<html><head></head><body><div class="ydpd17dc26dyahoo-style-wrap" style="font-family:Helvetica Neue, Helvetica, Arial, sans-serif;font-size:16px;"><div></div>
        <div>Hi,</div><div><br></div><div>I was able to get it to work now.  I had to add back (uncomment) the lines where the conditions and condition were created.</div><div><br></div><div>Thanks!</div><div><br></div><div>Jim</div><div><br></div><div>P.S.  BTW, and yes, I will look into moving to a newer version of OpenSAML, but I ran into some problems trying to use the newer one before, but I wanted to try to get something working first.</div><div><br></div><div><br></div><div><br></div><div><br></div>
        
        </div><div id="ydp4ca3d730yahoo_quoted_1222857273" class="ydp4ca3d730yahoo_quoted">
            <div style="font-family:'Helvetica Neue', Helvetica, Arial, sans-serif;font-size:13px;color:#26282a;">
                
                <div>
                    On Friday, February 15, 2019, 3:42:11 PM EST, o haya <ohaya@yahoo.com> wrote:
                </div>
                <div><br></div>
                <div><br></div>
                <div><div dir="ltr">Hi,<br></div><div dir="ltr"><br></div><div dir="ltr">Thanks, maybe I am mis-reading what you were suggesting (the formatting on Yahoo email may be bad), but if I remove the parts that you mentioned:<br></div><div dir="ltr"><br></div><div dir="ltr">====================================================================================================================================<br></div><div dir="ltr"><br></div><div dir="ltr">><br></div><div dir="ltr">> The part of my code that is building that is:<br></div><div dir="ltr">><br></div><div dir="ltr">>             SAMLObjectBuilder audienceRestrictionConditionBuilder = (SAMLObjectBuilder) SAMLWriter.getSAMLBuilder().getBuilder(AudienceRestriction.DEFAULT_ELEMENT_NAME);<br></div><div dir="ltr">>             Condition condition = (Condition) audienceRestrictionConditionBuilder.buildObject();<br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr">Here you are building the empty one ...<br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr">><br></div><div dir="ltr">>             SAMLObjectBuilder conditionsBuilder = (SAMLObjectBuilder) SAMLWriter.getSAMLBuilder().getBuilder(Conditions.DEFAULT_ELEMENT_NAME);<br></div><div dir="ltr">>             Conditions conditions = (Conditions) conditionsBuilder.buildObject();<br></div><div dir="ltr">>             conditions.getConditions().add(condition);<br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr">... and here you are adding the empty one to the Conditions.  You don't need to do this, or the above.<br></div><div dir="ltr"><br></div><div dir="ltr">====================================================================================================================================<br></div><div dir="ltr"><br></div><div dir="ltr">both "conditions" and "condition" are undefined?<br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr">Like I said, I may be mis-reading/misunderstanding what you were suggesting, but I think that this is what I got when I commented out the lines you mentioned:<br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr">            conditions.setNotBefore(now);<br></div><div dir="ltr">            conditions.setNotOnOrAfter(now2);<br></div><div dir="ltr">            <br></div><div dir="ltr">            SAMLObjectBuilder audienceRestrictionnBuilder = null;<br></div><div dir="ltr">            SAMLObjectBuilder audienceBuilder = null;<br></div><div dir="ltr">            audienceRestrictionnBuilder = (SAMLObjectBuilder) getSAMLBuilder().getBuilder(AudienceRestriction.DEFAULT_ELEMENT_NAME);<br></div><div dir="ltr">            audienceBuilder = (SAMLObjectBuilder) getSAMLBuilder().getBuilder(Audience.DEFAULT_ELEMENT_NAME);<br></div><div dir="ltr">            String audienceURI = "<a href="https://sandboxdtm01.xxx.dev/fed" rel="nofollow" target="_blank">https://sandboxdtm01.xxx.dev/fed</a>";<br></div><div dir="ltr">            <br></div><div dir="ltr">            // Create the audience<br></div><div dir="ltr">            