Exception when creating the signature using OpenSAML lib

Yaowen Tu yaowen.tu at gmail.com
Wed Oct 31 19:53:59 EDT 2012


What I am passing into the valida() is a Signature, and there is only one
signature under SPSSODescriptor, so that cannot be wrong, is it?

Another question, can you take a look at the metadata that I just sent
again? The structure is like:

<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
entityID="www.localhost.com">
    <md:SPSSODescriptor AuthnRequestsSigned="false"
WantAssertionsSigned="false" errorURL="www.localhost.com/SAML/ERROR"
protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
        <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
            ........
            <ds:KeyInfo>
                <ds:X509Data>
                    <ds:X509Certificate>.......</ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </ds:Signature>
        <md:KeyDescriptor>
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <ds:X509Data>
                    <ds:X509Certificate>........</ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </md:KeyDescriptor>
     </md:SPSSODescriptor>
</md:EntityDescriptor>

There are two <KeyInfo>, I am using the same public key and private key to
generate it, so does is matter to use which one to verify the signature? I
think no, but I just want to rule out this case.

Yaowen


On Wed, Oct 31, 2012 at 4:30 PM, Brent Putman <putmanb at georgetown.edu>wrote:

>
> On 10/31/12 7:23 PM, Yaowen Tu wrote:
>
> 1. I am not sure how to check if I am passing EntityDescriptor or
> SPSSODescriptor. In the code sample of the wiki:
>
>        Credential verificationCredential =
> getVerificationCredential(response);
>        SignatureValidator sigValidator = new
> SignatureValidator(verificationCredential);
>   The SignatureValidator only need a credential. I think as long as I get
> the credential under SPSSODescriptor, that should be fine. Is that
> correct?
>
>
>
> I meant what you are passing to the validate(...) method.  Although I
> forgot that your error is actually on the SAMLSignatureProfileValidator, so
> it's whatever you are passing to the validate(...) method of that.
>
> You error is odd though, b/c you have a non-null Signature which is saying
> it doesn't contain the Apache XMLSignature object.  So something that you
> are doing is off.
>
>
>
> --
> To unsubscribe from this list send an email to
> dev-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20121031/b127ab1d/attachment-0001.html 


More information about the dev mailing list