Re: [Dev] Shibboleth as an identity provider for APIM-3

2020-01-16 Thread Bernard Paris
Changing the "Signature Algorithm" to "RSA with SHA256" solved this problem. Bernard Le 16 janv. 2020 à 10:51, Bernard Paris mailto:bernard.pa...@uclouvain.be>> a écrit : Hi again, Unfortunately I get an error while trying to use SAML signature: Caused by:

Re: [Dev] Shibboleth as an identity provider for APIM-3

2020-01-16 Thread Bernard Paris
Hi again, Unfortunately I get an error while trying to use SAML signature: Caused by: org.wso2.carbon.identity.application.authenticator.samlsso.exception.SAMLSSOException: Error while signing the SAML Request …. Caused by: org.apache.xml.security.signature.XMLSignatureException: can't

Re: [Dev] Shibboleth as an identity provider for APIM-3

2020-01-16 Thread Bernard Paris
Ok that's what I was thinking but was not sure, thank you for this clarifications. Regards from Belgium, Bernard Le 15 janv. 2020 à 19:09, Sathya Bandara mailto:sat...@wso2.com>> a écrit : Hi Bernard, Shibboleth server public certificate configured in IDP config is used to verify the

Re: [Dev] Shibboleth as an identity provider for APIM-3

2020-01-15 Thread Sathya Bandara
Hi Bernard, Shibboleth server public certificate configured in IDP config is used to verify the signature of SAML responses coming from Shibboleth. When configuring WSO2 as a SP in shibboleth, you need to give WSO2 server’s public certificate (in wso2carbon.jks). If you have enabled assertion

Re: [Dev] Shibboleth as an identity provider for APIM-3

2020-01-15 Thread Bernard Paris
Hello, I understood that the certificate defined into the 'Identity Provider Public Certificate' is the public shibboleth certificate needed to decrypt the incoming SAML responses. It was automatically set when I loaded the shibboleth metadata.xml file under " SAML2 Web SSO Configuration"

Re: [Dev] Shibboleth as an identity provider for APIM-3

2020-01-15 Thread Sathya Bandara
Hi Bernard, You can upload the certificate into the 'Identity Provider Public Certificate' which is available under the 'Basic Information' section of Identity Provider configuration. Thanks, On Wed, Jan 15, 2020 at 8:19 PM Bernard Paris wrote: > Hi devs, > > We want to use Shibboleth as an

[Dev] Shibboleth as an identity provider for APIM-3

2020-01-15 Thread Bernard Paris
Hi devs, We want to use Shibboleth as an identity provider for API manager V.3. In the carbon console, via the IdP list, we have added an IdP entry then under "Federated Authenticators section and the SAML2 Web SSO Configuration section" we have configured our Shibboleth as identity provider.