Skip to Content.
Sympa Menu

metadata-support - Re: [Metadata-Support] SP configuration for new InCommon Aggregate

Subject: InCommon metadata support

List archive

Re: [Metadata-Support] SP configuration for new InCommon Aggregate


Chronological Thread 
  • From: "Kathy E. Wright" <>
  • To:
  • Subject: Re: [Metadata-Support] SP configuration for new InCommon Aggregate
  • Date: Fri, 28 Mar 2014 18:12:39 -0400

​This works without error:

<MetadataProvider type="XML" url=""http://wayf.incommonfederation.org/InCommon/InCommon-metadata.xml" backingFilePath="incommon/InCommon-metadata.xml">

             <MetadataFilter type="Signature" certificate="incommon/inc-md-cert.pem"/>

</MetadataProvider>


​This gives an error:
<MetadataProvider type="XML" url=""http://md.incommon.org/InCommon/InCommon-metadata-fallback.xml" backingFilePath="incommon/InCommon-metadata-fallback.xml">

             <MetadataFilter type="Signature" certificate="incommon/inc-md-cert.pem"/>

</MetadataProvider>

WARN OpenSAML.MetadataFilter.Signature : filtering out group at root of instance after failed signature check: Unable to verify signature with supplied key(s).

​Best always,
Kathy​





Then I would expect it to work with the fallback aggregate:

http://md.incommon.org/InCommon/InCommon-metadata-fallback.xml

Can you confirm this is the case?

Also, can you post your complete <MetadataProvider> element here? (or
send it offline if you're concerned for one reason or the other)

Thanks,

Tom






Archive powered by MHonArc 2.6.16.

Top of Page