Wrong KeyInfo in ArtifactResponse from IdP causing SSO to fail
Farrukh Najmi
farrukh at wellfleetsoftware.com
Thu May 23 10:50:52 EDT 2013
Hi Guys,
I was successfully getting Web SSO to work between my
spring-security-saml2 based SP and Shib 2.4.0 IdP. I was elated!
Then I am not sure what I changed that started Web SSO to fail right
after I entered credentials on Idp's login.jsp page.
Looking at logs the problem was a signature validation error on the SP
side when processing a <saml2p:ArtifactResponse> issued by the IdP.
Then looking at the Idp side logged protocol message I notice that the
KeyInfo in the *ArtifactResponse* message is for the key used by my SP
to earlier send the corresponding *ArtifactResolve* request message.
Should the IdP *ArtifactResponse* message not be using the KeyInfo for
the IdP's key instead of the KeyInfo of the SP's key?
What could cause this mixup in my configuration?
What follows is relevant parts of SP and IdP stack traces and log messages.
Thanks very much for any advice.
---------------------------Begin SP side trace --------------------------
INFO: 10:01:16,576 DEBUG SignatureValidator:77 - Signature did not
validate against the credential's key
INFO: 10:01:16,577 DEBUG BaseSignatureTrustEngine:144 - Signature
validation using candidate validation credential failed
org.opensaml.xml.validation.ValidationException: Signature did not
validate against the credential's key
at
org.opensaml.xml.signature.SignatureValidator.validate(SignatureValidator.java:79)
at
org.opensaml.xml.signature.impl.BaseSignatureTrustEngine.verifySignature(BaseSignatureTrustEngine.java:142)
at
org.opensaml.xml.signature.impl.ExplicitKeySignatureTrustEngine.validate(ExplicitKeySignatureTrustEngine.java:110)
at
org.opensaml.xml.signature.impl.ExplicitKeySignatureTrustEngine.validate(ExplicitKeySignatureTrustEngine.java:49)
at
org.springframework.security.saml.websso.AbstractProfileBase.verifySignature(AbstractProfileBase.java:271)
at
org.springframework.security.saml.websso.WebSSOProfileConsumerImpl.verifyAssertionSignature(WebSSOProfileConsumerImpl.java:416)
at
org.springframework.security.saml.websso.WebSSOProfileConsumerImpl.verifyAssertion(WebSSOProfileConsumerImpl.java:287)
at
org.springframework.security.saml.websso.WebSSOProfileConsumerImpl.processAuthenticationResponse(WebSSOProfileConsumerImpl.java:204)
at
org.springframework.security.saml.SAMLAuthenticationProvider.authenticate(SAMLAuthenticationProvider.java:81)
at
org.springframework.security.authentication.ProviderManager.authenticate(ProviderManager.java:156)
...
INFO: 10:01:16,578 DEBUG ExplicitKeySignatureTrustEngine:115 - Failed to
verify signature using either KeyInfo-derived or directly trusted
credentials
---------------------------End SP side trace --------------------------
-----------------------Begin *ArtifactResolve* request message in IdP
--------------------------
<?xml version="1.0" encoding="UTF-8"?><soap11:Envelope
xmlns:soap11="http://schemas.xmlsoap.org/soap/envelope/">
<soap11:Body>
<saml2p:ArtifactResolve
xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"
Destination="https://wellfleet1.wellfleetsoftware.
com:9443/idp/profile/SAML2/SOAP/ArtifactResolution"
ID="a4jd9a3fceg3e34g2a672dadf06aa3j"
IssueInstant="2013-05-23T14:01:16.118Z" Ver
sion="2.0">
<saml2:Issuer
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">urn:wellfleetsoftware:wellgeo-regrep</saml2:Issuer>
<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo>
<ds:CanonicalizationMethod
Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
<ds:SignatureMethod
Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
<ds:Reference URI="#a4jd9a3fceg3e34g2a672dadf06aa3j">
<ds:Transforms>
<ds:Transform
Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<ds:Transform
Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
</ds:Transforms>
<ds:DigestMethod
Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
<ds:DigestValue>8t6ByS9NYUFwk500JlT2dqOkBsY=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>OWtHzd6PdJbcEbYGWJhlTjsDwg7eJRRPZj8cUCEGedaTineVDU3qt8zYFQZPnMy1xuodgjZbmEpIE03/W+E5i96vA6LWI8AkNHPiH
ImeeT79JbMXvo10dHwmHGlYMLGP6EBRaWUY9NFG2L6YZEnC6VtLfFIe5ublT+CyFQmpb/nhvnSCcu+94ytUg6Q8ErkFO+huA1vlrrHfvqymd64+wv3FqL2sVQVhvoPDfUfZv
9IuFdopX81eHCej9ai6IaL9/fXyAQDJxhWSrpy7YF5N3RQQW5fS73l06pg0nmNmb61w+FqpdS12BENA//oeumZN6d+CD6SjsqvzAh22qouyBg==</ds:SignatureValue>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>*MIIDUjCCAj....*</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
....
-----------------------End *ArtifactResolve* request message in IdP
--------------------------
-----------------------Begin *ArtifactResponse* message in IdP
--------------------------
<?xml version="1.0" encoding="UTF-8"?><soap11:Envelope
xmlns:soap11="http://schemas.xmlsoap.org/soap/envelope/">
<soap11:Body>
<saml2p:ArtifactResponse
xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"
ID="_627a6951cf8c38ea13b755b8e033077a"
InResponseTo="a4jd9a3fceg3e34g2a672dadf06aa3j"
IssueInstant="2013-05-23T14:01:16.292Z" Version="2.0">
<saml2:Issuer
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">https://wellfleet1.wellfleetsoftware.com:9443/idp/shibboleth</saml2:Issuer>
<saml2p:Status>
<saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
</saml2p:Status>
<saml2p:Response ID="_eea41e50eb8b66c688d618c949343b43"
InResponseTo="a2aj02h8c03i8idg3g3f09c762668c5"
IssueInstant="2013-05-23T14:01:15.917Z" Version="2.0">
<saml2:Issuer
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">https://wellfleet1.wellfleetsoftware.com:9443/idp/shibboleth</saml2:Issuer>
<saml2p:Status>
<saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
</saml2p:Status>
<saml2:EncryptedAssertion
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">
<xenc:EncryptedData
xmlns:xenc="http://www.w3.org/2001/04/xmlenc#"
Id="_24afbdf7a315e9502d568bce606a2496"
Type="http://www.w3.org/2001/04/xmlenc#Element">
<xenc:EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"
xmlns:xenc="http://www.w3.org/2001/04/xmlenc#"/>
<ds:KeyInfo
xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<xenc:EncryptedKey
Id="_6a58851feaaef986005b7e4a4dd86022"
xmlns:xenc="http://www.w3.org/2001/04/xmlenc#">
<xenc:EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"
xmlns:xenc="http://www.w3.org/2001/04/xmlenc#">
<ds:DigestMethod
Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"
xmlns:ds="http://www.w3.org/2000/09/xmldsig#"/>
</xenc:EncryptionMethod>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>*MIIDUjCCAj....*</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
-----------------------End *ArtifactResponse* message in IdP
--------------------------
--
Regards,
Farrukh Najmi
Web: http://www.wellfleetsoftware.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130523/841b9ccf/attachment-0001.html
More information about the users
mailing list