<div dir="ltr">Hi,<div><br></div><div>I have created a simple SOAP service which will accept an AttributeQuery SAML element in the body of a SOAP envelope. This works fine, I am now moving on to validating a signed AttributeQuery. To do this I have created a simple integration test to build an attribute query, sign it and use a soap client to send the request.</div><div><br></div><div>The signing is done like so</div><div><br></div><div>SignatureBuilder sigBuilder = new SignatureBuilder();<br>Signature signature = sigBuilder.buildObject();<br><br>signature.setSigningCredential(x509Credential);<br>signature.setSignatureAlgorithm(SignatureConstants.ALGO_ID_SIGNATURE_RSA_SHA1);<br>signature.setCanonicalizationAlgorithm(SignatureConstants.ALGO_ID_C14N_EXCL_OMIT_COMMENTS);<br>signature.setKeyInfo(getKeyInfo(x509Credential));<br><br>query.setSignature(signature);<br><br>XMLObjectProviderRegistrySupport.getMarshallerFactory().getMarshaller(query).marshall(query);<br>Signer.signObject(signature);<br></div><div><br></div><div>Then on the server side I can rip the signature out of the AttributeQuery and do the validation like so (I build a list of X509Credentials from the service keystore, one of which will have the public key of the client that signed it)</div><div><br></div><div>SAMLSignatureProfileValidator profileValidator = new SAMLSignatureProfileValidator();<br>try {<br>   profileValidator.validate(sig);<br>} catch (SignatureException e) {<br>   throw new SignatureValidationException("Unable to validate signature profile", e);<br>}<br><br>boolean validated = false;<br><br>for (Credential cred : trustedCredentials) {<br>   try {<br>      SignatureValidator.validate(sig, cred);<br>      validated = true;<br>      break;<br>   } catch (SignatureException e) {<br>      <a href="http://logger.info/" target="_blank">logger.info</a>("Signature validation failed checking next credential");<br>   }<br>}<br><br>if (!validated) {<br>   throw new SignatureValidationException("Unable to validate signature");<br>}<br></div><div><br></div><div>The validation is failing, it seems that the decoded digest value is different from the computed digest value, and I can't for the life of me see why. Any ideas? Here's a sample soap envelope sent as a request.</div><div><br></div><div><SOAP-ENV:Envelope xmlns:SOAP-ENV="<a href="http://schemas.xmlsoap.org/soap/envelope/" target="_blank">http://schemas.xmlsoap.org/soap/envelope/</a>"><SOAP-ENV:Header/><SOAP-ENV:Body><ns5:AttributeQuery xmlns:ns2="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:ns3="<a href="http://www.w3.org/2001/04/xmlenc#" target="_blank">http://www.w3.org/2001/04/xmlenc#</a>" xmlns:ns4="<a