AuthNRequest profile signature validation failure w/ ECP HTTPSOAP11Decoder

Misagh Moayyed mmoayyed at unicon.net
Thu Dec 15 14:37:08 EST 2016


I am working on/troubleshooting a piece of ECP-related code where after
having decoded the SOAP request via the HTTPSOAP11Decoder, signature
validation of the final authentication request that is extracted from the
context fails. This is specifically reported back via
SAMLSignatureProfileValidator with the below error message:

 

<Apache xmlsec IdResolver could not resolve the Element for id reference:
_dea44c5bb9ee8778f82c946f82948065>

 

This page [1] relevant for OSTwo describes a technique to get around this
issue, but I am not quite sure:

 

-         How that might apply to OSThree

-         How that might apply to HTTPSOAP11Decoder 

 

If this helps, the test is done via the ECP script provided by CILogon
against an IdP that is not yet an InCommon member. I understand membership
is a requirement for the test to pass; I am wondering if the above has
anything to do with that or it's something entirely different. 

 

What might I be missing? 

 

--Misagh

 

[1]
https://wiki.shibboleth.net/confluence/display/OpenSAML/OSTwoUserManJavaXM
LEncryption#OSTwoUserManJavaXMLEncryption-CreateaSAML2Decrypter 

 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20161215/c3ed7317/attachment.html>


More information about the dev mailing list