[JIRA] Updated: (SIDP-538) Response does not contain Status when assertion assigning is enabled but signing credential is improperly configured
Chad La Joie (JIRA)
noreply at shibboleth.net
Tue Feb 21 19:19:37 GMT 2012
[ https://issues.shibboleth.net/jira/browse/SIDP-538?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Chad La Joie updated SIDP-538:
------------------------------
Description: If a relying party configuration contains a reference to a signing credential that is improperly configured the resultant response to the SP does not contains a Status element as required by the SAML specs. (was: ======================================
Adaptions to sample config (informal):
======================================
The following difference descriptions have been collected by comparisions of the template files to the changed versions using diff.
Template-Placeholders:
$IDP_SCOPE$="idefix.worldtalk.de" (note: adapted since installed because I used my IP instead the FQDN; which resulted in the last two numbers of the IP as scope)
$IDP_HOME$="C:\opt\shibboleth-idp"
$IDP_ENTITY_ID$="https://idefix.worldtalk.de/idp"
$IDP_HOSTNAME$="idefix.worldtalk.de"
[#### shibboleth-idp/conf/ ####]
Unchanged files: attribute-filter.xml, internal.xml, service.xml
--- attribute-resolver.xml ---
identical to template except <resolver:AttributeDefinition>-scope was adapted to "idefix.worldtalk.de"
--- handler.xml ---
commented out <ph:LoginHandler xsi:type="ph:RemoteUser">
activated <ph:LoginHandler xsi:type="ph:UsernamePassword" ...> as following:
<!-- Username/password login handler -->
<ph:LoginHandler xsi:type="ph:UsernamePassword"
jaasConfigurationLocation="file://C:\opt\shibboleth-idp/conf/login.config">
<ph:AuthenticationMethod>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</ph:AuthenticationMethod>
</ph:LoginHandler>
--- logging.xml ---
log-level set to DEBUG for:
<logger name="edu.internet2.middleware.shibboleth" level="DEBUG"/>
<logger name="org.opensaml" level="DEBUG"/>
actived logging of protocol messages:
<logger name="PROTOCOL_MESSAGE" level="DEBUG" />
Rest: Accoring to template (just $IDP_HOME$ replacements)
--- login.config ---
Block complete "ShibUserPassAuth" replaced by:
ShibUserPassAuth {
// Example LDAP authentication
// See: https://wiki.shibboleth.net/confluence/display/SHIB2/IdPAuthUserPass
edu.vt.middleware.ldap.jaas.LdapLoginModule required
ldapUrl="ldap://idefix.worldtalk.de"
bindDn="cn=Manager,dc=worldtalk,dc=de"
bindCredential="secretword"
baseDn="ou=people,dc=worldtalk,dc=de"
ssl="false"
userFilter="uid={0}";
};
--- relying-party.xml ---
Added RelyingParty (as child node of <rp:RelyingPartyGroup>) and a reference to the service provider metadata (child node of <metadata:MetadataProvider id="ShibbolethMetadata" xsi:type="metadata:ChainingMetadataProvider"> just below the metadata tag of the Idp):
----- CUT HERE ----
<rp:RelyingParty id="https://idefix.worldtalk.de/sp"
provider="https://idefix.worldtalk.de/idp"
defaultAuthenticationMethod="urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport" >
<rp:ProfileConfiguration xsi:type="saml:ShibbolethSSOProfile" />
<rp:ProfileConfiguration xsi:type="saml:SAML2SSOProfile" />
<rp:ProfileConfiguration xsi:type="saml:SAML2AttributeQueryProfile" />
<rp:ProfileConfiguration xsi:type="saml:SAML2ArtifactResolutionProfile" />
</rp:RelyingParty>
----- CUT HERE ----
----- CUT HERE ----
<metadata:MetadataProvider id="IdefixSP" xsi:type="metadata:ResourceBackedMetadataProvider">
<metadata:MetadataResource xsi:type="resource:FilesystemResource" file="C:\opt\shibboleth-sp\etc\shibboleth\sp-metadata.xml"/>
</metadata:MetadataProvider>
----- CUT HERE ----
[#### shibboleth-idp/metadata/ ####]
--- idp-metadata.xml ---
<IDPSSODescriptor> - All Location-URLs changed to "https://idefix.worldtalk.de/idp/..." instead of templated "https://idefix.worldtalk.de:8433/idp/..."
<AttributeAuthorityDescriptor> --- Same here for <AttributeService>-Tags...
Reason: Don't like to expose that port / tomcat to public for security reasons later (see AJP-Forwaring Apache/Tomcat above).
