata file and reload the metadata provider
module and SSO login now works for the test instance.<br>
<br>
They refer to this as a refresh. A prd to test refresh was done
last week but SSL login is failing before landing on our Shib
login page.<br>
<br>
In the id-process.log file from a SSO login attempt is the
following:<br>
<br>
<font size="2">2024-03-21 12:01:13,784 - WARN
[org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:287]
- Message Handler: Simple signature validation (with no
request-derived credentials) failed<br>
<br>
2024-03-21 12:01:13,784 - WARN
[org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:226]
- Message Handler: Validation of request simple signature
failed for context issuer:
<a class="moz-txt-link-freetext" href="https://acme--jmutest.sandbox.my.acme.com">https://acme--jmutest.sandbox.my.acme.com</a><br>
<br>
2024-03-21 12:01:13,784 - WARN
[net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:197]
- Profile Action WebFlowMessageHandlerAdaptor: Exception
handling message
org.opensaml.messaging.handler.MessageHandlerException:
Validation of request simple signature failed for context issuer
at
org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler.doEvaluate(BaseSAMLSimpleSignatureSecurityHandler.java:228)<br>
</font><br>
The vendor is telling me that I have our IdP mis-configured, but
can't explain why login to the prod instance log is successful.Our
test and prod instance share the same relying-party.xml,
attribute-filter.xml and saml-nameid.xml config file sections. <br>
<br>
What are my idp-process.log entries (above) telling me?<br>
<br>
thx,<br>
Don<br>
</font>
<pre class="moz-signature" cols="72">--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
</body>
</html>