configuring metadata for Net+ Box SP

Douglas E. Engert deengert at anl.gov
Mon Jul 8 14:30:39 EDT 2013



On 7/8/2013 12:00 PM, Rob Gorrell wrote:
>      > So your change was the deletion of the 'use="signing"' part in the md:KeyDescriptor tag? I made this change as well, reloaded the metadata and now the error (returned by them) has changed to:
>      >
>
>     Yes.
>
>
> So forgive me, but what does removing this parameter from the metadata actually do? the IdP won't sign the assertion because Box can't handle that? but the IdP will/should still encrypt the assertion
> and Box is supposed to support that? Though from what you were saying, you can't remember if thats something optionally they must enable? I've got an email out to my Box contacts, depending on what
> their response is, I may loop up with you for that information.

See Ian Young's response. The certificate can be used by the IDP to encrypt.


I assume box setup your site to use Shibboleth?

Have you seen:
https://spaces.internet2.edu/display/NetPlusIDG/BoxIDG

Here is the start of the encrypted assertion that worked from our 2.3.8 IDP to box.
Some things that might be an issue from your IDP: sha1, aes-128 and rsa-oaep-mgf1p

See if you can find the encrypted assertion in the IDP logs,
or use something like FireFox with the SAML Tracer plugin to see the
encrypted assertion, and with encryption methods are being used.



> <saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"
>                  Destination="https://sso.services.box.net/sp/ACS.saml2"
>                  ID="_6a05de62455eac3db626c6143ab54e58"
>                  InResponseTo="wg1.Wxbc4MQijCZgDSy4y2InY1Q"
>                  IssueInstant="2013-07-08T15:39:17.245Z"
>                  Version="2.0"
>                  >
>     <saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
>                   Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity"
>                   >https://identityprovider.anl.gov/idp/shibboleth</saml2:Issuer>
>     <saml2p:Status>
>         <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success" />
>     </saml2p:Status>
>     <saml2:EncryptedAssertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">
>         <xenc:EncryptedData xmlns:xenc="http://www.w3.org/2001/04/xmlenc#"
>                             Id="_978c88692bc29ffcfb92363b526d5096"
>                             Type="http://www.w3.org/2001/04/xmlenc#Element"
>                             >
>             <xenc:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"
>                                    xmlns:xenc="http://www.w3.org/2001/04/xmlenc#"
>                                    />
>             <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
>                 <xenc:EncryptedKey Id="_d516fb6cc2fe23480b2e19e2df28077b"
>                                    xmlns:xenc="http://www.w3.org/2001/04/xmlenc#"
>                                    >
>                     <xenc:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"
>                                            xmlns:xenc="http://www.w3.org/2001/04/xmlenc#"
>                                            >
>                         <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"
>                                          xmlns:ds="http://www.w3.org/2000/09/xmldsig#"
>                                          />
>                     </xenc:EncryptionMethod>
>                     <ds:KeyInfo>
>                         <ds:X509Data>
>                             <ds:X509Certificate>MIICHTCCAYagAwIBAgIGATc5d2+BMA0GCSqGSIb3DQEBBQUAMFIxCzAJBgNVBAYTAlVTMQswCQYD
> VQQIEwJDQTESMBAGA1UEBxMJTG9zIEFsdG9zMRAwDgYDVQQKEwdCb3gubmV0MRAwDgYDVQQDEwdi
> b3gubmV0MB4XDTEyMDUxMTAxMTU1N1oXDTE0MDUxMTAxMTU1N1owUjELMAkGA1UEBhMCVVMxCzAJ
> BgNVBAgTAkNBMRIwEAYDVQQHEwlMb3MgQWx0b3MxEDAOBgNVBAoTB0JveC5uZXQxEDAOBgNVBAMT
> B2JveC5uZXQwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAIf8XpSWiVUWmHgPBCJKE48DhAVp
> RYnlomeBzHrkhMFyr0i7EKo1qMC9ewQbvp3nguz1bd5r9g75+l/xdfQ/+OOpqw0WicqsNEUpkOeq
> I/w35q9n6LZL85w0s21PtoGrpI7dV3NDw4qMxI760+oYYRBoj2qxnXLlHfoAWLUJjzEPAgMBAAEw
> DQYJKoZIhvcNAQEFBQADgYEAEimuP4fO2Exrv3QQvkRUpgtWLpLVjOAEwDzD5hdLej0/wICHzT7l
> gB+wMrEVsZ/76Bxh5C0T5JBtgosqKs9/F/WySV9FSFnRnjh7DUptfJCv4UFhkZdY6l4fja673cX1
> eITlrMBEgtDrqETmJsqlp2RXv5GSPmhQXFA2tLENHVY=</ds:X509Certificate>
>                         </ds:X509Data>
>                     </ds:KeyInfo>
>                     <xenc:CipherData xmlns:xenc="http://www.w3.org/2001/04/xmlenc#">
>                         <xenc:CipherValue>FQctsh4+ag7KgNkTkkTIn+7yg/9A4kh1c237yK5fE4OLIRU4iYauwG9LrVF7zCa9gTlVFnZTzpIKn8rKtH3uVzSLBOR0HCqj3XsZds2FSpp1ZF54rmOJrpzt/WW6JmRn7wiUOfvAgpGhM03VxDXhHv5baAcYFdc55cNjOhTxE78=</xenc:CipherValue>
>                     </xenc:CipherData>
>                 </xenc:EncryptedKey>
>             </ds:KeyInfo>
>             <xenc:CipherData xmlns:xenc="http://www.w3.org/2001/04/xmlenc#">
 > ...(encrypted data) ...




>
> Thanks
> -Rob
>
>
> --
> Robert W. Gorrell
> Middleware Engineer, Identity and Access Management
> University of NC at Greensboro
> 336-334-5954
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>

-- 

  Douglas E. Engert  <DEEngert at anl.gov>
  Argonne National Laboratory
  9700 South Cass Avenue
  Argonne, Illinois  60439
  (630) 252-5444


More information about the users mailing list