Help ? Non-federation, custom meta-data ?

Robert Roll Robert.Roll at utah.edu
Thu Jul 18 13:55:38 EDT 2013


 At the bottom is the actual meta-data they sent me.
Note that there seems be something related to signatures
after the <ns0:EntitiesDescriptor....> 

 I actually removed this
as it wasn't actually within the <nso:EntityDescriptor..> ??
(I also removed all of the ns1: and ns0: tags ..)

but again, what seems weird to me is that with the logs there are messages such as:

         Forcing on-demand metadata provider refresh if necessary

and at the beginning of the transaction there appears the following that looks kind
of like some signature meta-data being sent from HireVue? Again, I'm kind of confused ?



10:34:19.976 - DEBUG [PROTOCOL_MESSAGE:113] - 
<?xml version="1.0" encoding="UTF-8"?><ns0:AuthnRequest xmlns:ns0="urn:oasis:names:tc:SAML:2.0:protocol" Destination="https://testidp.acs.utah.edu/idp/profile/SAML2/POST/SSO" ID="id-2932874784652d36
cb7eb853551c0471" IssueInstant="2013-07-18T16:34:14Z" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Version="2.0" xmlns:ns1="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:ns2="http
://www.w3.org/2000/09/xmldsig#">
   <ns1:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">urn:federation:hirevue.com:saml:sp:staging</ns1:Issuer>
   <ns2:Signature Id="Signature1">
      <ns2:SignedInfo>
         <ns2:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
         <ns2:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
         <ns2:Reference URI="#id-2932874784652d36cb7eb853551c0471">
            <ns2:Transforms>
               <ns2:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
               <ns2:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
            </ns2:Transforms>
            <ns2:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
            <ns2:DigestValue>Ia5DC4IjkelCafqy3xBU8A/w/nE=</ns2:DigestValue>
