<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:"Courier New \;color\:black";
panose-1:0 0 0 0 0 0 0 0 0 0;}
@font-face
{font-family:"Courier New \;color\:\#7F0055";
panose-1:0 0 0 0 0 0 0 0 0 0;}
@font-face
{font-family:"Courier New \;color\:\#0000C0";
panose-1:0 0 0 0 0 0 0 0 0 0;}
@font-face
{font-family:"Courier New \;color\:\#2A00FF";
panose-1:0 0 0 0 0 0 0 0 0 0;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;
color:black;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:#954F72;
text-decoration:underline;}
p.msonormal0, li.msonormal0, div.msonormal0
{mso-style-name:msonormal;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;
color:black;}
span.EmailStyle19
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.EmailStyle20
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body bgcolor="white" lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal"><span style="color:windowtext">Hi Brent,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:windowtext"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:windowtext">Thanks so very much, I will follow up on your suggestions.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:windowtext"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:windowtext">Ike<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:windowtext"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="color:windowtext">From:</span></b><span style="color:windowtext"> dev [mailto:dev-bounces@shibboleth.net]
<b>On Behalf Of </b>Brent Putman<br>
<b>Sent:</b> Monday, January 7, 2019 5:21 PM<br>
<b>To:</b> dev@shibboleth.net<br>
<b>Subject:</b> Re: Issue validating SAML signature<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal" style="line-height:12.0pt;background:#FDFEFE"><span style="font-size:10.0pt;font-family:"Arial",sans-serif">** This mail has been sent from an external source **
<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p><o:p> </o:p></p>
<div>
<p class="MsoNormal">On 1/5/19 11:49 PM, Eze Ikonne wrote:<o:p></o:p></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal">Hi all,<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal">I am not sure if this the right forum for the issue that I having,<o:p></o:p></p>
</blockquote>
<p><o:p> </o:p></p>
<p>Yes, this list (the Shibboleth developer's list) is the right place.<o:p></o:p></p>
<p><o:p> </o:p></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal">I have upgraded to opensaml3 downloaded from shibboleth. My application is a service provider and I am trying to validate Saml Response from an IDP that has a signed Assertion.
<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif">
<span style="background:silver;mso-highlight:silver">BasicX509Credential</span> cred =
</span><b><span style="font-size:10.0pt;font-family:"Courier New ;color:#7F0055",serif">new</span></b><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif">
<span style="background:silver;mso-highlight:silver">BasicX509Credential</span>();</span><o:p></o:p></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif"> cred.setEntityCertificate(matchedCert);</span><o:p></o:p></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif"> cred.setPublicKey(matchedCert.getPublicKey());</span><o:p></o:p></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif"> cred.setCRLs(</span><b><span style="font-size:10.0pt;font-family:"Courier New ;color:#7F0055",serif">null</span></b><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif">);
</span><o:p></o:p></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif">
</span><o:p></o:p></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif"> </span><b><span style="font-size:10.0pt;font-family:"Courier New ;color:#7F0055",serif">try</span></b><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif">
{</span><o:p></o:p></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif"> SignatureValidator signatureValidator =
</span><b><span style="font-size:10.0pt;font-family:"Courier New ;color:#7F0055",serif">new</span></b><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif"> SignatureValidator(cred);</span><o:p></o:p></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif"> signatureValidator.validate(sig);</span><o:p></o:p></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif">
</span><b><span style="font-size:10.0pt;font-family:"Courier New ;color:#7F0055",serif">return</span></b><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif">
</span><b><span style="font-size:10.0pt;font-family:"Courier New ;color:#7F0055",serif">true</span></b><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif">;</span><o:p></o:p></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif"> }
</span><b><span style="font-size:10.0pt;font-family:"Courier New ;color:#7F0055",serif">catch</span></b><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif"> (ValidationException ex) {</span><o:p></o:p></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif"> ex.printStackTrace();</span><o:p></o:p></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif"> System.</span><i><span style="font-size:10.0pt;font-family:"Courier New ;color:#0000C0",serif">out</span></i><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif">.println(</span><span style="font-size:10.0pt;font-family:"Courier New ;color:#2A00FF",serif">"********
