<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Verification of SAML assertion using the IDP's certificate provided failed. Error: failed to verify signature with cert in Security</title>
    <link>https://community.splunk.com/t5/Security/Verification-of-SAML-assertion-using-the-IDP-s-certificate/m-p/691142#M17943</link>
    <description>&lt;P&gt;my SAML Response to Splunk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;?xml version="1.0" encoding="UTF-8" standalone="no"?&amp;gt;&amp;lt;samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" Destination="&lt;A href="http://RTNB336:8000/saml/acs" target="_blank"&gt;http://RTNB336:8000/saml/acs&lt;/A&gt;" ID="_4c16f9be1c813c774f2f9111fd5602f6" InResponseTo="RTNB336.21.0882C4AC-681F-4648-AD0F-FDD9F4BE114B" IssueInstant="2024-06-20T01:56:14.199Z" Version="2.0"&amp;gt;&amp;lt;saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"&amp;gt;&lt;A href="http://hive.dreamidaas.com" target="_blank"&gt;http://hive.dreamidaas.com&lt;/A&gt;&amp;lt;/saml2:Issuer&amp;gt;&amp;lt;ds:Signature xmlns:ds="&lt;A href="http://www.w3.org/2000/09/xmldsig#" target="_blank"&gt;http://www.w3.org/2000/09/xmldsig#&lt;/A&gt;"&amp;gt;&amp;lt;ds:SignedInfo&amp;gt;&amp;lt;ds:CanonicalizationMethod Algorithm="&lt;A href="http://www.w3.org/2001/10/xml-exc-c14n#" target="_blank"&gt;http://www.w3.org/2001/10/xml-exc-c14n#&lt;/A&gt;"/&amp;gt;&amp;lt;ds:SignatureMethod Algorithm="&lt;A href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" target="_blank"&gt;http://www.w3.org/2001/04/xmldsig-more#rsa-sha256&lt;/A&gt;"/&amp;gt;&amp;lt;ds:Reference URI="#_4c16f9be1c813c774f2f9111fd5602f6"&amp;gt;&amp;lt;ds:Transforms&amp;gt;&amp;lt;ds:Transform Algorithm="&lt;A href="http://www.w3.org/2000/09/xmldsig#enveloped-signature" target="_blank"&gt;http://www.w3.org/2000/09/xmldsig#enveloped-signature&lt;/A&gt;"/&amp;gt;&amp;lt;ds:Transform Algorithm="&lt;A href="http://www.w3.org/2001/10/xml-exc-c14n#" target="_blank"&gt;http://www.w3.org/2001/10/xml-exc-c14n#&lt;/A&gt;"/&amp;gt;&amp;lt;/ds:Transforms&amp;gt;&amp;lt;ds:DigestMethod Algorithm="&lt;A href="http://www.w3.org/2001/04/xmlenc#sha256" target="_blank"&gt;http://www.w3.org/2001/04/xmlenc#sha256&lt;/A&gt;"/&amp;gt;&amp;lt;ds:DigestValue&amp;gt;Wjlp0IBLeluYep7QMphL/ZBkVsDqxbrFcgSDFiFxQBo=&amp;lt;/ds:DigestValue&amp;gt;&amp;lt;/ds:Reference&amp;gt;&amp;lt;/ds:SignedInfo&amp;gt;&amp;lt;ds:SignatureValue&amp;gt;Y0Lp7OR2BWIie+F60hJUhNdOLKhWlXnjLyD0Y7Ut1lPIYfL9uoClcQA98Ge961M7FjrC/uDA8yxGYKvApU4VOYzy7kLM0wbxFKUVXAuPAl5of0WWrMV8QMSWfCq8/ensPzlzsqg84tf86UgMZ2PodD6WOM9SIIW+izBPOP3emuv2c+UrvR2eyp1s+ItWn0AUB+0R0l+iqd+sNE/Gb+l9THlJYm68yLr2DY0nT66dOLKS3Q3jnMox6xrzsSnwaF6+H+dSnvd5YeBIMyjTC1bF6GjQpdudTNz8162TvtJjvAcTUOwhUmLyY4ytTvL+lHKOsDh57wZenvB4gVYzoF6T+A==&amp;lt;/ds:SignatureValue&amp;gt;&amp;lt;ds:KeyInfo&amp;gt;&amp;lt;ds:X509Data&amp;gt;&amp;lt;ds:X509Certificate&amp;gt;MIIDtDCCApygAwIBAgIKJxHdhEoMRRD/JjANBgkqhkiG9w0BAQsFADBCMQswCQYDVQQGEwJLUjEW&lt;BR /&gt;MBQGA1UECgwNRHJlYW1TZWN1cml0eTEMMAoGA1UECwwDU1NPMQ0wCwYDVQQDDARST09UMB4XDTIy&lt;BR /&gt;MDIyMzIzNTY1NFoXDTMyMDIyMzIzNTY1NFowTzELMAkGA1UEBhMCS1IxFjAUBgNVBAoMDURyZWFt&lt;BR /&gt;U2VjdXJpdHkxDDAKBgNVBAsMA1NTTzEaMBgGA1UEAwwRTUFHSUNfU1NPX0lEUF9TaWcwggEiMA0G&lt;BR /&gt;CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCGEA5RIOlCH/xJX5qnAQRixJfuUhv2dBoGyCjO1qbJ&lt;BR /&gt;GuJh6lCF7mwsJbS+PStFrFvXBrfFt8S2QU7hndK5aj3f83IJiiv6y+a26/4xNf19sp6AtafAmWr9&lt;BR /&gt;kkI5AH51/9l8ypzf67OAUfrJxFPW6ZKgWiGp5yjrensl1IKxwP0joxUQXISI+epu07XpdWF2SJQ7&lt;BR /&gt;rVRNPZUP6sA+lNQsFDznN7moWFcU+UyrTJHDkgj/2qw4QvucNBY7Hj/bC/6KX1d0XSKfvQCfI4gu&lt;BR /&gt;Gd/4FL1ApnyTvZ/tnbcbl420NWbKgtn19Q4ZIqhj10ruTzVn1YOpwqBGP/NlKDVmKOCem7tvAgMB&lt;BR /&gt;AAGjgZ4wgZswagYDVR0jBGMwYYAULffLTJtBlWrpR2I1Coc4OG3funyhRqREMEIxCzAJBgNVBAYT&lt;BR /&gt;AktSMRYwFAYDVQQKDA1EcmVhbVNlY3VyaXR5MQwwCgYDVQQLDANTU08xDTALBgNVBAMMBFJPT1SC&lt;BR /&gt;AQEwHQYDVR0OBBYEFPvKSaxuZMLnM8ZqaFFkw0xeDp8CMA4GA1UdDwEB/wQEAwIGwDANBgkqhkiG&lt;BR /&gt;9w0BAQsFAAOCAQEAflCL2e6ZHxGDtK6PSjrGrhrkJ4XYHvKGnEWWajhL0RqqDoQhEAOAzEyGMcpQ&lt;BR /&gt;zWBF6etI+uDlnr7EfPCAojvwfcQCEGK4gCHskHHDkXNz5MAC2sSHqVEn/ChAO9nRnTRo4EZlFVgH&lt;BR /&gt;SXIDJqeWZd2wJ86u9cqA6XTyB/KuVwnTD2U/1W87ERpKlXtDNnC5hB3cp1ONaW+0+Fnn4NdSgMQd&lt;BR /&gt;SwteL/CtU+q/gcYt1izy1RGdcDRR11+nmfkZT6UYCyKj0ea0yc4SbRjGIEOgJExDJBL8eyc4X2D3&lt;BR /&gt;4k6B4rhPzx+vF1OB1esHB69T6Vlo+iUM+XtoLFUOhloNiDzXq+2Hgg==&amp;lt;/ds:X509Certificate&amp;gt;&amp;lt;/ds:X509Data&amp;gt;&amp;lt;/ds:KeyInfo&amp;gt;&amp;lt;/ds:Signature&amp;gt;&amp;lt;saml2p:Status xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"&amp;gt;&amp;lt;saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/&amp;gt;&amp;lt;/saml2p:Status&amp;gt;&amp;lt;saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_93ae10442348482eb51b04051c58267a" IssueInstant="2024-06-20T01:56:14.199Z" Version="2.0"&amp;gt;&amp;lt;saml2:Issuer&amp;gt;&lt;A href="http://hive.dreamidaas.com" target="_blank"&gt;http://hive.dreamidaas.com&lt;/A&gt;&amp;lt;/saml2:Issuer&amp;gt;&amp;lt;saml2:Subject&amp;gt;&amp;lt;saml2:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress" NameQualifier="&lt;A href="http://hive.dreamidaas.com" target="_blank"&gt;http://hive.dreamidaas.com&lt;/A&gt;" SPNameQualifier="RTNB336"&amp;gt;rladnrud@devdreamsso.site&amp;lt;/saml2:NameID&amp;gt;&amp;lt;saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"&amp;gt;&amp;lt;saml2:SubjectConfirmationData