Signature trust could not be established via PKIX validation of signing credential

Schumacher, Adam J. adamschumacher at creighton.edu
Wed Jul 10 18:38:45 EDT 2013


I am attempting to get a partner SP to successfully do SSO with our Shibboleth IDP (v2.3.6).  The partner SP is not using Shibboleth SP, but is using an unknown (to me) SAML library.  It appears that the process is failing when the IDP attempts to verify that the certificate used to sign the incoming AuthN request from the SP is trusted.  The signature on the request is successfully verified using the supplied certificate so I know that at least the supplied certificate is the one used to create the signature.  I have verified that the certificate supplied in the request matches the certificate supplied in the SP metadata (copied both to a file and ran diff).  I've validated that the certificate is, in fact, a valid x509 certificate using openssl.  I'm not sure if this is relevant, but the certificate is a wildcard cert signed by a 3rd party CA.  As far as I can tell the SPs metadata is correct and complete.

Any thoughts on something else to try, or have the SP change?  

Here is an example AuthnRequest from the SP:

<samlp:AuthnRequest ID="_D2A25F3AA10788974A5F31B6617A8C48" Version="2.0" IssueInstant="2013-07-10T22:10:28.739Z" 
                    Destination="https://auth-test.creighton.edu/idp/profile/SAML2/POST/SSO" ForceAuthn="false" 
                    IsPassive="false" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" 
                    AssertionConsumerServiceURL="https://creighton.harvesthcm.com/SSO/AssertionService.aspx?binding=urn%3aoasis%3anames%3atc%3aSAML%3a2.0%3abindings%3aHTTP-POST" 
                    xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol">
  <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https://creighton.harvesthcm.com</saml:Issuer>
  <Signature xmlns="http://www.w3.org/2000/09/xmldsig#">
    <SignedInfo>
      <CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
      <SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1" />
      <Reference URI="#_D2A25F3AA10788974A5F31B6617A8C48">
        <Transforms>
          <Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" />
          <Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#">
            <InclusiveNamespaces PrefixList="#default saml ds xs xsi" xmlns="http://www.w3.org/2001/10/xml-exc-c14n#" />
          </Transform>
        </Transforms>
        <DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1" />
        <DigestValue>h9JIg7nk1tcyAR45cv88/ZqVpGg=</DigestValue>
      </Reference>
    </SignedInfo>