         </ns2:Reference>
      </ns2:SignedInfo>
      <ns2:SignatureValue>ik+4ybIJA/gNeNL5Xtv6oqxJsSRLK+rzEk5JPblMQfC7xGPQ3GOT+cJHDxkIHU2Y
/PfP80zvtB/t89fItUN9Hs0p738p2siXTcDc26t1K9oEnRpYEirzVIBHEZ/DJTib
+UveA4afVzkSB/0YuRRNLLVcVVmrUfc28GnBA/nREgZatCcSEbxDPIDPlon79K9k
4J1InI6sr43UTv+bxT+qcvdMk13ags+X/Bfo5moBQ+Jcylp/FYOWkwbt3BYkoizE
JH315+OkruiREWDpMK2eNFPqSxlEXrWbqyEazmdNav67o1fjYrj/RspOyBbJy0Bz
6fqJAWj6jsv64RhhowtNLw==</ns2:SignatureValue>
      <ns2:KeyInfo>
         <ns2:X509Data>
            <ns2:X509Certificate>MIIDtTCCAp2gAwIBAgIJALp4unzXVm/zMA0GCSqGSIb3DQEBBQUAMHExCzAJBgNVBAYTAlVTMQ0wCwYDVQQIDARVdGFoMRUwEwYDVQQHDAxTb3V0aCBKb3JkYW4xFjAUBgNVBAoMDUhpcmVWdWUsIEluYy4xJDAiBgNVB
AMMG2ZlZGVyYXRlZHNlY3VyaXR5LnN0Z2h2LmNvbTAeFw0xMzA2MjYyMDUwMDdaFw0xNDA2MjYyMDUwMDdaMHExCzAJBgNVBAYTAlVTMQ0wCwYDVQQIDARVdGFoMRUwEwYDVQQHDAxTb3V0aCBKb3JkYW4xFjAUBgNVBAoMDUhpcmVWdWUsIEluYy4xJDAiBgNVBAM
MG2ZlZGVyYXRlZHNlY3VyaXR5LnN0Z2h2LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKHNUAOmnf48gu5Ddvsf7H139aL8fXUdMwtTu6I9qqJ8EUL2reITBPN2SPLLo9EoR2oIlPGJWgpp3CJUruN/PHH1orqWFnUb7Uq+zvoAXAXKIjbtJ62tx
pt1PDBpMjwR50xGcvPAX3Vjp9sHFT3qoN8zb15AOIKN6QWkQQx2vLYUpnegC3yLYen1u13U7ANzfome8obbtORFrk+g60+gHtMvXQxsXir5CEu18KoH0gzY/MAJgnkOYzyjD8QKAqeoxoDOMmZ1E9ADSom4dJr7k4qqwGsZJ0j684DhM53TF7pqncy7llOdoQNZysM
KhBid/jFSsEtqPsYoo6cvsdCJHJECAwEAAaNQME4wHQYDVR0OBBYEFIktxReDKfdxzVQZK97Pw2az1aXVMB8GA1UdIwQYMBaAFIktxReDKfdxzVQZK97Pw2az1aXVMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEFBQADggEBADtd5MIW/xsqyiY7cgrBQYLpPKSNd
Rhz6m76xjhPc1HCvcnAl0gYhBXwR7PZ78SXnK7/CUxf0xNl6t3U448o9uqBdvvrpiQHDCw4WeBeENdlxK5kixM33+QxvidzE77cf2hrBMhbmgfg0mQDUuZLQVnYnU7OFs162OpRXurVEsHl19jHRNGNSNhiNwln8NdPC6HomDie8zFgTfeycSzESbcudmzSMmivpu1
G9YK/YOz25WAZ1HPSo4wcgNN0mm4z+v6cbqIF4uRC8XaxTDYa4N8k5ksZny0xaOkGSb+MJZxYIu6V0QTL43eoxXrB9H4URnTnie4NFYT7Lv86HDW5DbY=</ns2:X509Certificate>
         </ns2:X509Data>
      </ns2:KeyInfo>
   </ns2:Signature>