Added the following Organization/Contact-Information:
---- CUT HERE ----
<Organization xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata">
<OrganizationName xml:lang="en" xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata">
WorldTalk.de SP
</OrganizationName>
<OrganizationDisplayName xml:lang="en" xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata">
idefix.worldtalk.de
</OrganizationDisplayName>
<OrganizationURL xml:lang="en" xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata">
https://idefix.worldtalk.de/sp/
</OrganizationURL>
</Organization>
<ContactPerson contactType="technical" xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata">
<GivenName xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata">Admin</GivenName>
<SurName xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata">Admin</SurName>
<EmailAddress xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata">webmaster at idefix.worldtalk.de</EmailAddress>
</ContactPerson>
---- CUT HERE ----
[#### shibboleth-sp/etc/shibboleth/ ####]
--- apache22.config ---
Changed <Location /secure> to <Location /sp>
--- native.logger ----
Activated Logging for SAML/security policies:
---- CUT HERE ----
log4j.category.OpenSAML.MessageDecoder=DEBUG
log4j.category.OpenSAML.MessageEncoder=DEBUG
log4j.category.OpenSAML.SecurityPolicyRule=DEBUG
---- CUT HERE ----
--- shibboleth2.xml ---
Removed <InProcess logger="native.logger">-block for IIS / ISAPI, as I don't use IIS/ISAPI.
<Host>-Tag in <RequestMap> changed to:
---- CUT HERE ----
<Host name="idefix.worldtalk.de" applicationId="sp">
<Path name="sp" authType="shibboleth" requireSession="true"/>
</Host>
---- CUT HERE ----
For <ApplicationDefaults>-Tag:
modified the EntityID from "https://sp.example.org/shibboleth" to "https://idefix.worldtalk.de/sp"
---- CUT HERE ----
<SSO entityID="https://idp.example.org/shibboleth"
discoveryProtocol="SAMLDS" discoveryURL="https://ds.example.org/DS/WAYF">
SAML2 SAML1
</SSO>
---- CUT HERE ----
changed to:
---- CUT HERE ----
<SSO entityID="https://idefix.worldtalk.de/idp"
discoveryProtocol="SAMLDS" discoveryURL="https://idefix.worldtalk.de/idp/DS/WAYF">
SAML2 SAML1
</SSO>
---- CUT HERE ----
Set <Errors>-Tag parameter supportContact from "root at localhost" to "webmaster at idefix.worldtalk.de"
Removed comments for MetadataProvider-Example and changed file path to idp-metadata.xml:
---- CUT HERE ----
<!-- Example of locally maintained metadata. -->
<MetadataProvider type="XML" file="C:/opt/shibboleth-idp/metadata/idp-metadata.xml" validate="false" />
---- CUT HERE ----
Set Applications-Override for id "sp" (as defined in <Host>-Tag [see above]) to allow "/sp/Shibboleth.sso" to be used instead of "/Shibboleth.sso", since this host is used for idp and sp at the same time. Else AssertionConsumerServiceURL would be set to "https://idefix.worldtalk.de/Shibboleth.sso" in the <samlp:AuthnRequest>.
---- CUT HERE ----
<ApplicationOverride id="sp">
<Sessions lifetime="28800" timeout="3600" checkAddress="false" handlerURL="https://idefix.worldtalk.de/sp/Shibboleth.sso" />
</ApplicationOverride>
---- CUT HERE ----
--- sp-metadata.xml ---
Modified version of example-metadata.xml with the following adaptions:
* The entityID of <EntityDescriptor>-Tag changed from "https://idp.example.org/shibboleth" to "https://idefix.worldtalk.de/sp". The idp-EntityID doesn't make sense (does it) as we describe the ServiceProvider here.
* Removed the <IDPSSODescriptor>-Tag and <AttributeAuthorityDescriptor>-Tag.
* Adapted Organization/ContactPerson-Tags (changed values and new Tags!)
* Added <SPSSODescriptor>-Tag with Credentials (<ds:KeyName>https://idefix.worldtalk.de/sp</ds:KeyName>), <NameIDFormat xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata">urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat> and some <md:AssertionConsumerService> tags AS:
---- CUT HERE ----
<md:AssertionConsumerService Location="https://idefix.worldtalk.de/sp/Shibboleth.sso/SAML2/POST" index="1"
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"/>
<md:AssertionConsumerService Location="https://idefix.worldtalk.de/sp/Shibboleth.sso/SAML2/POST-SimpleSign" index="2"
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign"/>
<md:AssertionConsumerService Location="https://idefix.worldtalk.de/sp/Shibboleth.sso/SAML2/Artifact" index="3"
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact"/>
<md:AssertionConsumerService Location="https://idefix.worldtalk.de/sp/Shibboleth.sso/SAML2/ECP" index="4"
Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS"/>
<md:AssertionConsumerService Location="https://idefix.worldtalk.de/sp/Shibboleth.sso/SAML/POST" index="5"
Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"/>
<md:AssertionConsumerService Location="https://idefix.worldtalk.de/sp/Shibboleth.sso/SAML/Artifact" index="6"
Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"/>
---- CUT HERE ----
Note: This Metadata was added later. Maybe the <Session>-Tag with handlerURL in the shibboleth2.xml is not needed anymore, as these Location-Definitions may override them.
