<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> 
<html xmlns="http://www.w3.org/1999/xhtml"> 
    <head> 
        <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> 
        <meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0" /> <base href="https://issues.shibboleth.net/jira" /> 
        <title>Message Title</title> 
    </head> 
    <body class="jira" style="color: #333; font-family: Arial, sans-serif; font-size: 14px; line-height: 1.429"> 
        <table id="background-table" cellpadding="0" cellspacing="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt; background-color: #f5f5f5; border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt"> 
            <!-- header here --> 
            <tr> 
                <td id="header-pattern-container" style="padding: 0px; border-collapse: collapse; padding: 10px 20px"> 
                    <table id="header-pattern" cellspacing="0" cellpadding="0" border="0" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt"> 
                        <tr> 
                            <td id="header-avatar-image-container" valign="top" style="padding: 0px; border-collapse: collapse; vertical-align: top; width: 32px; padding-right: 8px"> <img id="header-avatar-image" class="image_fix" src="cid:jira-generated-image-avatar-putmanb@shibboleth.net-960f2b78-b778-4bdf-9e00-72efcd9f25a4" height="32" width="32" border="0" style="border-radius: 3px; vertical-align: top" /> 
                            </td> 
                            <td id="header-text-container" valign="middle" style="padding: 0px; border-collapse: collapse; vertical-align: middle; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 1px"> <a class="user-hover" rel="putmanb@shibboleth.net" id="email_putmanb@shibboleth.net" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=putmanb%40shibboleth.net" style="color:#3b73af;; color: #3b73af; text-decoration: none">Brent Putman</a> <strong>commented</strong> on <a href="https://issues.shibboleth.net/jira/browse/SIDP-628" style="color: #3b73af; text-decoration: none"><img src="cid:jira-generated-image-static-bug-50dc5340-20c7-4fbc-aa6d-5b7dd23f03ba" height="16" width="16" border="0" align="absmiddle" alt="Bug" /> SIDP-628</a> 
                            </td> 
                        </tr> 
                    </table> 
                </td> 
            </tr> 
            <tr> 
                <td id="email-content-container" style="padding: 0px; border-collapse: collapse; padding: 0 20px"> 
                    <table id="email-content-table" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt; border-spacing: 0; border-collapse: separate"> 
                        <tr> 
                            <!-- there needs to be content in the cell for it to render in some clients --> 
                            <td class="email-content-rounded-top mobile-expand" style="padding: 0px; border-collapse: collapse; color: #fff; padding: 0 15px 0 16px; height: 15px; background-color: #fff; border-left: 1px solid #ccc; border-top: 1px solid #ccc; border-right: 1px solid #ccc; border-bottom: 0; border-top-right-radius: 5px; border-top-left-radius: 5px; height: 10px; line-height: 10px; padding: 0 15px 0 16px; mso-line-height-rule: exactly">
                                 
                            </td> 
                        </tr> 
                        <tr> 
                            <td class="email-content-main mobile-expand " style="padding: 0px; border-collapse: collapse; border-left: 1px solid #ccc; border-right: 1px solid #ccc; border-top: 0; border-bottom: 0; padding: 0 15px 0 16px; background-color: #fff"> 
                                <table class="page-title-pattern" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt"> 
                                    <tr> 
                                        <td style="vertical-align: top;; padding: 0px; border-collapse: collapse; padding-right: 5px; font-size: 20px; line-height: 30px; mso-line-height-rule: exactly" class="page-title-pattern-header-container"> <span class="page-title-pattern-header" style="font-family: Arial, sans-serif; padding: 0; font-size: 20px; line-height: 30px; mso-text-raise: 2px; mso-line-height-rule: exactly; vertical-align: middle"> <a href="https://issues.shibboleth.net/jira/browse/SIDP-628" style="color: #3b73af; text-decoration: none">Re: Anonymous RP support interacts oddly with signed requests</a> </span> 
                                        </td> 
                                    </tr> 
                                </table> 
                            </td> 
                        </tr> 
                        <tr> 
                            <td id="text-paragraph-pattern-top" class="email-content-main mobile-expand  comment-top-pattern" style="padding: 0px; border-collapse: collapse; border-left: 1px solid #ccc; border-right: 1px solid #ccc; border-top: 0; border-bottom: 0; padding: 0 15px 0 16px; background-color: #fff; border-bottom: none; padding-bottom: 0"> 
                                <table class="text-paragraph-pattern" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 2px"> 
                                    <tr> 
                                        <td class="text-paragraph-pattern-container mobile-resize-text " style="padding: 0px; border-collapse: collapse; padding: 0 0 10px 0"> 
                                            <p style="margin: 10px 0 0 0">Was really puzzled by this, so spent some time tracing down the weird behavior. It's not quite what Scott speculated. I guess it's worse, in that I think it's really a bug in a fundamental component.</p> 
