May a shibboleth IdP deliver attributes for authZ without preceding authN ?

Chad La Joie lajoie at itumi.biz
Mon Oct 10 14:06:36 BST 2011


On Mon, Oct 10, 2011 at 08:58, Markus Ludwig Grandpre
<markus.grandpre at uni-konstanz.de> wrote:
> That's what we did. Unfortunately IdP is not sending an AuthNStatement
> when responding a AttributeQuery response. How can I achieve this?
> Please remember, AuthN has not taken place in IdP.

You can't.  The response to an attribute query is a <Response> with an
 <AttributeStatement>.  So what you're receiving is the proper
response.  If your code is expecting an AuthnStatement then it's your
code that has the bug, not the IdP.

> AttributeQuery request from saml2 module is:
>
> <?xml version="1.0" encoding="UTF-8"?>
> <ns0:Envelope
>  xmlns:ns0="http://schemas.xmlsoap.org/soap/envelope/">
>  <ns0:Body>
>  <ns1:AttributeQuery
>   xmlns:ns1="urn:oasis:names:tc:SAML:2.0:protocol"
>
> Destination="https://bwidm-idp.uni-konstanz.de/idp/profile/SAML2/SOAP/AttributeQuery"
>
>   ID="id-5cbb65cdb6ed86ad9f607e658fca6b51"
>   IssueInstant="2011-10-10T10:27:20Z" Version="2.0">
>   <ns2:Issuer
>    xmlns:ns2="urn:oasis:names:tc:SAML:2.0:assertion"
>    Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">
>    https://bwidm-sp01.uni-konstanz.de/shibboleth-sp
>   </ns2:Issuer>
>   <ns2:Subject
>    xmlns:ns2="urn:oasis:names:tc:SAML:2.0:assertion">
>    <ns2:NameID
>     Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"
>     NameQualifier="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"
>     SPNameQualifier="https://bwidm-sp01.uni-konstanz.de/shibboleth-sp">
>     daniel.scharon
>    </ns2:NameID>
>   </ns2:Subject>
>  </ns1:AttributeQuery>
>  </ns0:Body>
> </ns0:Envelope>
>
> AttributeQuery response from idp is:
>
> <?xml version="1.0" encoding="UTF-8"?>
> <soap11:Envelope
>  xmlns:soap11="http://schemas.xmlsoap.org/soap/envelope/">
>  <soap11:Body>
>  <saml2p:Response
>   xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"
>   ID="_06a28a8d6c2a2e09b75d613da49e3885"
>   InResponseTo="id-5cbb65cdb6ed86ad9f607e658fca6b51"
>   IssueInstant="2011-10-10T10:27:20.857Z" Version="2.0">
>   <saml2:Issuer
>    xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
>    Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">
>    https://bwidm-idp.uni-konstanz.de/idp</saml2:Issuer>
>    <saml2p:Status>
>     <saml2p:StatusCode
>      Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
>    </saml2p:Status>
>    <saml2:Assertion
>     xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
>     ID="_444ae0a995089f97b36c94b1fc6b1168"
>     IssueInstant="2011-10-10T10:27:20.857Z" Version="2.0">
>     <saml2:Issuer
>      Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">
>      https://bwidm-idp.uni-konstanz.de/idp
>     </saml2:Issuer>
>     <saml2:Subject>
>      <saml2:NameID
>       Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"
>       NameQualifier="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"
>       SPNameQualifier="https://bwidm-sp01.uni-konstanz.de/shibboleth-sp">
>       daniel.scharon
>      </saml2:NameID>
>      <saml2:SubjectConfirmation
>       Method="urn:oasis:names:tc:SAML:2.0:cm:sender-vouches">
>       <saml2:SubjectConfirmationData
>        Address="134.34.205.153"
>        InResponseTo="id-5cbb65cdb6ed86ad9f607e658fca6b51"
>        NotOnOrAfter="2011-10-10T10:32:20.857Z"/>
>      </saml2:SubjectConfirmation>
>     </saml2:Subject>
>     <saml2:Conditions
>      NotBefore="2011-10-10T10:27:20.857Z"
>      NotOnOrAfter="2011-10-10T10:32:20.857Z">
>      <saml2:AudienceRestriction>
>       <saml2:Audience>
>        https://bwidm-sp01.uni-konstanz.de/shibboleth-sp
>       </saml2:Audience>
>      </saml2:AudienceRestriction>
>     </saml2:Conditions>
>     <saml2:AttributeStatement>
>      <saml2:Attribute
>       FriendlyName="email"
>       Name="urn:oid:0.9.2342.19200300.100.1.3"
>       NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
>       <saml2:AttributeValue
>        xmlns:xs="http://www.w3.org/2001/XMLSchema"
>        xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
>        xsi:type="xs:string">
>        daniel.scharon at uni-konstanz.de
>       </saml2:AttributeValue>
>      </saml2:Attribute>
>     <saml2:Attribute
>      FriendlyName="surname"
>      Name="urn:oid:2.5.4.4"
>      NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
>      <saml2:AttributeValue
>       xmlns:xs="http://www.w3.org/2001/XMLSchema"
>       xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
>       xsi:type="xs:string">
>       Scharon
>      </saml2:AttributeValue>
>     </saml2:Attribute>
>     <saml2:Attribute
>      FriendlyName="givenName"
>      Name="urn:oid:2.5.4.42"
>      NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
>      <saml2:AttributeValue
>       xmlns:xs="http://www.w3.org/2001/XMLSchema"
>       xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
>       xsi:type="xs:string">
>       Daniel
>      </saml2:AttributeValue>
>     </saml2:Attribute>
>    </saml2:AttributeStatement>
>   </saml2:Assertion>
>  </saml2p:Response>
>  </soap11:Body>
> </soap11:Envelope>
>
> Obviously there is no AuthNStatement in AttributeQuery response.
>
> Best regards,
> Markus
>
>
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>



-- 
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the users mailing list