signature validation failed"</span><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif">);</span><o:p></o:p></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif"> }</span><o:p></o:p></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:10.0pt;font-family:"Courier New ;color:black",serif">
</span><o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
</blockquote>
<p><o:p> </o:p></p>
<p>I don't see anything fundamentally wrong with that code. It should work, for valid signature and credential inputs.<o:p></o:p></p>
<p>(For the record, there are other better ways using higher-level components to do signature validation for real-world use cases, using TrustEngine(s) and credentials resolved from SAML metadata. Those are pretty much mandatory if you have to deal with multiple
SAML peers. But none of that is relevant to your problem.)<o:p></o:p></p>
<p><o:p> </o:p></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal">But I keep getting the following stacktrace …<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal">2019-01-03 21:21:03,857 [Service-0] DEBUG systemout - org.opensaml.xml.validation.ValidationException: Signature did not validate against the credential's key<o:p></o:p></p>
<p class="MsoNormal">2019-01-03 21:21:03,858 [Service-0] DEBUG systemout - at org.opensaml.xml.signature.SignatureValidator.validate(SignatureValidator.java:78)<o:p></o:p></p>
<p class="MsoNormal">2019-01-03 21:21:03,858 [Service-0] DEBUG systemout - at com.sterlingcommerce.component.token.saml.SimpleSamlTokenManager.verifySAMLSignature(SimpleSamlTokenManager.java:482)<o:p></o:p></p>
<p class="MsoNormal">2019-01-03 21:21:03,858 [Service-0] DEBUG systemout - at com.sterlingcommerce.component.token.saml.SimpleSamlTokenManager.validateAssertionSignature(SimpleSamlTokenManager.java:370)<o:p></o:p></p>
<p class="MsoNormal">2019-01-03 21:21:03,859 [Service-0] DEBUG systemout - at com.sterlingcommerce.component.token.saml.SimpleSamlTokenManager.validateSignature(SimpleSamlTokenManager.java:333)<o:p></o:p></p>
<p class="MsoNormal">2019-01-03 21:21:03,859 [Service-0] DEBUG systemout - at com.sterlingcommerce.component.token.saml.SimpleSamlTokenManager.verifySamlAuthenticationResponse(SimpleSamlTokenManager.java:300)<o:p></o:p></p>
<p class="MsoNormal">2019-01-03 21:21:03,859 [Service-0] DEBUG systemout - at com.sterlingcommerce.component.sso.impl.SingleSignonServiceImpl.samlTokenVerify(SingleSignonServiceImpl.java:749)<o:p></o:p></p>
<p class="MsoNormal">2019-01-03 21:21:03,859 [Service-0] DEBUG systemout - at com.sterlingcommerce.component.sso.impl.SingleSignonServiceImpl$RequestListener$8.run(SingleSignonServiceImpl.java:1790)<o:p></o:p></p>
<p class="MsoNormal">2019-01-03 21:21:03,860 [Service-0] DEBUG systemout - at EDU.oswego.cs.dl.util.concurrent.PooledExecutor$Worker.run(PooledExecutor.java:727)<o:p></o:p></p>
<p class="MsoNormal">2019-01-03 21:21:03,860 [Service-0] DEBUG systemout - at java.lang.Thread.run(Thread.java:811)<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal">I would appreciate it if anyone could point me to the right solution or maybe point out what my code is doing wrong. I have tried to run sample codes around this issue, but I have still to get any of the signature validation to be successful.
Any help or suggestions would be greatly appreciated.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</blockquote>
<p><o:p> </o:p></p>
<p>Your code itself isn't wrong. So the most likely explanations are: 1) the certificate/public key with which you're trying to validate is not the correct one 2) you're corrupting the XML you receive before validating it 3) the signer (IdP) has a bug and
is generating an invalid signature. Unless the IdP is somebody's one-off and isn't a known good XML signature implementation, given our past experience #1 is far and away the most likely issue (like 90%+ probability). If you've already double-checked it,
then triple- and quadruple-check it. Most people swear that is not the problem, up to the moment they figure out that it is...<o:p></o:p></p>
<p>You may find this page in our wiki helpful. It's still homed in the OpenSAML v2 section, but ignore the warning about the old version. All the info there is still relevant to v3.<o:p></o:p></p>
<p><a href="https://wiki.shibboleth.net/confluence/display/OpenSAML/OSTwoUserManSigErrors">https://wiki.shibboleth.net/confluence/display/OpenSAML/OSTwoUserManSigErrors</a><o:p></o:p></p>
<p><o:p> </o:p></p>
<p>Thanks,<br>
Brent<o:p></o:p></p>
<p><o:p> </o:p></p>
</div>
</div>
=====================================================<br>
<font face="Arial" color="Black" size="2">Please refer to http://www.aricent.com/email-disclaimer<br>
for important disclosures regarding this electronic communication.<br>
</font>=====================================================<br>
</body>
</html>