Error occured in RSA Federated Identity Manger (FIM) 4.1 'Unable to verify the signature value' error when processing assertion
Originally Published: 2013-07-04
Article Number
Applies To
RSA Product/Service Type: RSA Federated Identity Manger (FIM)
RSA Version/Condition: 4.1
ComponantSpace SAML v2.0 Single Sign-On (SSO) Component for .NET
Issue
Error message in system.out log
Unable to verify the signature value: SAMLSignedObject.verify() detected an invalid signature profile, com.rsa.fim.exception.CryptoUtilException: Unable to verify the signature value: SAMLSignedObject.verify() detected an invalid signature profile
Error message in debug.log
util.crypto.dsig.verify.error, com.rsa.fim.saml.InvalidCryptoException: SAMLSignedObject.verify() detected an invalid signature profile.
Cause
The SAML 2.x specification lists only three acceptable transforms. If a transform other than the listed ones is used this error is generated.
5.4.4 Transforms
Signatures in SAML messages SHOULD NOT contain transforms other than the enveloped signature transform (with the identifier http://www.w3.org/2000/09/xmldsig#enveloped-signature) or the exclusive canonicalization transforms (with the identifier http://www.w3.org/2001/10/xml-exc-c14n# or http://www.w3.org/2001/10/xml-exc-c14n#WithComments).
Verifiers of signatures MAY reject signatures that contain other transform algorithms as invalid.
Resolution
Related Articles
SecurID Authentication API service down on RSA Authentication Manager 8.x 133Number of Views Access Manger MUX Pool Exhausted error message 123Number of Views How to check if NTP is working on your RSA SecurID Access Identity Router 662Number of Views Questions on the security of offline authentication data in the RSA SecurID Authentication Agent for Microsoft Windows 296Number of Views RSA Governance & Lifecycle Advanced Dashboards Library Release Notes - Revision 2.0 31Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA-2026-07: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?