Thanks,


Robert
   
 **** Meta-data sent (out of band) by HireVue.. *****

<?xml version="1.0" encoding="UTF-8"?>

<ns0:EntitiesDescriptor xmlns:ns0="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ns1="http://www.w3.org/2000/09/xmldsig#" ID="id-ec9ca1499547ebd6305ad08d88e0ba1b" validUntil="2013-07-25T22:14:37Z">

<ns1:Signature Id="Signature1">
<ns1:SignedInfo>
<ns1:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
<ns1:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
<ns1:Reference URI="#id-ec9ca1499547ebd6305ad08d88e0ba1b">
<ns1:Transforms>
  <ns1:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
  <ns1:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
</ns1:Transforms>
<ns1:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
<ns1:DigestValue>9mRewMR7erhQTSrSsBJfZFAJHm8=
</ns1:DigestValue>
</ns1:Reference>
</ns1:SignedInfo>
<ns1:SignatureValue>
LI7g2NJcxtUfBOY8v1XV7tM+UockvUtKhLtJ+OvyU6p4pMmWVQg+XcpzMSUGfU6F
xe/s4+5qery/tlEnSD73sWUfmZQb/TlT4oneHf24E2HOM2eOyx9P3YI+s0ipJiph
xPOF7ZuQI9rtXW1LzSz7mOYSsslgYZ9hG4Gf/H4nVBTO9r/cyIBY2/0FvP1umarb
STQks310T6D4uEA6nq3g85+1iCgApSfaGfuXlScvqdmMP0fEB/W0rpIAfKsEb/Pb
Ou7YIAbLV4hxww8yV5aVNikEJd8DXkaYSfRyw30zHdA0idL7+6oiOpPq13estLlk
amZOCPxC2runZjh3krPncQ==
</ns1:SignatureValue>
<ns1:KeyInfo>
<ns1:X509Data>
<ns1:X509Certificate>
MIIDtTCCAp2gAwIBAgIJALp4unzXVm/zMA0GCSqGSIb3DQEBBQUAMHExCzAJBgNVBAYTAlVTMQ0wCwYDVQQIDARVdGFoMRUwEwYDVQQHDAxTb3V0aCBKb3JkYW4xFjAUBgNVBAoMDUhpcmVWdWUsIEluYy4xJDAiBgNVBAMMG2ZlZGVyYXRlZHNlY3VyaXR5LnN0Z2
h2LmNvbTAeFw0xMzA2MjYyMDUwMDdaFw0xNDA2MjYyMDUwMDdaMHExCzAJBgNVBAYTAlVTMQ0wCwYDVQQIDARVdGFoMRUwEwYDVQQHDAxTb3V0aCBKb3JkYW4xFjAUBgNVBAoMDUhpcmVWdWUsIEluYy4xJDAiBgNVBAMMG2ZlZGVyYXRlZHNlY3VyaXR5LnN0Z2h2
LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKHNUAOmnf48gu5Ddvsf7H139aL8fXUdMwtTu6I9qqJ8EUL2reITBPN2SPLLo9EoR2oIlPGJWgpp3CJUruN/PHH1orqWFnUb7Uq+zvoAXAXKIjbtJ62txpt1PDBpMjwR50xGcvPAX3Vjp9sHFT3qoN
8zb15AOIKN6QWkQQx2vLYUpnegC3yLYen1u13U7ANzfome8obbtORFrk+g60+gHtMvXQxsXir5CEu18KoH0gzY/MAJgnkOYzyjD8QKAqeoxoDOMmZ1E9ADSom4dJr7k4qqwGsZJ0j684DhM53TF7pqncy7llOdoQNZysMKhBid/jFSsEtqPsYoo6cvsdCJHJECAwEA
AaNQME4wHQYDVR0OBBYEFIktxReDKfdxzVQZK97Pw2az1aXVMB8GA1UdIwQYMBaAFIktxReDKfdxzVQZK97Pw2az1aXVMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEFBQADggEBADtd5MIW/xsqyiY7cgrBQYLpPKSNdRhz6m76xjhPc1HCvcnAl0gYhBXwR7PZ78
SXnK7/CUxf0xNl6t3U448o9uqBdvvrpiQHDCw4WeBeENdlxK5kixM33+QxvidzE77cf2hrBMhbmgfg0mQDUuZLQVnYnU7OFs162OpRXurVEsHl19jHRNGNSNhiNwln8NdPC6HomDie8zFgTfeycSzESbcudmzSMmivpu1G9YK/YOz25WAZ1HPSo4wcgNN0mm4z+v6c
bqIF4uRC8XaxTDYa4N8k5ksZny0xaOkGSb+MJZxYIu6V0QTL43eoxXrB9H4URnTnie4NFYT7Lv86HDW5DbY=
</ns1:X509Certificate>
</ns1:X509Data>
</ns1:KeyInfo>
</ns1:Signature>

