<html><head></head><body><div class="ydpd17dc26dyahoo-style-wrap" style="font-family:Helvetica Neue, Helvetica, Arial, sans-serif;font-size:16px;"><div></div>
<div>Hi,</div><div><br></div><div>I was able to get it to work now. I had to add back (uncomment) the lines where the conditions and condition were created.</div><div><br></div><div>Thanks!</div><div><br></div><div>Jim</div><div><br></div><div>P.S. BTW, and yes, I will look into moving to a newer version of OpenSAML, but I ran into some problems trying to use the newer one before, but I wanted to try to get something working first.</div><div><br></div><div><br></div><div><br></div><div><br></div>
</div><div id="ydp4ca3d730yahoo_quoted_1222857273" class="ydp4ca3d730yahoo_quoted">
<div style="font-family:'Helvetica Neue', Helvetica, Arial, sans-serif;font-size:13px;color:#26282a;">
<div>
On Friday, February 15, 2019, 3:42:11 PM EST, o haya <ohaya@yahoo.com> wrote:
</div>
<div><br></div>
<div><br></div>
<div><div dir="ltr">Hi,<br></div><div dir="ltr"><br></div><div dir="ltr">Thanks, maybe I am mis-reading what you were suggesting (the formatting on Yahoo email may be bad), but if I remove the parts that you mentioned:<br></div><div dir="ltr"><br></div><div dir="ltr">====================================================================================================================================<br></div><div dir="ltr"><br></div><div dir="ltr">><br></div><div dir="ltr">> The part of my code that is building that is:<br></div><div dir="ltr">><br></div><div dir="ltr">> SAMLObjectBuilder audienceRestrictionConditionBuilder = (SAMLObjectBuilder) SAMLWriter.getSAMLBuilder().getBuilder(AudienceRestriction.DEFAULT_ELEMENT_NAME);<br></div><div dir="ltr">> Condition condition = (Condition) audienceRestrictionConditionBuilder.buildObject();<br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr">Here you are building the empty one ...<br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr">><br></div><div dir="ltr">> SAMLObjectBuilder conditionsBuilder = (SAMLObjectBuilder) SAMLWriter.getSAMLBuilder().getBuilder(Conditions.DEFAULT_ELEMENT_NAME);<br></div><div dir="ltr">> Conditions conditions = (Conditions) conditionsBuilder.buildObject();<br></div><div dir="ltr">> conditions.getConditions().add(condition);<br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr">... and here you are adding the empty one to the Conditions. You don't need to do this, or the above.<br></div><div dir="ltr"><br></div><div dir="ltr">====================================================================================================================================<br></div><div dir="ltr"><br></div><div dir="ltr">both "conditions" and "condition" are undefined?<br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr">Like I said, I may be mis-reading/misunderstanding what you were suggesting, but I think that this is what I got when I commented out the lines you mentioned:<br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr"> conditions.setNotBefore(now);<br></div><div dir="ltr"> conditions.setNotOnOrAfter(now2);<br></div><div dir="ltr"> <br></div><div dir="ltr"> SAMLObjectBuilder audienceRestrictionnBuilder = null;<br></div><div dir="ltr"> SAMLObjectBuilder audienceBuilder = null;<br></div><div dir="ltr"> audienceRestrictionnBuilder = (SAMLObjectBuilder) getSAMLBuilder().getBuilder(AudienceRestriction.DEFAULT_ELEMENT_NAME);<br></div><div dir="ltr"> audienceBuilder = (SAMLObjectBuilder) getSAMLBuilder().getBuilder(Audience.DEFAULT_ELEMENT_NAME);<br></div><div dir="ltr"> String audienceURI = "<a href="https://sandboxdtm01.xxx.dev/fed" rel="nofollow" target="_blank">https://sandboxdtm01.xxx.dev/fed</a>";<br></div><div dir="ltr"> <br></div><div dir="ltr"> // Create the audience<br></div><div dir="ltr"> Audience audience = (Audience) audienceBuilder.buildObject();<br></div><div dir="ltr"> audience.setAudienceURI(audienceURI);<br></div><div dir="ltr"><br></div><div dir="ltr"> // Create the audience restriction<br></div><div dir="ltr"> AudienceRestriction audienceRestriction = (AudienceRestriction) audienceRestrictionnBuilder.buildObject();<br></div><div dir="ltr"><br></div><div dir="ltr"> // add in the audience<br></div><div dir="ltr"> audienceRestriction.getAudiences().add(audience);<br></div><div dir="ltr"> conditions.getAudienceRestrictions().add(audienceRestriction);<br></div><div dir="ltr"> <br></div><div dir="ltr"><br></div><div dir="ltr">Jim<br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr">--------------------------------------------<br></div><div dir="ltr">On Fri, 2/15/19, Brent Putman <<a href="mailto:putmanb@georgetown.edu" rel="nofollow" target="_blank">putmanb@georgetown.edu</a>> wrote:<br></div><div dir="ltr"><br></div><div dir="ltr"> Subject: Re: New here - OpenSAML and conditions/audience restrictions problem<br></div><div dir="ltr"> To: <a href="mailto:dev@shibboleth.net" rel="nofollow" target="_blank">dev@shibboleth.net</a><br></div><div dir="ltr"> Date: Friday, February 15, 2019, 3:10 PM<br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> On 2/15/19<br></div><div dir="ltr"> 2:55 PM, o haya wrote:<br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> I