Skip to Content.
Sympa Menu

metadata-support - Re: [Metadata-Support] SP configuration for new InCommon Aggregate

Subject: InCommon metadata support

List archive

Re: [Metadata-Support] SP configuration for new InCommon Aggregate


Chronological Thread 
  • From: Tom Scavo <>
  • To: "" <>
  • Subject: Re: [Metadata-Support] SP configuration for new InCommon Aggregate
  • Date: Fri, 28 Mar 2014 18:26:31 -0400

On Fri, Mar 28, 2014 at 6:12 PM, Kathy E. Wright
<>
wrote:
> This works without error:
>
> <MetadataProvider type="XML"
> url="http://wayf.incommonfederation.org/InCommon/InCommon-metadata.xml";
> backingFilePath="incommon/InCommon-metadata.xml">
>
> <MetadataFilter type="Signature"
> certificate="incommon/inc-md-cert.pem"/>
>
> </MetadataProvider>
>
> This gives an error:
> <MetadataProvider type="XML"
> url="http://md.incommon.org/InCommon/InCommon-metadata-fallback.xml";
> backingFilePath="incommon/InCommon-metadata-fallback.xml">
>
> <MetadataFilter type="Signature"
> certificate="incommon/inc-md-cert.pem"/>
>
> </MetadataProvider>
>
> WARN OpenSAML.MetadataFilter.Signature : filtering out group at root of
> instance after failed signature check: Unable to verify signature with
> supplied key(s).

Do you receive the same error if you replace

http://md.incommon.org/InCommon/InCommon-metadata-fallback.xml

with

http://md.incommon.org/InCommon/InCommon-metadata.xml

in the MetadataProvider?

Also, can you remind me what version of Shibboleth IdP you're using?

Tom



Archive powered by MHonArc 2.6.16.

Top of Page