                                            <p style="margin: 10px 0 0 0">The <tt>SecurityPolicy</tt> that will be executed by the encoders (includes things like request signature checks) is determined by a configured <tt>SecurityPolicyResolver</tt>. There's really just one impl <tt>RelyingPartySecurityPolicyResolver</tt>, which uses a <tt>RelyingPartyConfigurationManager</tt> to lookup the relevant <tt>RelyingPartyConfiguration</tt>. And there's just one impl of that, <tt>SAMLMDRelyingPartyConfigurationManager</tt>.</p> 
                                            <p style="margin: 10px 0 0 0">The <tt>SAMLMDRelyingPartyConfigurationManager</tt> does not behave as I at least would expect. Perhaps this has something to do historically with the fuzziness around what we meant by "anonymous relying party". I seem to remember that was debated back in the early days of v2. The current definition AFAIK is that "anonymous" = "don't have metadata for that party (entityID)".</p> 
                                            <p style="margin: 10px 0 0 0">Under that definition, the <tt>SAMLMDRelyingPartyConfigurationManager</tt> is questionable. I think. It's main method here is <tt>RelyingPartyConfiguration getRelyingPartyConfiguration(String relyingPartyEntityID)</tt>. It never returns the anonymous <tt>RelyingPartyConfiguration</tt>, ever. It will only ever return a custom one, or the default one. Despite having a <tt>MetadataProvider</tt> instance, it doesn't use it to eval presence of metadata for the anonymous case. It only uses it to eval metadata groups from entities descriptors. </p> 
                                            <p style="margin: 10px 0 0 0">As a related observation, if you have a custom <tt>RelyingPartyConfiguration</tt> for the entityID, that's the one you get, since it doesn't confirm existence of metadata, etc. That also seems really wrong.</p> 
                                            <p style="margin: 10px 0 0 0">The only reason this isn't broken in other places is that other calling code that uses the RPC manager (pretty much just the abstract SAML profile handler) special cases this and explicitly pulls the anonymous RPC if there's no metadata, by checking it first:</p> 
                                            <div class="code panel" style="border-width: 1px;; border: 1px solid #ccc; background: #f5f5f5; font-size: 12px; line-height: 1.333; font-family: monospace; border: 1px solid #ccc; -moz-border-radius: 3px 3px 3px 3px; border-radius: 3px 3px 3px 3px; margin: 9px 0">
                                                <div class="codeContent panelContent" style="padding: 9px 12px"> 
                                                    <pre class="code-java" style="margin: 10px 0 0 0; max-height: 30em; overflow: auto; white-space: pre-wrap; word-wrap: normal">
    <span class="code-keyword" style="color: #000091">public</span> RelyingPartyConfiguration getRelyingPartyConfiguration(<span class="code-object" style="color: #910091">String</span> relyingPartyId) {
        <span class="code-keyword" style="color: #000091">try</span> {
            <span class="code-keyword" style="color: #000091">if</span> (getMetadataProvider().getEntityDescriptor(relyingPartyId) == <span class="code-keyword" style="color: #000091">null</span>) {
                log.warn(<span class="code-quote" style="color: #009100">"No metadata <span class="code-keyword" style="color: #000091; color: #009100">for</span> relying party {}, treating party as anonymous"</span>, relyingPartyId);
                <span class="code-keyword" style="color: #000091">return</span> getRelyingPartyConfigurationManager().getAnonymousRelyingConfiguration();
            }
        } <span class="code-keyword" style="color: #000091">catch</span> (MetadataProviderException e) {
            log.error(<span class="code-quote" style="color: #009100">"Unable to look up relying party metadata"</span>, e);
            <span class="code-keyword" style="color: #000091">return</span> <span class="code-keyword" style="color: #000091">null</span>;
        }

       <span class="code-comment" style="color: #808080">// This is effectively just the regular call to RPC manager, so will <span class="code-keyword" style="color: #000091; color: #808080">return</span> the custom or <span class="code-keyword" style="color: #000091; color: #808080">default</span> RPC
</span>        <span class="code-keyword" style="color: #000091">return</span> <span class="code-keyword" style="color: #000091">super</span>.getRelyingPartyConfiguration(relyingPartyId);
    }
</pre> 
                                                </div>
                                            </div> 
                                            <p style="margin: 10px 0 0 0">So I don't know for sure which approach was intended to be correct, but we can't have it both ways. Since the <tt>SAMLMDRelyingPartyConfigurationManager</tt> has a <tt>MetadataProvider</tt>, I would personally think it ought to encapsulate the metadata check itself.</p> 
                                            <p style="margin: 10px 0 0 0">Anyway, the security policy resolver doesn't do that. So it always either gets a custom RPC (if it exists) or the default RPC. In Scott's case it was getting the default one. And then it looks for the specific profile-specific <tt>ProfileConfiguration</tt> on the RPC. If there is no profile config for the profileId, then you get no security policy, so nothing runs. So that's what's happening when you comment out the <tt>saml:SAML2SSOProfile</tt> config for the default relying party and the "anonymous" signed request succeeds. Same for when it fails when the default RPC profile config is present.</p> 