InResponseTo="RTNB336.21.0882C4AC-681F-4648-AD0F-FDD9F4BE114B" NotOnOrAfter="2024-06-20T02:01:14.199Z" Recipient="&lt;A href="http://RTNB336:8000/saml/acs" target="_blank"&gt;http://RTNB336:8000/saml/acs&lt;/A&gt;"/&amp;gt;&amp;lt;/saml2:SubjectConfirmation&amp;gt;&amp;lt;/saml2:Subject&amp;gt;&amp;lt;saml2:Conditions NotBefore="2024-06-20T01:56:14.199Z" NotOnOrAfter="2024-06-20T02:01:14.199Z"&amp;gt;&amp;lt;saml2:AudienceRestriction&amp;gt;&amp;lt;saml2:Audience&amp;gt;RTNB336&amp;lt;/saml2:Audience&amp;gt;&amp;lt;/saml2:AudienceRestriction&amp;gt;&amp;lt;/saml2:Conditions&amp;gt;&amp;lt;saml2:AuthnStatement AuthnInstant="2024-06-20T01:55:52.000Z" SessionIndex="_8028c81d727dcc5a423afa58c645b8c5"&amp;gt;&amp;lt;saml2:AuthnContext&amp;gt;&amp;lt;saml2:AuthnContextClassRef&amp;gt;urn:oasis:names:tc:SAML:2.0:ac:classes:InternetProtocol&amp;lt;/saml2:AuthnContextClassRef&amp;gt;&amp;lt;/saml2:AuthnContext&amp;gt;&amp;lt;/saml2:AuthnStatement&amp;gt;&amp;lt;/saml2:Assertion&amp;gt;&amp;lt;/samlp:Response&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There's no problem in my IDP.&amp;nbsp;&lt;SPAN&gt;I don't know why Splunk can't verify signature properly&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jun 2024 04:15:38 GMT</pubDate>
    <dc:creator>lguplusIdaas</dc:creator>
    <dc:date>2024-06-20T04:15:38Z</dc:date>
    <item>
      <title>Verification of SAML assertion using the IDP's certificate provided failed. Error: failed to verify signature with cert</title>
      <link>https://community.splunk.com/t5/Security/Verification-of-SAML-assertion-using-the-IDP-s-certificate/m-p/691142#M17943</link>
      <description>&lt;P&gt;my SAML Response to Splunk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;?xml version="1.0" encoding="UTF-8" standalone="no"?&amp;gt;&amp;lt;samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" Destination="&lt;A href="http://RTNB336:8000/saml/acs" target="_blank"&gt;http://RTNB336:8000/saml/acs&lt;/A&gt;" ID="_4c16f9be1c813c774f2f9111fd5602f6" InResponseTo="RTNB336.21.0882C4AC-681F-4648-AD0F-FDD9F4BE114B" IssueInstant="2024-06-20T01:56:14.199Z" Version="2.0"&amp;gt;&amp;lt;saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"&amp;gt;&lt;A href="http://hive.dreamidaas.com" target="_blank"&gt;http://hive.dreamidaas.com&lt;/A&gt;&amp;lt;/saml2:Issuer&amp;gt;&amp;lt;ds:Signature xmlns:ds="&lt;A href="http://www.w3.org/2000/09/xmldsig#" target="_blank"&gt;http://www.w3.org/2000/09/xmldsig#&lt;/A&gt;"&amp;gt;&amp;lt;ds:SignedInfo&amp;gt;&amp;lt;ds:CanonicalizationMethod Algorithm="&lt;A href="http://www.w3.org/2001/10/xml-exc-c14n#" target="_blank"&gt;http://www.w3.org/2001/10/xml-exc-c14n#&lt;/A&gt;"/&amp;gt;&amp;lt;ds:SignatureMethod Algorithm="&lt;A