Skip to Content.
Sympa Menu

mace-opensaml-users - RE: [OpenSAML] RE: SAML1.1 response signature validation fails but assertion signature validation passes

Subject: OpenSAML user discussion

List archive

RE: [OpenSAML] RE: SAML1.1 response signature validation fails but assertion signature validation passes


Chronological Thread 
  • From: "Pantvaidya, Vishwajit" <>
  • To: "" <>, Scott Cantor <>
  • Subject: RE: [OpenSAML] RE: SAML1.1 response signature validation fails but assertion signature validation passes
  • Date: Mon, 17 Nov 2008 18:26:41 -0800
  • Accept-language: en-US
  • Acceptlanguage: en-US


> > > Actually, the IdP is older and uses xmlsec 1.2.1 (not 1.4.2) - so the
> > > digester debug logging settings I set in the IdP log4j.xml did not
> work.
> > I
> > > am trying to see if/how I can enable digester debug logging there.

> >
> > Based on recent conversations, you can't. You'll have to update it to
> use
> > 1.4.2 or find some other way to debug this.
> >
> > -- Scott
> >


>
> [Pantvaidya, Vishwajit] That's what I am trying to do right now - after I
> found I could not find much on xmlsec 1.2.1. Thanks Scott.

[Pantvaidya, Vishwajit] That didn't work (I got an exception on the IdP side
while generating a message) - maybe the IdP uses some 1.2.1 xmlsec api that
is not there in 1.4.2

My next option was to use the testshib IdP to send a saml request to my SP -
but that would require my local machine to be externally visible, which it is
not. So I guess my only remaining option is to install a local Shibboleth IdP
for sending saml responses to my SP.





Archive powered by MHonArc 2.6.16.

Top of Page