In this case, we do control both ends and XPath is there if we need it. This is for securing messages between PEP, PDP, Policy Service and Attribute Service in an authorization management system, all of which we control. The goal is a SAMLProcessor library that the four services will all use.<div>

<br></div><div>I&#39;d rather not have this restriction, of course, and that the solution be fully interoperable. But the signing spec is so over to the top in this case that I&#39;d be happy to get something that works at all. The spec is far beyond what any impl I know of will support.</div>

<div><br></div><div>Any suggestions on where to start?<br><br><div class="gmail_quote">On Mon, Oct 24, 2011 at 8:59 PM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>&gt;</span> wrote:<br>

<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;"><div class="im">On 10/24/11 8:51 PM, &quot;Brad Cox&quot; &lt;<a href="mailto:bradjcox@gmail.com">bradjcox@gmail.com</a>&gt; wrote:<br>


<br>
&gt;I&#39;m trying to meet stringent DOD security requirements that require that<br>
&gt;several elements in the headers be signed. Actually the body too, but<br>
&gt;presumably just the payload but am not sure, so I&#39;ve left body signing<br>
&gt;aside for now). For example, the Timestamp, MessageID, and SAML Assertion<br>
&gt;should all be signed.<br>
<br>
</div>It&#39;s extremely complex to do that in a way that isn&#39;t vulnerable to<br>
wrapping attacks. You need XPath or a lot of control over the application<br>
on both ends.<br>
<div class="im"><br>
&gt;I have Assertion signing working now, but am stumped on Timestamp and<br>
&gt;MessageID since these come from xmltooling and don&#39;t comply with<br>
&gt;SignableSAMLObject.<br>
<br>
</div>I don&#39;t believe there is any built-in support for WS-Security message<br>
signatures. We haven&#39;t ever analyzed how it would be handled or how to<br>
make it safe.<br>
<br>
The safest thing is to sign the whole message. A whole document reference<br>
isn&#39;t usable with SOAP intermediaries, but it is secure.<br>
<br>
-- Scott<br>
<font color="#888888"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:dev-unsubscribe@shibboleth.net">dev-unsubscribe@shibboleth.net</a><br>
</font></blockquote></div><br><br clear="all"><div><br></div>-- <br>Cell: 703-594-1883<br>Blog: <a href="http://bradjcox.blogspot.com">http://bradjcox.blogspot.com</a><br>Web: <a href="http://virtualschool.edu">http://virtualschool.edu</a><br>

Manassas VA 20111<br><br>
</div>