am just getting started with OpenSAML, and using Java and<br></div><div dir="ltr"> OpenSAML 2.6.6 <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> Don't. Use the latest 3.x OpenSAML 2.x has<br></div><div dir="ltr"> been End Of Life for<br></div><div dir="ltr"> over 2.5 years at this point. See the announcement and<br></div><div dir="ltr"> links here:<br></div><div dir="ltr"> <a href="https://wiki.shibboleth.net/confluence/display/OpenSAML/Home" rel="nofollow" target="_blank">https://wiki.shibboleth.net/confluence/display/OpenSAML/Home</a><br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> There's absolutely no reason to start a new<br></div><div dir="ltr"> project with 2.x,<br></div><div dir="ltr"> and it is indeed a bad idea due to security<br></div><div dir="ltr"> vulnerabilities which<br></div><div dir="ltr"> have been fixed since it went EOL.<br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> I have code now that, in fact does add the<br></div><div dir="ltr"> <Conditions>, but I am ending up with two<br></div><div dir="ltr"> <saml:AudienceRestriction> elements. <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> Yes, you are adding it twice.<br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> whereas I think that what I want is (i.e., just the one<br></div><div dir="ltr"> saml2:AudienceRestriction with the URI):<br></div><div dir="ltr"> <br></div><div dir="ltr"> <saml2:Conditions<br></div><div dir="ltr"> NotOnOrAfter="2019-02-15T19:27:56.620Z"<br></div><div dir="ltr"> NotBefore="2019-02-15T19:27:56.603Z"><br></div><div dir="ltr"> <saml2:AudienceRestriction><br></div><div dir="ltr"> <saml2:Audience><a href="https://sandboxdtm01.xxx.dev/fed" rel="nofollow" target="_blank">https://sandboxdtm01.xxx.dev/fed</a></saml2:Audience><br></div><div dir="ltr"> </saml2:AudienceRestriction><br></div><div dir="ltr"> </saml2:Conditions><br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> Correct. An empty AudienceRestriction would not make<br></div><div dir="ltr"> any sense.<br></div><div dir="ltr"> It might even be schema-invalid, I'd have to<br></div><div dir="ltr"> check.<br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> The part of my code that is building that is:<br></div><div dir="ltr"> <br></div><div dir="ltr"> SAMLObjectBuilder<br></div><div dir="ltr"> audienceRestrictionConditionBuilder = (SAMLObjectBuilder)<br></div><div dir="ltr"> SAMLWriter.getSAMLBuilder().getBuilder(AudienceRestriction.DEFAULT_ELEMENT_NAME);<br></div><div dir="ltr"> Condition condition = (Condition)<br></div><div dir="ltr"> audienceRestrictionConditionBuilder.buildObject();<br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> Here you are building the empty one ...<br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> SAMLObjectBuilder conditionsBuilder =<br></div><div dir="ltr"> (SAMLObjectBuilder)<br></div><div dir="ltr"> SAMLWriter.getSAMLBuilder().getBuilder(Conditions.DEFAULT_ELEMENT_NAME);<br></div><div dir="ltr"> Conditions conditions = (Conditions)<br></div><div dir="ltr"> conditionsBuilder.buildObject();<br></div><div dir="ltr"> conditions.getConditions().add(condition);<br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> ... and here you are adding the empty one to the<br></div><div dir="ltr"> Conditions. You<br></div><div dir="ltr"> don't need to do this, or the above.<br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> // Create the audience restriction<br></div><div dir="ltr"> AudienceRestriction audienceRestriction =<br></div><div dir="ltr"> (AudienceRestriction)<br></div><div dir="ltr"> audienceRestrictionnBuilder.buildObject();<br></div><div dir="ltr"> <br></div><div dir="ltr"> // add in the audience<br></div><div dir="ltr"> audienceRestriction.getAudiences().add(audience);<br></div><div dir="ltr"> <br></div><div dir="ltr"> conditions.getAudienceRestrictions().add(audienceRestriction);<br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> And here you are adding the non-empty one, which is<br></div><div dir="ltr"> the code to<br></div><div dir="ltr"> keep.<br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> It seems like just instantiating the builder is making the<br></div><div dir="ltr"> empty saml2:AudienceRestriction, but I don't know how to<br></div><div dir="ltr"> make an "empty" builder?<br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> No, that's not correct. Instantiating a builder<br></div><div dir="ltr"> does not make<br></div><div dir="ltr"> anything (other than the builder of course). Calling<br></div><div dir="ltr"> one of the<br></div><div dir="ltr"> build(...) methods is what makes the SAMLObject. So<br></div><div dir="ltr"> there's no<br></div><div dir="ltr"> such thing as an "empty" builder.<br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr"> -- <br></div><div dir="ltr"> To unsubscribe from this list send an email to<br></div><div dir="ltr"> <a href="mailto:dev-unsubscribe@shibboleth.net" rel="nofollow" target="_blank">dev-unsubscribe@shibboleth.net</a><br></div><div dir="ltr"> -----Inline Attachment Follows-----<br></div><div dir="ltr"> <br></div><div dir="ltr"> </div></div>
</div>
</div></body></html>