href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" target="_blank"&gt;http://www.w3.org/2001/04/xmldsig-more#rsa-sha256&lt;/A&gt;"/&amp;gt;&amp;lt;ds:Reference URI="#_4c16f9be1c813c774f2f9111fd5602f6"&amp;gt;&amp;lt;ds:Transforms&amp;gt;&amp;lt;ds:Transform Algorithm="&lt;A href="http://www.w3.org/2000/09/xmldsig#enveloped-signature" target="_blank"&gt;http://www.w3.org/2000/09/xmldsig#enveloped-signature&lt;/A&gt;"/&amp;gt;&amp;lt;ds:Transform Algorithm="&lt;A href="http://www.w3.org/2001/10/xml-exc-c14n#" target="_blank"&gt;http://www.w3.org/2001/10/xml-exc-c14n#&lt;/A&gt;"/&amp;gt;&amp;lt;/ds:Transforms&amp;gt;&amp;lt;ds:DigestMethod Algorithm="&lt;A href="http://www.w3.org/2001/04/xmlenc#sha256" target="_blank"&gt;http://www.w3.org/2001/04/xmlenc#sha256&lt;/A&gt;"/&amp;gt;&amp;lt;ds:DigestValue&amp;gt;Wjlp0IBLeluYep7QMphL/ZBkVsDqxbrFcgSDFiFxQBo=&amp;lt;/ds:DigestValue&amp;gt;&amp;lt;/ds:Reference&amp;gt;&amp;lt;/ds:SignedInfo&amp;gt;&amp;lt;ds:SignatureValue&amp;gt;Y0Lp7OR2BWIie+F60hJUhNdOLKhWlXnjLyD0Y7Ut1lPIYfL9uoClcQA98Ge961M7FjrC/uDA8yxGYKvApU4VOYzy7kLM0wbxFKUVXAuPAl5of0WWrMV8QMSWfCq8/ensPzlzsqg84tf86UgMZ2PodD6WOM9SIIW+izBPOP3emuv2c+UrvR2eyp1s+ItWn0AUB+0R0l+iqd+sNE/Gb+l9THlJYm68yLr2DY0nT66dOLKS3Q3jnMox6xrzsSnwaF6+H+dSnvd5YeBIMyjTC1bF6GjQpdudTNz8162TvtJjvAcTUOwhUmLyY4ytTvL+lHKOsDh57wZenvB4gVYzoF6T+A==&amp;lt;/ds:SignatureValue&amp;gt;&amp;lt;ds:KeyInfo&amp;gt;&amp;lt;ds:X509Data&amp;gt;&amp;lt;ds:X509Certificate&amp;gt;MIIDtDCCApygAwIBAgIKJxHdhEoMRRD/JjANBgkqhkiG9w0BAQsFADBCMQswCQYDVQQGEwJLUjEW&lt;BR /&gt;MBQGA1UECgwNRHJlYW1TZWN1cml0eTEMMAoGA1UECwwDU1NPMQ0wCwYDVQQDDARST09UMB4XDTIy&lt;BR /&gt;MDIyMzIzNTY1NFoXDTMyMDIyMzIzNTY1NFowTzELMAkGA1UEBhMCS1IxFjAUBgNVBAoMDURyZWFt&lt;BR /&gt;U2VjdXJpdHkxDDAKBgNVBAsMA1NTTzEaMBgGA1UEAwwRTUFHSUNfU1NPX0lEUF9TaWcwggEiMA0G&lt;BR /&gt;CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCGEA5RIOlCH/xJX5qnAQRixJfuUhv2dBoGyCjO1qbJ&lt;BR /&gt;GuJh6lCF7mwsJbS+PStFrFvXBrfFt8S2QU7hndK5aj3f83IJiiv6y+a26/4xNf19sp6AtafAmWr9&lt;BR /&gt;kkI5AH51/9l8ypzf67OAUfrJxFPW6ZKgWiGp5yjrensl1IKxwP0joxUQXISI+epu07XpdWF2SJQ7&lt;BR /&gt;rVRNPZUP6sA+lNQsFDznN7moWFcU+UyrTJHDkgj/2qw4QvucNBY7Hj/bC/6KX1d0XSKfvQCfI4gu&lt;BR /&gt;Gd/4FL1ApnyTvZ/tnbcbl420NWbKgtn19Q4ZIqhj10ruTzVn1YOpwqBGP/NlKDVmKOCem7tvAgMB&lt;BR /&gt;AAGjgZ4wgZswagYDVR0jBGMwYYAULffLTJtBlWrpR2I1Coc4OG3funyhRqREMEIxCzAJBgNVBAYT&lt;BR /&gt;AktSMRYwFAYDVQQKDA1EcmVhbVNlY3VyaXR5MQwwCgYDVQQLDANTU08xDTALBgNVBAMMBFJPT1SC&lt;BR /&gt;AQEwHQYDVR0OBBYEFPvKSaxuZMLnM8ZqaFFkw0xeDp8CMA4GA1UdDwEB/wQEAwIGwDANBgkqhkiG&lt;BR /&gt;9w0BAQsFAAOCAQEAflCL2e6ZHxGDtK6PSjrGrhrkJ4XYHvKGnEWWajhL0RqqDoQhEAOAzEyGMcpQ&lt;BR /&gt;zWBF6etI+uDlnr7EfPCAojvwfcQCEGK4gCHskHHDkXNz5MAC2sSHqVEn/ChAO9nRnTRo4EZlFVgH&lt;BR /&gt;SXIDJqeWZd2wJ86u9cqA6XTyB/KuVwnTD2U/1W87ERpKlXtDNnC5hB3cp1ONaW+0+Fnn4NdSgMQd&lt;BR /&gt;SwteL/CtU+q/gcYt1izy1RGdcDRR11+nmfkZT6UYCyKj0ea0yc4SbRjGIEOgJExDJBL8eyc4X2D3&lt;BR /&gt;4k6B4rhPzx+vF1OB1esHB69T6Vlo+iUM+XtoLFUOhloNiDzXq+2Hgg==&amp;lt;/ds:X509Certificate&amp;gt;&amp;lt;/ds:X509Data&amp;gt;&amp;lt;/ds:KeyInfo&amp;gt;&amp;lt;/ds:Signature&amp;gt;&amp;lt;saml2p:Status xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"&amp;gt;&amp;lt;saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/&amp;gt;&amp;lt;/saml2p:Status&amp;gt;&amp;lt;saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_93ae10442348482eb51b04051c58267a" IssueInstant="2024-06-20T01:56:14.199Z" Version="2.0"&amp;gt;&amp;lt;saml2:Issuer&amp;gt;&lt;A href="http://hive.dreamidaas.com" target="_blank"&gt;http://hive.dreamidaas.com&lt;/A&gt;&amp;lt;/saml2:Issuer&amp;gt;&amp;lt;saml2:Subject&amp;gt;&amp;lt;saml2:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress" NameQualifier="&lt;A href="http://hive.dreamidaas.com" target="_blank"&gt;http://hive.dreamidaas.com&lt;/A&gt;" SPNameQualifier="RTNB336"&amp;gt;rladnrud@devdreamsso.site&amp;lt;/saml2:NameID&amp;gt;&amp;lt;saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"&amp;gt;&amp;lt;saml2:SubjectConfirmationData InResponseTo="RTNB336.21.0882C4AC-681F-4648-AD0F-FDD9F4BE114B" NotOnOrAfter="2024-06-20T02:01:14.199Z" Recipient="&lt;A href="http://RTNB336:8000/saml/acs" target="_blank"&gt;http://RTNB336:8000/saml/acs&lt;/A&gt;"/&amp;gt;&amp;lt;/saml2:SubjectConfirmation&amp;gt;&amp;lt;/saml2:Subject&amp;gt;&amp;lt;saml2:Conditions NotBefore="2024-06-20T01:56:14.199Z" NotOnOrAfter="2024-06-20T02:01:14.199Z"&amp;gt;&amp;lt;saml2:AudienceRestriction&amp;gt;&amp;lt;saml2:Audience&amp;gt;RTNB336&amp;lt;/saml2:Audience&amp;gt;&amp;lt;/saml2:AudienceRestriction&amp;gt;&amp;lt;/saml2:Conditions&amp;gt;&amp;lt;saml2:AuthnStatement AuthnInstant="2024-06-20T01:55:52.000Z" SessionIndex="_8028c81d727dcc5a423afa58c645b8c5"&amp;gt;&amp;lt;saml2:AuthnContext&amp;gt;&amp;lt;saml2:AuthnContextClassRef&amp;gt;urn:oasis:names:tc:SAML:2.0:ac:classes:InternetProtocol&amp;lt;/saml2:AuthnContextClassRef&amp;gt;&amp;lt;/saml2:AuthnContext&amp;gt;&amp;lt;/saml2:AuthnStatement&amp;gt;&amp;lt;/saml2:Assertion&amp;gt;&amp;lt;/samlp:Response&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There's no problem in my IDP.&amp;nbsp;&lt;SPAN&gt;I don't know why Splunk can't verify signature properly&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2024 04:15:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Verification-of-SAML-assertion-using-the-IDP-s-certificate/m-p/691142#M17943</guid>
      <dc:creator>lguplusIdaas</dc:creator>
      <dc:date>2024-06-20T04:15:38Z</dc:date>
    </item>
  </channel>
</rss>

