Error occured in RSA Federated Identity Manger (FIM) 4.1 'Unable to verify the signature value' error when processing assertion
Originally Published: 2013-07-04
Last Modified: 2023-10-06
Article Number
Applies To
RSA Product/Service Type: RSA Federated Identity Manger (FIM)
RSA Version/Condition: 4.1
ComponantSpace SAML v2.0 Single Sign-On (SSO) Component for .NET
Issue
Error message in system.out log
Unable to verify the signature value: SAMLSignedObject.verify() detected an invalid signature profile, com.rsa.fim.exception.CryptoUtilException: Unable to verify the signature value: SAMLSignedObject.verify() detected an invalid signature profile
Error message in debug.log
util.crypto.dsig.verify.error, com.rsa.fim.saml.InvalidCryptoException: SAMLSignedObject.verify() detected an invalid signature profile.
Cause
The SAML 2.x specification lists only three acceptable transforms. If a transform other than the listed ones is used this error is generated.
5.4.4 Transforms
Signatures in SAML messages SHOULD NOT contain transforms other than the enveloped signature transform (with the identifier http://www.w3.org/2000/09/xmldsig#enveloped-signature) or the exclusive canonicalization transforms (with the identifier http://www.w3.org/2001/10/xml-exc-c14n# or http://www.w3.org/2001/10/xml-exc-c14n#WithComments).
Verifiers of signatures MAY reject signatures that contain other transform algorithms as invalid.
Resolution
Related Articles
Users tab slow to load in SecurID Governance & Lifecycle 127Number of Views System.DllNotFoundException: Unable to load DLL 'km' 36Number of Views Example: SAML IdP for Cloud Access Service Assertion 46Number of Views Attributes are missing from the SAML response sent by the RSA SecurID Access Identity Router to Microsoft AD FS 47Number of Views HardwareTokenReplacementBestPractices 85Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update How to Forward RSA Authentication Manager 8.4 or Later Logs to Multiple Syslog Servers Using rsyslog RSA Authentication Manager 8.9 Patches and Hotfixes Readme
Don't see what you're looking for?