Error: Failed to verify the XML signature, SHA-1 Problem?

Hi guys,

We have a single customer (although an important one) that fails when verifiying saml response in the saml security service provided by you for .NET Core 1.x. We can not figure out why but hoping you guys can help, we notice something about SHA256 supported but SHA1 is used.

This worked when verifying in the old .NET for given customer, more security added perhaps? What can we do about it?

Log from Xml Security is as attached in email.

The configuration for this customer is as follows:
SSO: https://auth.goteborg.se/FIM/sps/Rappet/saml20/login
SLO: https://auth.goteborg.se/FIM/sps/Rappet/saml20/slo
X509Certificate: Same as above

Best regards,
Davidsaml:subjectsaml:nameid&quot;"</saml:nameid""></saml:subject>

Hi David
Please send the log file as an email attachment to support@componentspace.com.

[quote]
ComponentSpace - 10/24/2017
Hi David
Please send the log file as an email attachment to support@componentspace.com.
[/quote]

Hi,

done.

Thanks. Received and investigating.

Hi team,

please resolve the issue I have apply the online PF claim but I have do not apply the online PF i have received error of XML signature verification failed


[quote]
RAMSWAROOP KOLI - 6/2/2018

Hi team,

please resolve the issue I have apply the online PF claim but I have do not apply the online PF i have received error of XML signature verification failed


[/quote]

please help on the same

I’m not sure what you mean by “online PF claim”.
Please elaborate on what the issue is providing as much detail as possible.
Also, please enable SAML trace and send the generated log file to support@componentspace.com mentioning this forum post.

[quote]
Hi guys,

We have a single customer (although an important one) that fails when verifiying saml response in the saml security service provided by you for .NET Core 1.x. We can not figure out why but hoping you guys can help, we notice something about SHA256 supported but SHA1 is used.

This worked when verifying in the old .NET for given customer, more security added perhaps? What can we do about it?

Log from Xml Security is as attached in email.

The configuration for this customer is as follows:
SSO: https://auth.goteborg.se/FIM/sps/Rappet/saml20/login
SLO: https://auth.goteborg.se/FIM/sps/Rappet/saml20/slo
X509Certificate: Same as above

Best regards,
David
[/quote]


Hi team,
please resolve the issue I have apply the online PF claim but I have do not apply the online PF i have received error of XML signature verification failed

I’m not sure what you mean by “online PF claim”.
Please elaborate on what the issue is providing as much detail as possible.
Also, please enable SAML trace and send the generated log file to support@componentspace.com mentioning this forum post.