Error occured in RSA Federated Identity Manger (FIM) 4.1 'Unable to verify the signature value' error when processing assertion
Originally Published: 2013-07-04
Article Number
Applies To
RSA Product/Service Type: RSA Federated Identity Manger (FIM)
RSA Version/Condition: 4.1
ComponantSpace SAML v2.0 Single Sign-On (SSO) Component for .NET
Issue
Error message in system.out log
Unable to verify the signature value: SAMLSignedObject.verify() detected an invalid signature profile, com.rsa.fim.exception.CryptoUtilException: Unable to verify the signature value: SAMLSignedObject.verify() detected an invalid signature profile
Error message in debug.log
util.crypto.dsig.verify.error, com.rsa.fim.saml.InvalidCryptoException: SAMLSignedObject.verify() detected an invalid signature profile.
Cause
The SAML 2.x specification lists only three acceptable transforms. If a transform other than the listed ones is used this error is generated.
5.4.4 Transforms
Signatures in SAML messages SHOULD NOT contain transforms other than the enveloped signature transform (with the identifier http://www.w3.org/2000/09/xmldsig#enveloped-signature) or the exclusive canonicalization transforms (with the identifier http://www.w3.org/2001/10/xml-exc-c14n# or http://www.w3.org/2001/10/xml-exc-c14n#WithComments).
Verifiers of signatures MAY reject signatures that contain other transform algorithms as invalid.
Resolution
Related Articles
SecurID Authentication API service down on RSA Authentication Manager 8.x 118Number of Views Access Manger MUX Pool Exhausted error message 123Number of Views Admin GUI Actions pop-up menu is missing 12Number of Views "No configured interfaces were detected" error after finishing Quick Setup on a new RSA Authentication Manager 8.4 server 497Number of Views Verify the LDAP Directory Identity Source 68Number of Views
Trending Articles
RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows How a Multi-App Entitlement Collector (MAEDC) resolves entitlement relationships with accounts and groups collected by a M… RSA Governance & Lifecycle 8.0 Patch 10 Release Notes Cloud Administration Clear PIN RSA DS100 OTP Credential API User Event Monitor Messages for Cloud Access Service (20601 - 38000)
Don't see what you're looking for?