<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html;
      charset=windows-1252">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <p><br>
    </p>
    <br>
    <div class="moz-cite-prefix">On 4/28/17 9:42 AM, Locatelli da Silva,
      Thiago wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:D528BBC6.D985%25thiago.locatellidasilva@transamerica.com">
      <meta http-equiv="Content-Type" content="text/html;
        charset=windows-1252">
      <div><br>
        <div style="color: rgb(0, 0, 0); font-family: Calibri,
          sans-serif; font-size: 14px;">
          I found this old discussion from the list, <a
href="http://shibboleth.1660669.n2.nabble.com/Error-on-signing-outbound-SAML-message-td7621620.html"
            moz-do-not-send="true">http://shibboleth.1660669.n2.nabble.com/Error-on-signing-outbound-SAML-message-td7621620.html</a>,
          in which the user is facing the same issue I am facing, even
          though I am programmatically signing and encrypting, the
          resulting exception is the same. At the end of the discussion
          Scott says something about xmlsec 2.x, and looking at my maven
          dependencies I see xmlsec 1.5.7, which is coming from this
          dependency</div>
        <div style="color: rgb(0, 0, 0); font-family: Calibri,
          sans-serif; font-size: 14px;">
          <br>
        </div>
        <div>
          <p style="color: rgb(78, 145, 146); font-family: Monaco;
            font-size: 11px; margin: 0px; line-height: normal;">
            <span style="color: #000000"><span class="Apple-tab-span" style="white-space:pre"></span></span><span
              style="color: #009193"><</span>dependency<span
              style="color: #009193">></span></p>
          <p style="color: rgb(0, 0, 0); font-family: Monaco; font-size:
            11px; margin: 0px; line-height: normal;">
            <span class="Apple-tab-span" style="white-space:pre"></span><span
              style="color: #009193"><</span><span style="color:
              #4e9192">groupId</span><span style="color: #009193">></span>org.opensaml<span
              style="color: #009193"></</span><span style="color:
              #4e9192">groupId</span><span style="color: #009193">></span></p>
          <p style="color: rgb(78, 145, 146); font-family: Monaco;
            font-size: 11px; margin: 0px; line-height: normal;">
            <span style="color: #000000"><span class="Apple-tab-span" style="white-space:pre"></span></span><span
              style="color: #009193"><</span>artifactId<span
              style="color: #009193">></span><span
              style="text-decoration: underline ; color: #000000">xmltooling</span><span
              style="color: #009193"></</span>artifactId<span
              style="color: #009193">></span></p>
          <p style="color: rgb(78, 145, 146); font-family: Monaco;
            font-size: 11px; margin: 0px; line-height: normal;">
            <span style="color: #000000"><span class="Apple-tab-span" style="white-space:pre"></span></span><span
              style="color: #009193"><</span>version<span
              style="color: #009193">></span><span style="color:
              #000000">1.4.4</span><span style="color: #009193"></</span>version<span
              style="color: #009193">></span></p>
          <p style="color: rgb(78, 145, 146); font-family: Monaco;
            font-size: 11px; margin: 0px; line-height: normal;">
            <span style="color: #000000"><span class="Apple-tab-span" style="white-space:pre"></span></span><span
              style="color: #009193"></</span>dependency<span
              style="color: #009193">></span></p>
          <p style="color: rgb(78, 145, 146); font-family: Monaco;
            font-size: 11px; margin: 0px; line-height: normal;">
            <span style="color: #009193"><br>
            </span></p>
          <p style="margin: 0px; line-height: normal;"><font
              face="Calibri">I added an exclusion to this dependency so
              Maven could use the version declared by
              opensaml-security-api, which is xmlsec 2.0.5. </font></p>
        </div>
      </div>
    </blockquote>
    <br>
    Ah. Well, you shouldn't have that xmltooling dependency at all. 