                                            <p style="margin: 10px 0 0 0">So, debating whether I should risk fixing this by changing the <tt>SAMLMDRelyingPartyConfigurationManager</tt> to do the metadata check. Seems like a big change. Opinions? Anyone have any historical knowledge about this?</p> 
                                            <p style="margin: 10px 0 0 0">The other route to fix would be to have the <tt>RelyingPartySecurityPolicyResolver</tt> do the metadata check. But that would be problematic b/c it currently doesn't get injected with a <tt>MetadataProvider</tt>.</p> 
                                        </td> 
                                    </tr> 
                                </table> 
                            </td> 
                        </tr> 
                        <tr> 
                            <td class="email-content-main mobile-expand " style="padding: 0px; border-collapse: collapse; border-left: 1px solid #ccc; border-right: 1px solid #ccc; border-top: 0; border-bottom: 0; padding: 0 15px 0 16px; background-color: #fff"> 
                                <table id="actions-pattern" cellspacing="0" cellpadding="0" border="0" width="100%" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 1px"> 
                                    <tr> 
                                        <td id="actions-pattern-container" valign="middle" style="padding: 0px; border-collapse: collapse; padding: 10px 0 10px 24px; vertical-align: middle; padding-left: 0"> 
                                            <table align="left" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt"> 
                                                <tr> 
                                                    <td class="actions-pattern-action-icon-container" style="padding: 0px; border-collapse: collapse; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 0px; vertical-align: middle"> <a href="https://issues.shibboleth.net/jira/browse/SIDP-628#add-comment" target="_blank" title="Add Comment" style="color: #3b73af; text-decoration: none"> <img class="actions-pattern-action-icon-image" src="cid:jira-generated-image-static-comment-icon-0ce8a2f3-5afa-4a97-9a18-7c32be679c9f" alt="Add Comment" title="Add Comment" height="16" width="16" border="0" style="vertical-align: middle" /> </a> 
                                                    </td> 
                                                    <td class="actions-pattern-action-text-container" style="padding: 0px; border-collapse: collapse; font-family: Arial, sans-serif; font-size: 14px; line-height: 20px; mso-line-height-rule: exactly; mso-text-raise: 4px; padding-left: 5px"> <a href="https://issues.shibboleth.net/jira/browse/SIDP-628#add-comment" target="_blank" title="Add Comment" style="color: #3b73af; text-decoration: none">Add Comment</a> 
                                                    </td> 
                                                </tr> 
                                            </table> 
                                        </td> 
                                    </tr> 
                                </table> 
                            </td> 
                        </tr> 
                        <!-- there needs to be content in the cell for it to render in some clients --> 
                        <tr> 
                            <td class="email-content-rounded-bottom mobile-expand" style="padding: 0px; border-collapse: collapse; color: #fff; padding: 0 15px 0 16px; height: 5px; line-height: 5px; background-color: #fff; border-top: 0; border-left: 1px solid #ccc; border-bottom: 1px solid #ccc; border-right: 1px solid #ccc; border-bottom-right-radius: 5px; border-bottom-left-radius: 5px; mso-line-height-rule: exactly">
                                 
                            </td> 
                        </tr> 
                    </table> 
                </td> 
            </tr> 
            <tr> 
                <td id="footer-pattern" style="padding: 0px; border-collapse: collapse; padding: 12px 20px"> 
                    <table id="footer-pattern-container" cellspacing="0" cellpadding="0" border="0" style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt"> 
                        <tr> 
                            <td id="footer-pattern-text" class="mobile-resize-text" width="100%" style="padding: 0px; border-collapse: collapse; color: #999; font-size: 12px; line-height: 18px; font-family: Arial, sans-serif; mso-line-height-rule: exactly; mso-text-raise: 2px">
                                 This message was sent by Atlassian JIRA <span id="footer-build-information">(v6.4.1#64016-<span title="5d7581434f35c063b7031942e62ed4d72a97fa9c" data-commit-id="5d7581434f35c063b7031942e62ed4d72a97fa9c}">sha1:5d75814</span>)</span> 
                            </td> 
                            <td id="footer-pattern-logo-desktop-container" valign="top" style="padding: 0px; border-collapse: collapse; padding-left: 20px; vertical-align: top"> 
                                <table style="border-collapse: collapse; mso-table-lspace: 0pt; mso-table-rspace: 0pt"> 
                                    <tr> 
                                        <td id="footer-pattern-logo-desktop-padding" style="padding: 0px; border-collapse: collapse; padding-top: 3px"> <img id="footer-pattern-logo-desktop" src="cid:jira-generated-image-static-footer-desktop-logo-edb788e3-992e-495f-9373-8c8cd6f83e4e" alt="Atlassian logo" title="Atlassian logo" width="169" height="36" class="image_fix" /> 
                                        </td> 
                                    </tr> 
                                </table> 
                            </td> 
                        </tr> 
                    </table> 
                </td> 
            </tr> 
        </table>   
    </body>
</html>