Re: [Dev] Shibboleth as an identity provider for APIM-3

2020-01-16 Thread Bernard Paris
Changing the "Signature Algorithm" to "RSA with SHA256" solved this problem. Bernard Le 16 janv. 2020 à 10:51, Bernard Paris mailto:bernard.pa...@uclouvain.be>> a écrit : Hi again, Unfortunately I get an error while trying to use SAML signature: Caused by: org.wso2.carbon.identity.applicatio

Re: [Dev] Shibboleth as an identity provider for APIM-3

2020-01-16 Thread Bernard Paris
Hi again, Unfortunately I get an error while trying to use SAML signature: Caused by: org.wso2.carbon.identity.application.authenticator.samlsso.exception.SAMLSSOException: Error while signing the SAML Request …. Caused by: org.apache.xml.security.signature.XMLSignatureException: can't identi

Re: [Dev] Shibboleth as an identity provider for APIM-3

2020-01-16 Thread Bernard Paris
Ok that's what I was thinking but was not sure, thank you for this clarifications. Regards from Belgium, Bernard Le 15 janv. 2020 à 19:09, Sathya Bandara mailto:sat...@wso2.com>> a écrit : Hi Bernard, Shibboleth server public certificate configured in IDP config is used to verify the signat

Re: [Dev] Shibboleth as an identity provider for APIM-3

2020-01-15 Thread Sathya Bandara
Hi Bernard, Shibboleth server public certificate configured in IDP config is used to verify the signature of SAML responses coming from Shibboleth. When configuring WSO2 as a SP in shibboleth, you need to give WSO2 server’s public certificate (in wso2carbon.jks). If you have enabled assertion enc

Re: [Dev] Shibboleth as an identity provider for APIM-3

2020-01-15 Thread Bernard Paris
Hello, I understood that the certificate defined into the 'Identity Provider Public Certificate' is the public shibboleth certificate needed to decrypt the incoming SAML responses. It was automatically set when I loaded the shibboleth metadata.xml file under " SAML2 Web SSO Configuration" >

Re: [Dev] Shibboleth as an identity provider for APIM-3

2020-01-15 Thread Sathya Bandara
Hi Bernard, You can upload the certificate into the 'Identity Provider Public Certificate' which is available under the 'Basic Information' section of Identity Provider configuration. Thanks, On Wed, Jan 15, 2020 at 8:19 PM Bernard Paris wrote: > Hi devs, > > We want to use Shibboleth as an id