技术文章 - CS349837
使用 SSO 配置 Windchill 时,Shibboleth 日志中出现错误“消息已签名,但无法验证签名”
已修改: 11-Aug-2022
适用于
- Windchill PDMLink 11.1 to 12.1
说明
- shibd.log 文件中的以下错误:
WARN OpenSAML.SecurityPolicyRule.XMLSigning [2] [default]: unable to verify message signature with supplied trust engine WARN Shibboleth.SSO.SAML2 [2] [default]: detected a problem with assertion: Message was signed, but signature could not be verified. WARN Shibboleth.SSO.SAML2 [2] [default]: error processing incoming assertion: Message was signed, but signature could not be verified.
- IdP 用于签名的证书不属于用于签名验证的证书列表(包含在 federationmetadata.xml 中)
这是文章 349837 的 PDF 版本,可能已过期。最新版本 CS349837