Hi Oli, I added slf4j to Tomcat to obtain more details about what's wrong. You can find the stacktrace below:
6504 [http-bio-8443-exec-1] INFO org.apache.cxf.fediz.core.FederationProcessorImpl - Issuer url: http://localhost:8000/STS/issue 6504 [http-bio-8443-exec-1] INFO org.apache.cxf.fediz.core.FederationProcessorImpl - WAuth: null 6504 [http-bio-8443-exec-1] INFO org.apache.cxf.fediz.core.FederationProcessorImpl - HomeRealm: null 8885 [http-bio-8443-exec-2] WARN org.apache.cxf.fediz.core.FederationProcessorImpl - Failed to validate token java.lang.IllegalStateException: Not supported certificate validation type at org.apache.cxf.fediz.core.config.TrustedIssuer.getCertificateValidationMethod(TrustedIssuer.java:56) at org.apache.cxf.fediz.core.saml.SAMLTokenValidator.validateAndProcessToken(SAMLTokenValidator.java:122) at org.apache.cxf.fediz.core.FederationProcessorImpl.processSignInRequest(FederationProcessorImpl.java:168) at org.apache.cxf.fediz.core.FederationProcessorImpl.processRequest(FederationProcessorImpl.java:70) at org.apache.cxf.fediz.tomcat.FederationAuthenticator.authenticate(FederationAuthenticator.java:339) at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:544) at org.apache.cxf.fediz.tomcat.FederationAuthenticator.invoke(FederationAuthenticator.java:180) at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:168) at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:98) at org.apache.catalina.valves.AccessLogValve.invoke(AccessLogValve.java:927) at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:118) at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:407) at org.apache.coyote.http11.AbstractHttp11Processor.process(AbstractHttp11Processor.java:1001) at org.apache.coyote.AbstractProtocol$AbstractConnectionHandler.process(AbstractProtocol.java:585) at org.apache.tomcat.util.net.JIoEndpoint$SocketProcessor.run(JIoEndpoint.java:312) at java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown Source) at java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source) at java.lang.Thread.run(Unknown Source) Cheers, Frank