    <SignatureValue>osDrjhr6RT7NHeVWI6BkT9qJSomgvzz/XXjhwwMmMtJ5X/qgpCefJf3zCnqH3Mxaj2nZemFfsSC4OFb3bWHcqo/VdDPO+aUeVuQarPTA56UJXksrcilw1pCWoz53Ej4BpgjEJdmjHg3wcuzrT/h2/B3F6jHFp/2n34wEJxzys6ICANl6mz4fmHgu/pHuPrRrKERUs945SremqMs3kAwufctRYvaucrrI6VO0ud1CGG0yk5K7spxwsEDJFmFQg6kx14D22ozP4bU7pjXfIsVxhgDPIuU1/Bdk84H/nC7ew6/t1z9966PAczRMdd2+svkQdWUyqJaKZASo0/8z4ySsSw==</SignatureValue>
    <KeyInfo>
      <X509Data>
        <X509Certificate>MIIGvDCCBaSgAwIBAgIQDUmA2ckCXrNh3rzF8Z2tRjANBgkqhkiG9w0BAQUFADBmMQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3d3cuZGlnaWNlcnQuY29tMSUwIwYDVQQDExxEaWdpQ2VydCBIaWdoIEFzc3VyYW5jZSBDQS0zMB4XDTEzMDUwMjAwMDAwMFoXDTE2MDcyMDEyMDAwMFowdDELMAkGA1UEBhMCVVMxETAPBgNVBAgTCE5lYnJhc2thMQ4wDAYDVQQHEwVPbWFoYTEaMBgGA1UEChMRSGFydmVzdCBIQ00sIEluYy4xCzAJBgNVBAsTAklUMRkwFwYDVQQDDBAqLkhhcnZlc3RIQ00uY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxjji0FYQGak6fPIxxUlvRSCOVruHIPUlGQpN4acJOo/wZfNpaj7nFkRrQ4c65njH1u9n5U9Md2ACrijR1WmrMPzcCfDktEbUvC6PRDV1MVHxqxSCQTr8jpO/QQHNj+7GxLWTzE9HJW4Y22lFDv068gCCbgLs7C4nNequhUyUmDtBysd1jwui1N4AgYRadrSDt8N7ymRkEIa/5WgWtRzkQP1f2RQTmelE4xqJUrya5hNDGZC9QiSb7lAzLLISS8sL+X/eqQBb7MffeInaNwNihFdljMjwYHd8sKg+qp+daA2PvT7kbhs/UxOi/mBwSG3OKgWjYIBE1c49YgJP/y1WxwIDAQABo4IDVjCCA1IwHwYDVR0jBBgwFoAUUOpzidsp+xCPnuUBINTeeZlIg/cwHQYDVR0OBBYEFL9gCgWFCN4Vil0L9+ZRlu539RYRMCsGA1UdEQQkMCKCECouSGFydmVzdEhDTS5jb22CDkhhcnZlc3RIQ00uY29tMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwYQYDVR0fBFowWDAqoCigJoYkaHR0cDovL2NybDMuZGlnaWNlcnQuY29tL2NhMy1nMjEuY3JsMCqgKKAmhiRodHRwOi8vY3JsNC5kaWdpY2VydC5jb20vY2EzLWcyMS5jcmwwggHEBgNVHSAEggG7MIIBtzCCAbMGCWCGSAGG/WwBATCCAaQwOgYIKwYBBQUHAgEWLmh0dHA6Ly93d3cuZGlnaWNlcnQuY29tL3NzbC1jcHMtcmVwb3NpdG9yeS5odG0wggFkBggrBgEFBQcCAjCCAVYeggFSAEEAbgB5ACAAdQBzAGUAIABvAGYAIAB0AGgAaQBzACAAQwBlAHIAdABpAGYAaQBjAGEAdABlACAAYwBvAG4AcwB0AGkAdAB1AHQAZQBzACAAYQBjAGMAZQBwAHQAYQBuAGMAZQAgAG8AZgAgAHQAaABlACAARABpAGcAaQBDAGUAcgB0ACAAQwBQAC8AQwBQAFMAIABhAG4AZAAgAHQAaABlACAAUgBlAGwAeQBpAG4AZwAgAFAAYQByAHQAeQAgAEEAZwByAGUAZQBtAGUAbgB0ACAAdwBoAGkAYwBoACAAbABpAG0AaQB0ACAAbABpAGEAYgBpAGwAaQB0AHkAIABhAG4AZAAgAGEAcgBlACAAaQBuAGMAbwByAHAAbwByAGEAdABlAGQAIABoAGUAcgBlAGkAbgAgAGIAeQAgAHIAZQBmAGUAcgBlAG4AYwBlAC4wewYIKwYBBQUHAQEEbzBtMCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5kaWdpY2VydC5jb20wRQYIKwYBBQUHMAKGOWh0dHA6Ly9jYWNlcnRzLmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEhpZ2hBc3N1cmFuY2VDQS0zLmNydDAMBgNVHRMBAf8EAjAAMA0GCSqGSIb3DQEBBQUAA4IBAQCfyoPeXkpONswSJkuXVSWT5EgHsRjwCVx9+NkmyQ1qFPal73T4OVdUtV90G9Tws8fN6SBhnBG92GK04YbPAEh1C2kshh3JSYIdKdGaS6rDUidWAAivyIh2htb+boCZ3m/A4lUu45aFwgYfqmSuKOZ/RgqUHDl30A9PuUlQ+gVytBWpWlrRWAx780usmmtATzSeAj4tJAxV2xbJm3kry80Iwl79N/fum7f2c2VCPhJLfHilcQkKz+YrUEldHECWdTabP9FSS6BBim6nNfTTUNyLGkty9Jol+IJgMdD88gqLdLe8AXddOK9LcrNlt0AJsoDfHZBnobRHBGSiuMnpozGR</X509Certificate>
      </X509Data>
    </KeyInfo>
  </Signature>
  <samlp:NameIDPolicy AllowCreate="true" />
</samlp:AuthnRequest>