Audience audience = (Audience) audienceBuilder.buildObject();<br></div><div dir="ltr">            audience.setAudienceURI(audienceURI);<br></div><div dir="ltr"><br></div><div dir="ltr">            // Create the audience restriction<br></div><div dir="ltr">            AudienceRestriction audienceRestriction = (AudienceRestriction) audienceRestrictionnBuilder.buildObject();<br></div><div dir="ltr"><br></div><div dir="ltr">            // add in the audience<br></div><div dir="ltr">            audienceRestriction.getAudiences().add(audience);<br></div><div dir="ltr">            conditions.getAudienceRestrictions().add(audienceRestriction);<br></div><div dir="ltr">            <br></div><div dir="ltr"><br></div><div dir="ltr">Jim<br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr">--------------------------------------------<br></div><div dir="ltr">On Fri, 2/15/19, Brent Putman <<a href="mailto:putmanb@georgetown.edu" rel="nofollow" target="_blank">putmanb@georgetown.edu</a>> wrote:<br></div><div dir="ltr"><br></div><div dir="ltr"> Subject: Re: New here - OpenSAML and conditions/audience restrictions problem<br></div><div dir="ltr"> To: <a href="mailto:dev@shibboleth.net" rel="nofollow" target="_blank">dev@shibboleth.net</a><br></div><div dir="ltr"> Date: Friday, February 15, 2019, 3:10 PM<br></div><div dir="ltr"> <br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     On 2/15/19<br></div><div dir="ltr"> 2:55 PM, o haya wrote:<br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     <br></div><div dir="ltr">       <br></div><div dir="ltr"> <br></div><div dir="ltr"> I am just getting started with OpenSAML, and using Java and<br></div><div dir="ltr"> OpenSAML 2.6.6 <br></div><div dir="ltr">     <br></div><div dir="ltr">     <br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     Don't.  Use the latest 3.x  OpenSAML 2.x has<br></div><div dir="ltr"> been End Of Life for<br></div><div dir="ltr">       over 2.5 years at this point. See the announcement and<br></div><div dir="ltr"> links here:<br></div><div dir="ltr">     <a href="https://wiki.shibboleth.net/confluence/display/OpenSAML/Home" rel="nofollow" target="_blank">https://wiki.shibboleth.net/confluence/display/OpenSAML/Home</a><br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">      There's absolutely no reason to start a new<br></div><div dir="ltr"> project with 2.x,<br></div><div dir="ltr">       and it is indeed a bad idea due to security<br></div><div dir="ltr"> vulnerabilities which<br></div><div dir="ltr">       have been fixed since it went EOL.<br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     <br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     <br></div><div dir="ltr">       <br></div><div dir="ltr"> <br></div><div dir="ltr"> I have code now that, in fact does add the<br></div><div dir="ltr"> <Conditions>, but I am ending up with two<br></div><div dir="ltr"> <saml:AudienceRestriction> elements. <br></div><div dir="ltr">     <br></div><div dir="ltr">     <br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     Yes, you are adding it twice.<br></div><div dir="ltr">     <br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     <br></div><div dir="ltr">       <br></div><div dir="ltr"> whereas I think that what I want is (i.e., just the one<br></div><div dir="ltr"> saml2:AudienceRestriction with the URI):<br></div><div dir="ltr"> <br></div><div dir="ltr"> <saml2:Conditions<br></div><div dir="ltr"> NotOnOrAfter="2019-02-15T19:27:56.620Z"<br></div><div dir="ltr"> NotBefore="2019-02-15T19:27:56.603Z"><br></div><div dir="ltr">     <saml2:AudienceRestriction><br></div><div dir="ltr">         <saml2:Audience><a href="https://sandboxdtm01.xxx.dev/fed" rel="nofollow" target="_blank">https://sandboxdtm01.xxx.dev/fed</a></saml2:Audience><br></div><div dir="ltr">     </saml2:AudienceRestriction><br></div><div dir="ltr"> </saml2:Conditions><br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     <br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     Correct. An empty AudienceRestriction would not make<br></div><div dir="ltr"> any sense.