<ns0:EntityDescriptor entityID="urn:federation:hirevue.com:saml:sp:staging">
<ns0:SPSSODescriptor AuthnRequestsSigned="true" WantAssertionsSigned="true" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<ns0:KeyDescriptor use="signing">
<ns1:KeyInfo>
<ns1:X509Data>
<ns1:X509Certificate>
MIIDtTCCAp2gAwIBAgIJALp4unzXVm/zMA0GCSqGSIb3DQEBBQUAMHExCzAJBgNV
BAYTAlVTMQ0wCwYDVQQIDARVdGFoMRUwEwYDVQQHDAxTb3V0aCBKb3JkYW4xFjAU
BgNVBAoMDUhpcmVWdWUsIEluYy4xJDAiBgNVBAMMG2ZlZGVyYXRlZHNlY3VyaXR5
LnN0Z2h2LmNvbTAeFw0xMzA2MjYyMDUwMDdaFw0xNDA2MjYyMDUwMDdaMHExCzAJ
BgNVBAYTAlVTMQ0wCwYDVQQIDARVdGFoMRUwEwYDVQQHDAxTb3V0aCBKb3JkYW4x
FjAUBgNVBAoMDUhpcmVWdWUsIEluYy4xJDAiBgNVBAMMG2ZlZGVyYXRlZHNlY3Vy
aXR5LnN0Z2h2LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKHN
UAOmnf48gu5Ddvsf7H139aL8fXUdMwtTu6I9qqJ8EUL2reITBPN2SPLLo9EoR2oI
lPGJWgpp3CJUruN/PHH1orqWFnUb7Uq+zvoAXAXKIjbtJ62txpt1PDBpMjwR50xG
cvPAX3Vjp9sHFT3qoN8zb15AOIKN6QWkQQx2vLYUpnegC3yLYen1u13U7ANzfome
8obbtORFrk+g60+gHtMvXQxsXir5CEu18KoH0gzY/MAJgnkOYzyjD8QKAqeoxoDO
MmZ1E9ADSom4dJr7k4qqwGsZJ0j684DhM53TF7pqncy7llOdoQNZysMKhBid/jFS
sEtqPsYoo6cvsdCJHJECAwEAAaNQME4wHQYDVR0OBBYEFIktxReDKfdxzVQZK97P
w2az1aXVMB8GA1UdIwQYMBaAFIktxReDKfdxzVQZK97Pw2az1aXVMAwGA1UdEwQF
MAMBAf8wDQYJKoZIhvcNAQEFBQADggEBADtd5MIW/xsqyiY7cgrBQYLpPKSNdRhz
6m76xjhPc1HCvcnAl0gYhBXwR7PZ78SXnK7/CUxf0xNl6t3U448o9uqBdvvrpiQH
DCw4WeBeENdlxK5kixM33+QxvidzE77cf2hrBMhbmgfg0mQDUuZLQVnYnU7OFs16
2OpRXurVEsHl19jHRNGNSNhiNwln8NdPC6HomDie8zFgTfeycSzESbcudmzSMmiv
pu1G9YK/YOz25WAZ1HPSo4wcgNN0mm4z+v6cbqIF4uRC8XaxTDYa4N8k5ksZny0x
aOkGSb+MJZxYIu6V0QTL43eoxXrB9H4URnTnie4NFYT7Lv86HDW5DbY=
</ns1:X509Certificate>
</ns1:X509Data>
</ns1:KeyInfo>
</ns0:KeyDescriptor>
<ns0:NameIDFormat>
 urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
</ns0:NameIDFormat>
<ns0:NameIDFormat>
urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
</ns0:NameIDFormat>
<ns0:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://uuhc.stghv.com/integrations/saml2/acs/" index="1"/>
<ns0:AttributeConsumingService index="1" isDefault="true">
<ns0:ServiceName xml:lang="en">SSO Attributes
</ns0:ServiceName><ns0:RequestedAttribute FriendlyName="sn" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<ns0:RequestedAttribute FriendlyName="givenname" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
</ns0:AttributeConsumingService>
</ns0:SPSSODescriptor>
</ns0:EntityDescriptor>

</ns0:EntitiesDescriptor>

________________________________________
From: users-bounces at shibboleth.net [users-bounces at shibboleth.net] on behalf of Cantor, Scott [cantor.2 at osu.edu]
Sent: Thursday, July 18, 2013 11:28 AM
To: Shib Users
Subject: RE: Help ? Non-federation, custom meta-data ?

> We have a new SAS Service provider HireVue. They seem to be able to do
> either SP initiated or IDP initiated login.
> I managed to get their meta-data to seem to work for the IDP initiated login,
> but the SP initiated is pretty confusing
> to me.. It looks like it tries to add meta-data on the fly ?

I doubt they even use metadata, so I'm not sure what you mean by that.

> In any case I get the
> following error:
>
>  Message did not meet security requirements
> org.opensaml.ws.security.SecurityPolicyException: Validation of protocol
> message signature failed

That just means they signed the request (which is unnecessary in most cases) and the metadata you loaded didn't contain the proper key.

If you weren't encrypting anything in the IdP-initiated case, then the metadata you loaded wouldn't have had to contain a key for them at all, which would explain why it doesn't work in the other case.

-- Scott


--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list