Here is what I am seeing in the logs (I've turned them up to TRACE):

17:22:37.260 - DEBUG [org.opensaml.xml.signature.SignatureValidator:54] - Attempting to validate signature using key from supplied credential
17:22:37.260 - DEBUG [org.opensaml.xml.signature.SignatureValidator:90] - Creating XMLSignature object
17:22:37.260 - DEBUG [org.opensaml.xml.signature.SignatureValidator:64] - Validating signature with signature algorithm URI: http://www.w3.org/2000/09/xmldsig#rsa-sha1
17:22:37.261 - DEBUG [org.opensaml.xml.signature.SignatureValidator:65] - Validation credential key algorithm 'RSA', key instance class 'sun.security.rsa.RSAPublicKeyImpl'
17:22:37.262 - DEBUG [org.apache.xml.security.utils.DigesterOutputStream:-1] - Pre-digested input:
17:22:37.263 - DEBUG [org.apache.xml.security.utils.DigesterOutputStream:-1] - <samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" AssertionConsumerServiceURL="https://creighton.harvesthcm.com/SSO/AssertionService.aspx?binding=urn%3aoasis%3anames%3atc%3aSAML%3a2.0%3abindings%3aHTTP-POST" Destination="https://auth-test.creighton.edu/idp/profile/SAML2/POST/SSO" ForceAuthn="false" ID="_8528A7E500B99BA8C6DAFC41AC993F36" IsPassive="false" IssueInstant="2013-07-10T22:22:36.722Z" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Version="2.0"><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https://creighton.harvesthcm.com</saml:Issuer><samlp:NameIDPolicy AllowCreate="true"></samlp:NameIDPolicy></samlp:AuthnRequest>

17:22:37.263 - DEBUG [org.opensaml.xml.signature.SignatureValidator:70] - Signature validated with key from supplied credential
17:22:37.263 - DEBUG [org.opensaml.xml.signature.impl.BaseSignatureTrustEngine:148] - Signature validation using candidate credential was successful
17:22:37.263 - DEBUG [org.opensaml.xml.signature.impl.BaseSignatureTrustEngine:101] - Successfully verified signature using KeyInfo-derived credential
17:22:37.264 - DEBUG [org.opensaml.xml.signature.impl.BaseSignatureTrustEngine:102] - Attempting to establish trust of KeyInfo-derived credential
17:22:37.264 - DEBUG [org.opensaml.xml.security.x509.BasicX509CredentialNameEvaluator:220] - Supplied trusted names are null or empty, skipping name evaluation
17:22:37.264 - DEBUG [org.opensaml.xml.signature.impl.PKIXSignatureTrustEngine:229] - Signature trust could not be established via PKIX validation of signing credential
17:22:37.265 - DEBUG [org.opensaml.xml.signature.impl.BaseSignatureTrustEngine:107] - Failed to establish trust of KeyInfo-derived credential
17:22:37.265 - DEBUG [org.opensaml.xml.signature.impl.BaseSignatureTrustEngine:115] - Failed to verify signature and/or establish trust using any KeyInfo-derived credentials
17:22:37.265 - DEBUG [org.opensaml.xml.signature.impl.PKIXSignatureTrustEngine:162] - PKIX validation of signature failed, unable to resolve valid and trusted signing key
17:22:37.265 - DEBUG [org.opensaml.common.binding.security.SAMLProtocolMessageXMLSignatureSecurityPolicyRule:136] - Validation of protocol message signature failed for context issuer 'https://creighton.harvesthcm.com', message type: {urn:oasis:names:tc:SAML:2.0:protocol}AuthnRequest
17:22:37.277 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:379] - Message did not meet security requirements

sha1(

Adam Schumacher [CISSP] [MS] [MBA]
Information Security Engineer
Creighton University

Don't share your password with ANYONE, EVER.  This means YOU!

402-280-2383
402-672-1732

)

= e50d1557b6a49879f7949666c8806ca56c5fde8d




More information about the users mailing list