========================
Index of attached files:
========================
C:\opt\shibboleth-idp\conf
-> attribute-filter.xml
-> attribute-resolver.xml
-> handler.xml
-> internal.xml
-> logging.xml
-> login.config
-> relying-party.xml
-> service.xml
C:\opt\shibboleth-idp\metadata
-> idp-metadata.xml
C:\opt\shibboleth-sp\etc\shibboleth
-> apache22.config
-> native.logger
-> shibd.logger
-> shibboleth2.xml
-> sp-metadata.xml
C:\opt\shibboleth-idp\logs
-> idp-process.log
-> idp-access.log
-> idp-audit.log
C:\opt\shibboleth-sp\var\log\shibboleth
-> native.log
-> shibd.log
-> native_warn.log
-> shibd_warn.log
-> signature.log
-> transaction.log
Anything missing? Let me know... and I'll post it.
NOTE: As this is only a test setup, there is no need to keep stuff (as the selfsigned / autogenerated certificates confidential).)
Environment:
* shibboleth-identityprovider-2.3.5-bin.zip
* shibboleth-sp-2.4.3-win64.msi
Supporting/Additional Software (on same computer):
* Apache Server 2.2.21 (WAMP under Windows)
* Tomcat 1.6 bound via AJP-Proxy-Pass to let Apache do HTTPS
* OpenLDAP 2.4.26 Standalone
was:
Service-Provider: https://idefix.worldtalk.de/sp
Identity-Provider: https://idefix.worldtalk.de/idp
Note: Ports 80/443 are unfortunately protected firefall; URLs can't be accessed from public internet.
OS: Windows 7 (64 bit)
Installation Paths:
* C:/opt/shibboleth-sp/
* C:/opt/shibboleth-idp/
Versions:
* shibboleth-identityprovider-2.3.5-bin.zip (used install.bat; *.msi-Installer had problems, didn't find an excutable or sth. like that)
* shibboleth-sp-2.4.3-win64.msi
Supporting/Additional Software (on same computer):
* Apache Server 2.2.21 (WAMP under Windows)
* Tomcat 1.6 bound via AJP-Proxy-Pass to let Apache do HTTPS
* OpenLDAP 2.4.26 Standalone
---------- APACHE-Config for Service-Provider Alias: /sp -------
Include "C:/opt/shibboleth-sp/etc/shibboleth/apache22.config"
Alias /sp/ "c:/opt/"
<Location /sp>
ShibRequestSetting applicationId sp
Options Indexes FollowSymLinks MultiViews
AllowOverride all
Order allow,deny
Allow from all
</Location>
---------- APACHE-Config for IdP Alias: /idp -------
<Location "/idp">
Order allow,deny
Allow from all
ProxyPass ajp://idefix.worldtalk.de:8009/idp
</Location>
---------- Tomcat AJP-Entry in server.xml ----------------------
[...]
<!-- Define an AJP 1.3 Connector on port 8009 -->
<Connector port="8009" protocol="AJP/1.3" redirectPort="8443" />
[...]
Summary: Response does not contain Status when assertion assigning is enabled but signing credential is improperly configured (was: xmltooling::ValidationException at (https://FQDN/path/Shibboleth.sso/SAML2/POST) StatusResponseType must have Status.)
> Response does not contain Status when assertion assigning is enabled but signing credential is improperly configured
> --------------------------------------------------------------------------------------------------------------------
>
> Key: SIDP-538
> URL: https://issues.shibboleth.net/jira/browse/SIDP-538
> Project: Shibboleth IdP 2 - Java
> Issue Type: Bug
> Components: SAML 2
> Affects Versions: 2.3.5
> Environment: * shibboleth-identityprovider-2.3.5-bin.zip
> * shibboleth-sp-2.4.3-win64.msi
> Supporting/Additional Software (on same computer):
> * Apache Server 2.2.21 (WAMP under Windows)
> * Tomcat 1.6 bound via AJP-Proxy-Pass to let Apache do HTTPS
> * OpenLDAP 2.4.26 Standalone
> Reporter: sdwarfs at idp.protectnetwork.org
> Assignee: Chad La Joie
> Attachments: idp-processing.log.part.txt, shibboleth-idp-bug-report.zip
>
>
> If a relying party configuration contains a reference to a signing credential that is improperly configured the resultant response to the SP does not contains a Status element as required by the SAML specs.
--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira
More information about the commits
mailing list