href="http://www.w3.org/2000/09/xmldsig#" target="_blank">http://www.w3.org/2000/09/xmldsig#</a>" xmlns:ns5="urn:oasis:names:tc:SAML:2.0:protocol" Version="2.0"><ns4:Signature><ns4:SignedInfo><ns4:CanonicalizationMethod Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#" target="_blank">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/><ns4:SignatureMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#rsa-sha1" target="_blank">http://www.w3.org/2000/09/xmldsig#rsa-sha1</a>"/><ns4:Reference URI=""><ns4:Transforms><ns4:Transform Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature" target="_blank">http://www.w3.org/2000/09/xmldsig#enveloped-signature</a>"/><ns4:Transform Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#" target="_blank">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/></ns4:Transforms><ns4:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#sha256" target="_blank">http://www.w3.org/2001/04/xmlenc#sha256</a>"/><ns4:DigestValue>buzHLMIa7woVXZi1i43aC9i5rb5+YnFTIPJS9tBEcmc=</ns4:DigestValue></ns4:Reference></ns4:SignedInfo><ns4:SignatureValue>FFwejG1KyWgH6AIO2MYXr1wQGXbs4id7iIyMcBYUabZbTQr90gErMMpCxIRTx+yrV4rNfdS5r5ye5i9f1yVeLqjZDyKh0p+eXt7o8bZKKDmP99iyEP0GUvm03co0q9Tg7nZ3Ex8l+DqNm1chRak4ZD2n8LbP7pHOTeo/kJjmqdt2u5ku5lSFLmhi1m3irrBJkoy/1gC/Mt9su1e1AjFA1jDlpdn/ESzMMptvivgR8GRHEey7wJPpgnomvCGFxoUes0qQ54W9BJXATPuND/Z/GduaHuIs9X1tEbcXziwpcSRXyHoMhzuMOR059/+hzNyAv8yyyiNw5G0JUarQur1RPg==</ns4:SignatureValue><ns4:KeyInfo><ns4:X509Data><ns4:X509Certificate>MIIDazCCAlOgAwIBAgIEbZO3mzANBgkqhkiG9w0BAQsFADBmMQswCQYDVQQGEwJVSzEQMA4GA1UECBMHVW5rbm93bjEQMA4GA1UEBxMHVW5rbm93bjEPMA0GA1UEChMGY2xpZW50MRAwDgYDVQQLEwdVbmtub3duMRAwDgYDVQQDEwdVbmtub3duMB4XDTIwMDQyMzEwNTQ0MVoXDTMwMDQyMTEwNTQ0MVowZjELMAkGA1UEBhMCVUsxEDAOBgNVBAgTB1Vua25vd24xEDAOBgNVBAcTB1Vua25vd24xDzANBgNVBAoTBmNsaWVudDEQMA4GA1UECxMHVW5rbm93bjEQMA4GA1UEAxMHVW5rbm93bjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAIC2iX8p2c1FSXFGXjgYMh1AaYmVnFQwebmw51wM/0K8TOYyAm0mX5hgAFfd//MI3sNhhIBVMEFxdCb70hmPzXu4FsNXdl+whXhb2xwicCLjajYX5rBdDH8ywTOyahM/kUxf5vDoq+C+dj8LuwhTZQUc/vlbtJVsl7qCZUS3clckpRqVXgXjX+mgZ98/2YvYJ8xMP7PupRKlR+9c+8JEbPFCXSfCneUiaKvbaoIK1G4pZDUlDTGDPNRNn2J975D8HsgKEAAXK125jplzYu1WN4oDJFd7SfBykGdl3E/IIaZul9DXXx8kcJcKBIXy5vMABUSnLW342yGMY8HFJrQYJlcCAwEAAaMhMB8wHQYDVR0OBBYEFFNlhUmRb5SXP25C1pgfAW+mQ8LrMA0GCSqGSIb3DQEBCwUAA4IBAQBNuo14kLTkZdUI2Fym2Oz578u8LigH8K8yAJHIuWk55OCI2ss9MgfWrxCUNU1/8TIJaQdNggOXAbLUhzUTKlaKIkHSGESm3KcasDdzsdbLTZ8OBFn0WCjatlj6c+O6eQX+MZjS2DhoN4VIGjcuwy/eNoTx+avj9WocD9kf5gZUPUA42ZigOOBnUMGrTcx1DbLLHu775cRvR1HBcbkMqITT7xMIuhcZsUqqoGJy3MEy86KIJMW0UDzFLbPEdxwzGcVEio7hQOE5LMKgJqMRMI4rMf4VHDkz3Bw5a7wWhNb6M4no+mQQEoLkoJdHfTjr/xDIykFKnKni+n4kn+9xDOlZ</ns4:X509Certificate></ns4:X509Data></ns4:KeyInfo></ns4:Signature><ns2:Subject><ns2:NameID>cn=fake,dc=fake,dc=org,dc=uk</ns2:NameID></ns2:Subject><ns2:Attribute FriendlyName="MyAttr" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"/></ns5:AttributeQuery></SOAP-ENV:Body></SOAP-ENV:Envelope><br></div><div><br></div><div>Thanks,</div><div><br></div><div>Paul</div></div>