SP-specific failure to generate 'good' SAML assertion
David Bantz
dabantz at alaska.edu
Tue Nov 12 20:25:27 EST 2013
On Tue, 12 Nov 2013, at 15:24 , Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 11/12/13, 4:07 PM, "David Bantz" <dabantz at alaska.edu> wrote:
>
>> While a value of transientId is created and among those filtered for
>> release to the appropriate end point, it is not included in the SAML
>> assertion, with the following debug message:
>
> If it weren't being included, you'd still get the same error as before.
> Are you?
Not the same SAML, no.
The SAML in the log before adding transientId release was:
10:03:53.154 - DEBUG [PROTOCOL_MESSAGE:74] -
<?xml version="1.0" encoding="UTF-8"?><saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="https://www.fuzemeeting.com/fuze/saml_verify/alaskaedu" ID="_d4e8bfd0abb3f317c3118c6c6ae5b687" InResponseTo="id-1fa5a56e5e1d2231ef97d750c8adce1a" IssueInstant="2013-11-12T19:03:53.137Z" Version="2.0">
<saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">urn:mace:incommon:alaska.edu</saml2:Issuer>
<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
<ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
<ds:Reference URI="#_d4e8bfd0abb3f317c3118c6c6ae5b687">
<ds:Transforms>
<ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
</ds:Transforms>
<ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
<ds:DigestValue>JfS1I36EYVMD150rFhQCabfhWiw=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>tich/3vqKBzxBAeft7vmFfm2DnBE3x6v38gS4duzG8kL/LyBElBfrq/qOu7Q4l18DS4XUIV/7L7bVNcczIBNaJHrz6hRLnonBsilnGJmLB+4ttUN8dnqtTLikysNa34A9RbeCHM+If5G11NKJeqT+Bubb74h1g/hM5N4Tp8AjtCjtYyYfKuFzan9U/ytsFf82iC2++QWzR7GbvpGyz7CwEUDo1gXDsN8mLAC3krkagF4OKBsMdliMDhwBhy8D4Pq7GvXi7gjFBSalxti45Wv3f8pvmcIgd/+76+74GHBxxqdJ1r2DrA4u8O6cFhUKRg2VLg4jZ6hQMSXAo6ZRgyG0g==</ds:SignatureValue>
<ds:KeyInfo>
<ds:X509Data>
<ds:...</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</ds:Signature>
<saml2p:Status>
<saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Responder">
<saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:InvalidNameIDPolicy"/>
</saml2p:StatusCode>
<saml2p:StatusMessage>Required NameID format not supported</saml2p:StatusMessage>
</saml2p:Status>
</saml2p:Response>
The SAML after adding transientId release is:
14:20:48.672 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:279] - Assertion to be encrypted is:
<?xml version="1.0" encoding="UTF-8"?><saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_defa5f0f8eaeec6de100a6c7c932cb54" IssueInstant="2013-11-12T23:20:48.629Z" Version="2.0" xmlns:xs="http://www.w3.org/2001/XMLSchema">
<saml2:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">urn:mace:incommon:alaska.edu</saml2:Issuer>
<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
<ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
<ds:Reference URI="#_defa5f0f8eaeec6de100a6c7c932cb54">
<ds:Transforms>
<ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#">
<ec:InclusiveNamespaces xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="xs"/>
</ds:Transform>
</ds:Transforms>
<ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
<ds:DigestValue>3ltHq0ozJFiEFtAgUZtvdMu7h3U=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>kFYEqeQ6CLw84dFSSsqWRY9up/JfWi5MG7gONW1q2jrzohnRWHXghb2vtgtBW9KWWwXUDmysJKk32xGEjrGppUCnyzpMQKmJKdiGRqv/ew5FzrVv1SJf6p7OcsqaCMHMrU21FO6fChgGHz3vPqnKTOtqIEGV+3kyupFXxszaWq/FJuioUoLVmeefsszdgkAzig60u/+/WOZ7sKfsPmUSvAFrNaOwi+E1Pgjr6Xy4rH+lj3YMmkQy1vjMDA1eKQ+wOsr8Au1fVUI3I5dZEXmDEYIYxLKXjN/XHn5C2wm7HDtUbmwkqLX4mJjOK2rHsrPmFOtAMXpFAmmzLgMJ0qGGQw==</ds:SignatureValue>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>...</ds:X509Data>
