shibboleth-sp "message not signed" issue.

Erica Johansson ericalj at gmail.com
Fri Sep 28 15:34:09 EDT 2012


Hello,
I'm troubleshooting an issue between shibboleth-sp and ADFS (2 ADFS servers
behind the load balancer of login.foo.com) as the IdP where after replacing
an apache front end SSL for a web site, the SSO is no longer working.

Users sign into the www.foo.com, which is all windows, but when they
attempt to go to cms.foo.com which is the apache/shibboleth piece, the
following error message is thrown in shibd.log when I enable debugging:

2012-09-28 12:47:12 INFO Shibboleth.Listener [1]: detected socket closure,
shutting down worker thread
2012-09-28 12:47:18 DEBUG Shibboleth.Listener [10]: dispatching message
(default::getHeaders::Application)
2012-09-28 12:47:18 DEBUG Shibboleth.Listener [11]: dispatching message
(default/Login::run::ADFSSI)
2012-09-28 12:47:18 INFO Shibboleth.SessionInitiator.ADFS [11]: unable to
locate ADFS-aware identity provider role for provider (
http://login.foo.com/adfs/services/trust)
2012-09-28 12:47:18 DEBUG Shibboleth.Listener [11]: dispatching message
(default/Login::run::SAML2SI)
2012-09-28 12:47:18 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [11]:
validating input
2012-09-28 12:47:18 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [11]:
marshalling, deflating, base64-encoding the message
2012-09-28 12:47:18 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [11]:
marshalled message:
<samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
AssertionConsumerServiceURL="https://cms.foo.com/Shibboleth.sso/SAML2/POST"
Destination="https://login.foo.com/adfs/ls/"
ID="_c3c745747ddb5ecda84dccfa78425caf" IssueInstant="2012-09-28T16:47:18Z"
ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
Version="2.0"><saml:Issuer
xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">
https://cms.foo.com/shibboleth</saml:Issuer><samlp:NameIDPolicy
AllowCreate="1"/></samlp:AuthnRequest>
2012-09-28 12:47:18 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [11]:
message encoded, sending redirect to client
2012-09-28 12:47:18 DEBUG Shibboleth.Listener [12]: dispatching message
(default/SAML2/POST)
2012-09-28 12:47:18 DEBUG OpenSAML.MessageDecoder.SAML2POST [12]:
validating input
2012-09-28 12:47:18 DEBUG OpenSAML.MessageDecoder.SAML2POST [12]: decoded
SAML message:
2012-09-28 12:47:18 DEBUG OpenSAML.MessageDecoder.SAML2 [12]: extracting
issuer from SAML 2.0 protocol message
2012-09-28 12:47:18 DEBUG OpenSAML.MessageDecoder.SAML2 [12]: message from (
http://login.foo.com/adfs/services/trust)
2012-09-28 12:47:18 DEBUG OpenSAML.MessageDecoder.SAML2 [12]: searching
metadata for message issuer...
2012-09-28 12:47:18 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [12]:
evaluating message flow policy (replay checking on, expiration 60)
2012-09-28 12:47:18 DEBUG XMLTooling.StorageService [12]: inserted record
(_36a781a5-70cf-451e-b238-de9fc8cb4b57) in context (MessageFlow) with
expiration (1348851078)
2012-09-28 12:47:18 DEBUG Shibboleth.SSO.SAML2 [12]: processing message
against SAML 2.0 SSO profile
2012-09-28 12:47:18 DEBUG XMLTooling.CredentialCriteria [12]: key algorithm
didn't match ('AES' != 'RSA')
2012-09-28 12:47:18 DEBUG Shibboleth.SSO.SAML2 [12]: decrypted Assertion:
<Assertion xmlns="urn:oasis:names:tc:SAML:2.0:assertion"
ID="_fc52a2da-c77e-4d44-bbb0-08501bcabad1"
IssueInstant="2012-09-28T16:47:18.430Z" Version="2.0"><Issuer>
http://login.foo.com/adfs/services/trust</Issuer><ds:Signature xmlns:ds="
http://www.w3.org/2000/09/xmldsig#"><ds:SignedInfo><ds:CanonicalizationMethod
Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/><ds:SignatureMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/><ds:Reference
URI="#_fc52a2da-c77e-4d44-bbb0-08501bcabad1"><ds:Transforms><ds:Transform
Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/><ds:Transform
Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/></ds:Transforms><ds:DigestMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/><ds:DigestValue>n2uxLhU7xqQx5PieceNiLDICukmJMZWVXAQbjFtJHhk=</ds:DigestValue></ds:Reference></ds:SignedInfo><ds:SignatureValue>C/L0fq5hEuBPMs9hO/+vqZ17yYGDfyg+g6j2iEjdW7vWi22JfB+N/APZzHRZnZm8Lzv1KQb5NoG/wAiWJ2Yof5YTqlLPQ9a6zsWvBDjb17Uj6PSNYTvl/wVomjiwKjokM65IH0sZWZia0+2c6PU/2LGzANzZsb1PfxCFzbzMFOp25j7hNe4H/L7mWKgA8mFJS/OgPiorp4In++4Q0NB4H8Md3xZQwgvmbjC3o+SFVh3YJxzGpNt3q5bTmWGePJDffz7bSF15FytePBQ21OhjKV8S9DN871qVnLSSnq5qY9O8+gthMRVthpo10t4rQTvh58y+z9z88s711Zb1sMOCAQ==</ds:SignatureValue><KeyInfo
xmlns="http://www.w3.org/2000/09/xmldsig#"><ds:X509Data><ds:X509Certificate>Y2QoCpx+ngyA4ecM0PAWAI1pqJc0l6bas4e3VqVjZmHSvCQ6uICuzpPPlAlcb/AbGLEb3YeH7/3fPXKtCSKJ3W70wQUs8aalyiA2SVzz5Ht0Il9XnSHc/qC1r/wa8Vc0</ds:X509Certificate></ds:X509Data></KeyInfo></ds:Signature><Subject><NameID>4aHHPvWYKE+/ZTRUso2+eA==</NameID><SubjectConfirmation
Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><SubjectConfirmationData
InResponseTo="_c3c745747ddb5ecda84dccfa78425caf"
NotOnOrAfter="2012-09-28T16:52:18.430Z" Recipient="
https://cms.foo.com/Shibboleth.sso/SAML2/POST"/></SubjectConfirmation></Subject><Conditions
NotBefore="2012-09-28T16:47:18.415Z"
NotOnOrAfter="2012-09-28T17:47:18.415Z"><AudienceRestriction><Audience>
https://cms.foo.com/shibboleth</Audience></AudienceRestriction></Conditions><AttributeStatement><Attribute
Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/title
"><AttributeValue>ericalj at foo.com</AttributeValue></Attribute><Attribute
Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn
"><AttributeValue>ericalj at foo.com</AttributeValue></Attribute></AttributeStatement><AuthnStatement
AuthnInstant="2012-09-28T16:15:43.349Z"
SessionIndex="_fc52a2da-c77e-4d44-bbb0-08501bcabad1"><AuthnContext><AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</AuthnContextClassRef></AuthnContext></AuthnStatement></Assertion>
2012-09-28 12:47:18 DEBUG Shibboleth.SSO.SAML2 [12]: extracting issuer from
SAML 2.0 assertion
2012-09-28 12:47:18 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [12]:
evaluating message flow policy (replay checking on, expiration 60)
2012-09-28 12:47:18 DEBUG XMLTooling.StorageService [12]: inserted record
(_fc52a2da-c77e-4d44-bbb0-08501bcabad1) in context (MessageFlow) with
expiration (1348851078)
2012-09-28 12:47:18 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [12]:
validating signature profile
2012-09-28 12:47:18 DEBUG XMLTooling.CredentialCriteria [12]: keys didn't
match
2012-09-28 12:47:18 DEBUG XMLTooling.TrustEngine.ExplicitKey [12]: unable
to validate signature, no credentials available from peer
2012-09-28 12:47:18 DEBUG XMLTooling.TrustEngine.PKIX [12]: validating
signature using certificate from within the signature
2012-09-28 12:47:18 DEBUG XMLTooling.TrustEngine.PKIX [12]: signature
verified with key inside signature, attempting certificate validation...
2012-09-28 12:47:18 DEBUG XMLTooling.TrustEngine.PKIX [12]: checking that
the certificate name is acceptable
2012-09-28 12:47:18 DEBUG XMLTooling.TrustEngine.PKIX [12]: certificate
subject: CN=login.foo.com,OU=OIT,O=US Dept of
G,L=Washington,ST=DC,DC=va,DC=gov
2012-09-28 12:47:18 DEBUG XMLTooling.TrustEngine.PKIX [12]: unable to match
DN, trying TLS subjectAltName match
2012-09-28 12:47:18 DEBUG XMLTooling.TrustEngine.PKIX [12]: unable to match
subjectAltName, trying TLS CN match
2012-09-28 12:47:18 ERROR XMLTooling.TrustEngine.PKIX [12]: certificate
name was not acceptable
2012-09-28 12:47:18 ERROR OpenSAML.SecurityPolicyRule.XMLSigning [12]:
unable to verify message signature with supplied trust engine
2012-09-28 12:47:18 WARN Shibboleth.SSO.SAML2 [12]: detected a problem with
assertion: Message was signed, but signature could not be verified.

I'm unfortunately learning SSO as I go, so, I'm sorry if this seems like an
obvious/simple issue. I am leaning towards an issue with the metadata, but
I'm not certain how to check that further or resolve it if it is.

I've verified the sp-cert referenced in shibboleth2.xml is still valid and
hasn't been touched. I've verified on the ADFS portion that the relying
data matches the sp-cert as well.

Thanks,
Erica
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120928/7fc4f002/attachment-0001.html 


More information about the users mailing list