mace-opensaml-users - RE: [OpenSAML] Verifying SAML signed metadata files
Subject: OpenSAML user discussion
List archive
- From: Paolo Selvini <>
- To: "" <>
- Subject: RE: [OpenSAML] Verifying SAML signed metadata files
- Date: Fri, 2 May 2008 15:42:12 +0200
- Accept-language: it-IT, en-US
- Acceptlanguage: it-IT, en-US
Hi again and thanks for the hint about the metadata filter.
I did as you suggested and I managed to correctly verify a signed metadata file.
Now I have a (hopefully) last problem: my original metadata file contains a SPSSODescriptor element with a number of AttributeConsumingService elements. According
to the specification, each of those can store one or more RequestedAttribute elements, possibly including a FriendlyName attribute.
However, if I use - for the value of such FriendlyName attribute - some accented chars (like à, è, ...) that are pretty common in the Italian language, the
signature in the new signed file is no more verified. That is, the same code used to sign and verify a metadata file without accented chars, no longer works it I change even just a single char (say from "a" to "à") in the unsigned file, sign it and verify
it. If I replace the accented char back with a normal char, sign and verify again, everything is ok.
What happens is a MetadataProviderException with inner cause "org.opensaml.saml2.metadata.provider.FilterException: Signature trust establishment
failed for metadata entry" when I invoke the initialize() method on the metadata provider.
FYI: both the unsigned and the signed files have UTF-8 encoding without BOM (byte order mark).
Any idea about the possible cause?
thanks,
Paolo
Le informazioni contenute in questa comunicazione e negli allegati sono riservate; e' vietato a soggetti diversi dai destinatari qualsiasi uso, copia, diffusione di quanto in essi contenuto. Se avete ricevuto questa copia per errore, vi preghiamo di distruggerla immediatamente ed informarci via e-mail. Prima di stampare questa e-mail consideratene l’impatto sull’ambiente. Grazie per la collaborazione. This e-mail and any attachment(s) are strictly confidential. This message must not be copied, disclosed or used by anybody other than the intended recipient(s). If you are not the intended recipient, please inform the sender by e-mail and destroy this message immediately. Please consider the environment before printing this e-mail. Thank you for your cooperation. |
- RE: [OpenSAML] Verifying SAML signed metadata files, Paolo Selvini, 05/02/2008
- Re: [OpenSAML] Verifying SAML signed metadata files, Chad La Joie, 05/02/2008
- RE: [OpenSAML] Verifying SAML signed metadata files, Paolo Selvini, 05/02/2008
- RE: [OpenSAML] Verifying SAML signed metadata files, Scott Cantor, 05/02/2008
- RE: [OpenSAML] Verifying SAML signed metadata files, Paolo Selvini, 05/02/2008
- RE: [OpenSAML] Verifying SAML signed metadata files, Paolo Selvini, 05/05/2008
- Re: [OpenSAML] Verifying SAML signed metadata files, Chad La Joie, 05/05/2008
- RE: [OpenSAML] Verifying SAML signed metadata files, Paolo Selvini, 05/05/2008
- Re: [OpenSAML] Verifying SAML signed metadata files, Chad La Joie, 05/05/2008
- RE: [OpenSAML] Verifying SAML signed metadata files, Paolo Selvini, 05/05/2008
- RE: [OpenSAML] Verifying SAML signed metadata files, Paolo Selvini, 05/02/2008
- Re: [OpenSAML] Verifying SAML signed metadata files, Chad La Joie, 05/02/2008
Archive powered by MHonArc 2.6.16.