    That's OpenSAML v2.  If you're doing OpenSAML v3 (and you should,
    since v2 is dead and EOL), then you can't mix them.  All of the v3
    dependencies have artifactIds like opensaml-*.  You absolutely
    should not have xmltooling, openws or opensaml in your declared or
    transitive dependencies.  That will definitely cause problems.  I
    didn't even think to ask about something like that before.<br>
    <br>
    <br>
    <blockquote type="cite"
      cite="mid:D528BBC6.D985%25thiago.locatellidasilva@transamerica.com">
      <div>
        <div>
          <p style="margin: 0px; line-height: normal;"><font
              face="Calibri">By doing this my problem was fixed. I am
              now able to encrypt my signed assertions and marshall
              them.</font></p>
        </div>
      </div>
    </blockquote>
    <br>
    Ok, that makes sense.  The older Santuario (xmlsec) lib had a bug
    fixed in the newer 2.x series.<br>
    <br>
    <blockquote type="cite"
      cite="mid:D528BBC6.D985%25thiago.locatellidasilva@transamerica.com">
      <div>
        <div>
          <p style="margin: 0px; line-height: normal;"><font
              face="Calibri"><br>
            </font></p>
          <p style="margin: 0px; line-height: normal;"><font
              face="Calibri">I am only running into a validation issue
              with my response, but I think the way I am doing is not
              valid anymore for OpenSAML V3.</font></p>
          <p style="margin: 0px; line-height: normal;"><font
              face="Calibri"><br>
            </font></p>
          <p style="margin: 0px; font-size: 11px; line-height: normal;
            font-family: Monaco;">
                    <span style="color: #931a68">for</span>(String <span
              style="color: #7e504f">
              suiteId</span> : Arrays.asList(</p>
          <p style="margin: 0px; font-size: 11px; line-height: normal;
            font-family: Monaco; color: rgb(57, 51, 255);">
            <span style="color: #000000">                    </span>"saml2-core-schema-validator"<span
              style="color: #000000">,</span></p>
          <p style="margin: 0px; font-size: 11px; line-height: normal;
            font-family: Monaco; color: rgb(57, 51, 255);">
            <span style="color: #000000">                    </span>"saml2-core-spec-validator"<span
              style="color: #000000">,</span></p>
          <p style="margin: 0px; font-size: 11px; line-height: normal;
            font-family: Monaco; color: rgb(57, 51, 255);">
            <span style="color: #000000">                    </span>"saml2-metadata-schema-validator"<span
              style="color: #000000">, </span></p>
          <p style="margin: 0px; font-size: 11px; line-height: normal;
            font-family: Monaco; color: rgb(57, 51, 255);">
            <span style="color: #000000">                    </span>"saml2-metadata-spec-validator"<span
              style="color: #000000">)) {</span></p>
          <p style="margin: 0px; font-size: 11px; line-height: normal;
            font-family: Monaco;">
                        ValidatorSuite <span style="color: #7e504f">validatorSuide</span>
            = <span style="color: #931a68">
              new</span> ValidatorSuite(<span style="color: #7e504f">suiteId</span>);</p>
          <p style="margin: 0px; font-size: 11px; line-height: normal;
            font-family: Monaco;">
                        <span style="color: #7e504f">validatorSuide</span>.validate((XMLObject)
            <span style="color: #7e504f">response</span>.getDOM());</p>
          <p style="margin: 0px; font-size: 11px; line-height: normal;
            font-family: Monaco;">
                    }</p>
          <p style="margin: 0px; font-size: 11px; line-height: normal;
            font-family: Monaco;">
            <br>
          </p>
          <p style="margin: 0px; font-size: 11px; line-height: normal;
            font-family: Monaco;">
            java.lang.ClassCastException:
            com.sun.org.apache.xerces.internal.dom.ElementNSImpl cannot
            be cast to org.opensaml.xml.XMLObject</p>
          <br>
        </div>
      </div>
    </blockquote>
    <br>
    The ValidatorSuite is from v2, so that's not going to work once you
    remove the xmltooling dependency.  We removed all the XMLObject
    Validator and ValidatorSuite stuff from v3, as it wasn't really used
    and wasn't maintained.<br>
    <br>
    In v3, if you want to validate the XML at parsing time against the
    SAML schemas, we have a convenience class
    org.opensaml.saml.common.xml.SAMLSchemaBuilder for building a
    javax.xml.validation.Schema instance.  Then you configure that on
    your ParserPool instance (e.g.
    net.shibboleth.utilities.java.support.xml.BasicParserPool).  This is
    the easiest way to do JAXP-level schema validation.<br>
    <br>
    <br>
  </body>
</html>