Exception when creating the signature using OpenSAML lib
Yaowen Tu
yaowen.tu at gmail.com
Wed Oct 31 19:53:59 EDT 2012
What I am passing into the valida() is a Signature, and there is only one
signature under SPSSODescriptor, so that cannot be wrong, is it?
Another question, can you take a look at the metadata that I just sent
again? The structure is like:
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
entityID="www.localhost.com">
<md:SPSSODescriptor AuthnRequestsSigned="false"
WantAssertionsSigned="false" errorURL="www.localhost.com/SAML/ERROR"
protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
........
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>.......</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</ds:Signature>
<md:KeyDescriptor>
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>........</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
</md:SPSSODescriptor>
</md:EntityDescriptor>
There are two <KeyInfo>, I am using the same public key and private key to
generate it, so does is matter to use which one to verify the signature? I
think no, but I just want to rule out this case.
Yaowen
On Wed, Oct 31, 2012 at 4:30 PM, Brent Putman <putmanb at georgetown.edu>wrote:
>
> On 10/31/12 7:23 PM, Yaowen Tu wrote:
>
> 1. I am not sure how to check if I am passing EntityDescriptor or
> SPSSODescriptor. In the code sample of the wiki:
>
> Credential verificationCredential =
> getVerificationCredential(response);
> SignatureValidator sigValidator = new
> SignatureValidator(verificationCredential);
> The SignatureValidator only need a credential. I think as long as I get
> the credential under SPSSODescriptor, that should be fine. Is that
> correct?
>
>
>
> I meant what you are passing to the validate(...) method. Although I
> forgot that your error is actually on the SAMLSignatureProfileValidator, so
> it's whatever you are passing to the validate(...) method of that.
>
> You error is odd though, b/c you have a non-null Signature which is saying
> it doesn't contain the Apache XMLSignature object. So something that you
> are doing is off.
>
>
>
> --
> To unsubscribe from this list send an email to
> dev-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20121031/b127ab1d/attachment-0001.html
More information about the dev
mailing list