[JIRA] Commented: (SSPCPP-442) NotBefore / NotOnOrAfter from SAML1 IDP possibly not honored

Scott Cantor (JIRA) noreply at shibboleth.net
Mon Apr 23 14:34:03 BST 2012


    [ https://issues.shibboleth.net/jira/browse/SSPCPP-442?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14025#comment-14025 ] 

Scott Cantor commented on SSPCPP-442:
-------------------------------------

Even if the Condition wasn't checked, IssueInstant would be. So what that means is you have a broken configuration in place. Something has disabled the SecurityPolicy code or bypassed both the MessageFlow and Condition rules.

I'll double check the code for any unusual problems, but since IssueInstant would apply before the condition check, it's 100% certain your configuration is the problem. Or a bug leading to the wrong configuration, anyway.

A lot depends on how far back the config goes. A 2.4 config defines the policy rules in the security-policy.xml file, and that gets loaded explicitly at the bottom of the main file. An older config has rules defined at the bottom of the main file.

Please attach at least shibboleth2.xml and security-policy.xml for review.

Also attach a log trace on DEBUG of it accepting a response like this.

> NotBefore / NotOnOrAfter from SAML1 IDP possibly not honored
> ------------------------------------------------------------
>
>                 Key: SSPCPP-442
>                 URL: https://issues.shibboleth.net/jira/browse/SSPCPP-442
>             Project: Shibboleth SP - C++
>          Issue Type: Bug
>          Components: SAML 1.x Single Sign-On
>    Affects Versions: 2.4.3
>            Reporter: martin.haase at idp.protectnetwork.org
>            Assignee: Scott Cantor
>            Priority: Minor
>              Labels: Session
>
> The NotBefore / NotOnOrAfter Conditions Statement sent by a non-Shibboleth SAML 1 IdP seems to be not honored by the SP. In this case, the timeslot set by the IdP is just 1 minute. However, the user is logged in even if the SAML response is presented to the SP a full hour later than issued. Th SP's clock skew is standard (300 sec), also tried with 0 sec.
> Condition checking is not altered. It would be good to know whether the SAML response was not correct, so I'm pasting it here:
> <samlp:Response IssueInstant="2012-03-30T14:02:09.020Z"
>                 MajorVersion="1"
>                 MinorVersion="1"
>                 Recipient="https://sp.example.org/Shibboleth.sso/autologin"
>                 ResponseID="_1234567890abcdef"
>                 xmlns:samlp="urn:oasis:names:tc:SAML:1.0:protocol"
>                 >
>     <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
>         <ds:SignedInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
>             <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"
>                                        xmlns:ds="http://www.w3.org/2000/09/xmldsig#"
>                                        />
>             <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"
>                                 xmlns:ds="http://www.w3.org/2000/09/xmldsig#"
>                                 />
>             <ds:Reference URI="#_1234567890abcdef"
>                           xmlns:ds="http://www.w3.org/2000/09/xmldsig#"
>                           >
>                 <ds:Transforms xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
>                     <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"
>                                   xmlns:ds="http://www.w3.org/2000/09/xmldsig#"
>                                   />
>                     <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"
>                                   xmlns:ds="http://www.w3.org/2000/09/xmldsig#"
>                                   >
>                         <ec:InclusiveNamespaces PrefixList="ds saml samlp xs"
>                                                 xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#"
>                                                 />
>                     </ds:Transform>
>                 </ds:Transforms>
>                 <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"
>                                  xmlns:ds="http://www.w3.org/2000/09/xmldsig#"
>                                  />
>                 <ds:DigestValue xmlns:ds="http://www.w3.org/2000/09/xmldsig#">XXXXXXXXXXXXXXXXXX</ds:DigestValue>
>             </ds:Reference>
>         </ds:SignedInfo>
>         <ds:SignatureValue xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
> XXXXXXXXXXXXXXXXXX
> </ds:SignatureValue>
>         <ds:KeyInfo>
>             <ds:X509Data>
>                 <ds:X509Certificate>XXXXXXXXXXXXXXXX</ds:X509Certificate>
>             </ds:X509Data>
>         </ds:KeyInfo>
>     </ds:Signature>
>     <samlp:Status>
>         <samlp:StatusCode Value="samlp:Success" />
>     </samlp:Status>
>     <saml:Assertion AssertionID="_fedcba0987654321"
>                     IssueInstant="2012-03-30T14:02:09.020Z"
>                     Issuer="idp.example.org"
>                     MajorVersion="1"
>                     MinorVersion="1"
>                     xmlns:saml="urn:oasis:names:tc:SAML:1.0:assertion"
>                     >
>         <saml:Conditions NotBefore="2012-03-30T14:02:09.020Z"
>                          NotOnOrAfter="2012-03-30T14:03:09.020Z"
>                          />
>         <saml:AuthenticationStatement AuthenticationInstant="2012-03-30T14:02:02.208Z"
>                                       AuthenticationMethod="urn:oasis:names:tc:SAML:1.0:am:password"
>                                       >
>             <saml:Subject>
>                 <saml:NameIdentifier Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
>                                      NameQualifier="uid"
>                                      >A12345</saml:NameIdentifier>
>                 <saml:SubjectConfirmation>
>                     <saml:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:bearer</saml:ConfirmationMethod>
>                 </saml:SubjectConfirmation>
>             </saml:Subject>
>         </saml:AuthenticationStatement>
>         <saml:AttributeStatement>
>             <saml:Subject>
>                 <saml:NameIdentifier Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
>                                      NameQualifier="uid"
>                                      >J616251</saml:NameIdentifier>
>                 <saml:SubjectConfirmation>
>                     <saml:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:bearer</saml:ConfirmationMethod>
>                 </saml:SubjectConfirmation>
>             </saml:Subject>
>             <saml:Attribute AttributeName="gender"
>                             AttributeNamespace="idpns"
>                             >
>                 <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema"
>                                      xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
>                                      xsi:type="xs:string"
>                                      >M</saml:AttributeValue>
>             </saml:Attribute>
>             <saml:Attribute AttributeName="sn"
>                             AttributeNamespace="idpns"
>                             >
>                 <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema"
>                                      xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
>                                      xsi:type="xs:string"
>                                      >DOE</saml:AttributeValue>
>             </saml:Attribute>
> 	    <!-- further attributes following -->
>         </saml:AttributeStatement>
>     </saml:Assertion>
> </samlp:Response>

--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira


More information about the commits mailing list