</ds:KeyInfo>
</ds:Signature>
<saml2:Subject>
<saml2:EncryptedID>
<xenc:EncryptedData xmlns:xenc="http://www.w3.org/2001/04/xmlenc#" Id="_dbc9704db7de310cb15c256292cfb5a9" Type="http://www.w3.org/2001/04/xmlenc#Element">
<xenc:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc" xmlns:xenc="http://www.w3.org/2001/04/xmlenc#"/>
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<xenc:EncryptedKey Id="_361ea1828ca82e2b3a7d3cc85e94ef85" xmlns:xenc="http://www.w3.org/2001/04/xmlenc#">
<xenc:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p" xmlns:xenc="http://www.w3.org/2001/04/xmlenc#">
<ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1" xmlns:ds="http://www.w3.org/2000/09/xmldsig#"/>
</xenc:EncryptionMethod>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>... </ds:X509Data>
</ds:KeyInfo>
<xenc:CipherData xmlns:xenc="http://www.w3.org/2001/04/xmlenc#">
<xenc:CipherValue>hiMVge6QdcbeEXq94IZ+6VrWB6/XnRke0/7AODvUqaQlf0XvfroV1mOqmrLAMRsTLUjnxI8YKlzspE6g4qxjW5W11+aU5QzhJqlyASGGZWRxlO9tnBXsNL8bo/JRCOLBIE0xpTXSRpUomYD7UQv4111rfxCoSAyOmJGM03Gy8lU=</xenc:CipherValue>
</xenc:CipherData>
</xenc:EncryptedKey>
</ds:KeyInfo>
<xenc:CipherData xmlns:xenc="http://www.w3.org/2001/04/xmlenc#”>
<xenc:CipherValue>…..</xenc:CipherValue>
</xenc:CipherData>
</xenc:EncryptedData>
</saml2:EncryptedID>
<saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
<saml2:SubjectConfirmationData Address="137.229.12.164" InResponseTo="id-f6ea64e95fbae2638f2c975fa6b29809" NotOnOrAfter="2013-11-12T23:25:48.629Z" Recipient="https://www.fuzemeeting.com/fuze/saml_verify/alaskaedu"/>
</saml2:SubjectConfirmation>
</saml2:Subject>
<saml2:Conditions NotBefore="2013-11-12T23:20:48.629Z" NotOnOrAfter="2013-11-12T23:25:48.629Z">
<saml2:AudienceRestriction>
<saml2:Audience>www.fuzemeeting.com</saml2:Audience>
</saml2:AudienceRestriction>
</saml2:Conditions>
<saml2:AuthnStatement AuthnInstant="2013-11-12T23:20:47.778Z" SessionIndex="554538ed7e12b0fc733eedbb277bfc4060c7d1d81686b42727b12bb1aa54ea8c">
<saml2:SubjectLocality Address="137.229.12.164"/>
<saml2:AuthnContext>
<saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef>
</saml2:AuthnContext>
</saml2:AuthnStatement>
<saml2:AttributeStatement>
<saml2:Attribute FriendlyName="sn" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">Bantz</saml2:AttributeValue>
</saml2:Attribute>
<saml2:Attribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">Q at alaska.edu</saml2:AttributeValue>
<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">db at alaska.edu</saml2:AttributeValue>
</saml2:Attribute>
<saml2:Attribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">dabantz at alaska.edu</saml2:AttributeValue>
</saml2:Attribute>
<saml2:Attribute FriendlyName="givenName" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">David</saml2:AttributeValue>
</saml2:Attribute>
</saml2:AttributeStatement>
</saml2:Assertion>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131112/c6af45a2/attachment-0001.html
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 163 bytes
Desc: Message signed with OpenPGP using GPGMail
Url : http://shibboleth.net/pipermail/users/attachments/20131112/c6af45a2/attachment-0001.bin
More information about the users
mailing list