<br></div><div dir="ltr">       It might even be schema-invalid, I'd have to<br></div><div dir="ltr"> check.<br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     <br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     <br></div><div dir="ltr">       <br></div><div dir="ltr"> The part of my code that is building that is:<br></div><div dir="ltr"> <br></div><div dir="ltr">             SAMLObjectBuilder<br></div><div dir="ltr"> audienceRestrictionConditionBuilder = (SAMLObjectBuilder)<br></div><div dir="ltr"> SAMLWriter.getSAMLBuilder().getBuilder(AudienceRestriction.DEFAULT_ELEMENT_NAME);<br></div><div dir="ltr">             Condition condition = (Condition)<br></div><div dir="ltr"> audienceRestrictionConditionBuilder.buildObject();<br></div><div dir="ltr">     <br></div><div dir="ltr">     <br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     Here you are building the empty one ...<br></div><div dir="ltr">     <br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     <br></div><div dir="ltr">       <br></div><div dir="ltr"> <br></div><div dir="ltr">             SAMLObjectBuilder conditionsBuilder =<br></div><div dir="ltr"> (SAMLObjectBuilder)<br></div><div dir="ltr"> SAMLWriter.getSAMLBuilder().getBuilder(Conditions.DEFAULT_ELEMENT_NAME);<br></div><div dir="ltr">             Conditions conditions = (Conditions)<br></div><div dir="ltr"> conditionsBuilder.buildObject();<br></div><div dir="ltr">             conditions.getConditions().add(condition);<br></div><div dir="ltr">     <br></div><div dir="ltr">     <br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     ... and here you are adding the empty one to the<br></div><div dir="ltr"> Conditions.  You<br></div><div dir="ltr">       don't need to do this, or the above.<br></div><div dir="ltr">     <br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     <br></div><div dir="ltr">       <br></div><div dir="ltr">             // Create the audience restriction<br></div><div dir="ltr">             AudienceRestriction audienceRestriction =<br></div><div dir="ltr"> (AudienceRestriction)<br></div><div dir="ltr"> audienceRestrictionnBuilder.buildObject();<br></div><div dir="ltr"> <br></div><div dir="ltr">             // add in the audience<br></div><div dir="ltr">             audienceRestriction.getAudiences().add(audience);<br></div><div dir="ltr">        <br></div><div dir="ltr">     conditions.getAudienceRestrictions().add(audienceRestriction);<br></div><div dir="ltr">     <br></div><div dir="ltr">     <br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     And here you are adding the non-empty one, which is<br></div><div dir="ltr"> the code to<br></div><div dir="ltr">       keep.<br></div><div dir="ltr">     <br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     <br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     <br></div><div dir="ltr">       <br></div><div dir="ltr"> <br></div><div dir="ltr"> It seems like just instantiating the builder is making the<br></div><div dir="ltr"> empty saml2:AudienceRestriction, but I don't know how to<br></div><div dir="ltr"> make an "empty" builder?<br></div><div dir="ltr">     <br></div><div dir="ltr">     <br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     No, that's not correct. Instantiating a builder<br></div><div dir="ltr"> does not make<br></div><div dir="ltr">       anything (other than the builder of course).  Calling<br></div><div dir="ltr"> one of the<br></div><div dir="ltr">       build(...) methods is what makes the SAMLObject.  So<br></div><div dir="ltr"> there's no<br></div><div dir="ltr">       such thing as an "empty" builder.<br></div><div dir="ltr"> <br></div><div dir="ltr">     <br></div><div dir="ltr">     <br></div><div dir="ltr"> <br></div><div dir="ltr">   -- <br></div><div dir="ltr"> To unsubscribe from this list send an email to<br></div><div dir="ltr"> <a href="mailto:dev-unsubscribe@shibboleth.net" rel="nofollow" target="_blank">dev-unsubscribe@shibboleth.net</a><br></div><div dir="ltr"> -----Inline Attachment Follows-----<br></div><div dir="ltr"> <br></div><div dir="ltr"> </div></div>
            </div>
        </div></body></html>