SP-specific failure to generate 'good' SAML assertion

David Bantz dabantz at alaska.edu
Tue Nov 12 20:25:27 EST 2013


On Tue, 12 Nov 2013, at 15:24 , Cantor, Scott <cantor.2 at osu.edu> wrote:

> On 11/12/13, 4:07 PM, "David Bantz" <dabantz at alaska.edu> wrote:
> 
>> While a value of transientId is created and among those filtered for
>> release to the appropriate end point, it is not included in the SAML
>> assertion, with the following debug message:
> 
> If it weren't being included, you'd still get the same error as before.
> Are you?

Not the same SAML, no.

The SAML in the log before adding transientId release was:

10:03:53.154 - DEBUG [PROTOCOL_MESSAGE:74] - 
<?xml version="1.0" encoding="UTF-8"?><saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="https://www.fuzemeeting.com/fuze/saml_verify/alaskaedu" ID="_d4e8bfd0abb3f317c3118c6c6ae5b687" InResponseTo="id-1fa5a56e5e1d2231ef97d750c8adce1a" IssueInstant="2013-11-12T19:03:53.137Z" Version="2.0">
   <saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">urn:mace:incommon:alaska.edu</saml2:Issuer>
   <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
      <ds:SignedInfo>
         <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
         <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
         <ds:Reference URI="#_d4e8bfd0abb3f317c3118c6c6ae5b687">
            <ds:Transforms>
               <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
               <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
            </ds:Transforms>
            <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
            <ds:DigestValue>JfS1I36EYVMD150rFhQCabfhWiw=</ds:DigestValue>
         </ds:Reference>
      </ds:SignedInfo>
      <ds:SignatureValue>tich/3vqKBzxBAeft7vmFfm2DnBE3x6v38gS4duzG8kL/LyBElBfrq/qOu7Q4l18DS4XUIV/7L7bVNcczIBNaJHrz6hRLnonBsilnGJmLB+4ttUN8dnqtTLikysNa34A9RbeCHM+If5G11NKJeqT+Bubb74h1g/hM5N4Tp8AjtCjtYyYfKuFzan9U/ytsFf82iC2++QWzR7GbvpGyz7CwEUDo1gXDsN8mLAC3krkagF4OKBsMdliMDhwBhy8D4Pq7GvXi7gjFBSalxti45Wv3f8pvmcIgd/+76+74GHBxxqdJ1r2DrA4u8O6cFhUKRg2VLg4jZ6hQMSXAo6ZRgyG0g==</ds:SignatureValue>
      <ds:KeyInfo>
         <ds:X509Data>
            <ds:...</ds:X509Certificate>
         </ds:X509Data>
      </ds:KeyInfo>
   </ds:Signature>
   <saml2p:Status>
      <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Responder">
         <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:InvalidNameIDPolicy"/>
      </saml2p:StatusCode>
      <saml2p:StatusMessage>Required NameID format not supported</saml2p:StatusMessage>
   </saml2p:Status>
</saml2p:Response>


The SAML after adding transientId release is:

14:20:48.672 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:279] - Assertion to be encrypted is:
<?xml version="1.0" encoding="UTF-8"?><saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_defa5f0f8eaeec6de100a6c7c932cb54" IssueInstant="2013-11-12T23:20:48.629Z" Version="2.0" xmlns:xs="http://www.w3.org/2001/XMLSchema">
   <saml2:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">urn:mace:incommon:alaska.edu</saml2:Issuer>
   <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
      <ds:SignedInfo>
         <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
         <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
         <ds:Reference URI="#_defa5f0f8eaeec6de100a6c7c932cb54">
            <ds:Transforms>
               <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
               <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#">
                  <ec:InclusiveNamespaces xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="xs"/>
               </ds:Transform>
            </ds:Transforms>
            <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
            <ds:DigestValue>3ltHq0ozJFiEFtAgUZtvdMu7h3U=</ds:DigestValue>
         </ds:Reference>
      </ds:SignedInfo>
      <ds:SignatureValue>kFYEqeQ6CLw84dFSSsqWRY9up/JfWi5MG7gONW1q2jrzohnRWHXghb2vtgtBW9KWWwXUDmysJKk32xGEjrGppUCnyzpMQKmJKdiGRqv/ew5FzrVv1SJf6p7OcsqaCMHMrU21FO6fChgGHz3vPqnKTOtqIEGV+3kyupFXxszaWq/FJuioUoLVmeefsszdgkAzig60u/+/WOZ7sKfsPmUSvAFrNaOwi+E1Pgjr6Xy4rH+lj3YMmkQy1vjMDA1eKQ+wOsr8Au1fVUI3I5dZEXmDEYIYxLKXjN/XHn5C2wm7HDtUbmwkqLX4mJjOK2rHsrPmFOtAMXpFAmmzLgMJ0qGGQw==</ds:SignatureValue>
      <ds:KeyInfo>
         <ds:X509Data>
            <ds:X509Certificate>...</ds:X509Data>
      </ds:KeyInfo>
   </ds:Signature>
   <saml2:Subject>
      <saml2:EncryptedID>
         <xenc:EncryptedData xmlns:xenc="http://www.w3.org/2001/04/xmlenc#" Id="_dbc9704db7de310cb15c256292cfb5a9" Type="http://www.w3.org/2001/04/xmlenc#Element">
            <xenc:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc" xmlns:xenc="http://www.w3.org/2001/04/xmlenc#"/>
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
               <xenc:EncryptedKey Id="_361ea1828ca82e2b3a7d3cc85e94ef85" xmlns:xenc="http://www.w3.org/2001/04/xmlenc#">
                  <xenc:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p" xmlns:xenc="http://www.w3.org/2001/04/xmlenc#">
                     <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1" xmlns:ds="http://www.w3.org/2000/09/xmldsig#"/>
                  </xenc:EncryptionMethod>
                  <ds:KeyInfo>
                     <ds:X509Data>
                        <ds:X509Certificate>... </ds:X509Data>
                  </ds:KeyInfo>
                  <xenc:CipherData xmlns:xenc="http://www.w3.org/2001/04/xmlenc#">
                     <xenc:CipherValue>hiMVge6QdcbeEXq94IZ+6VrWB6/XnRke0/7AODvUqaQlf0XvfroV1mOqmrLAMRsTLUjnxI8YKlzspE6g4qxjW5W11+aU5QzhJqlyASGGZWRxlO9tnBXsNL8bo/JRCOLBIE0xpTXSRpUomYD7UQv4111rfxCoSAyOmJGM03Gy8lU=</xenc:CipherValue>
                  </xenc:CipherData>
               </xenc:EncryptedKey>
            </ds:KeyInfo>
            <xenc:CipherData xmlns:xenc="http://www.w3.org/2001/04/xmlenc#”>        
            <xenc:CipherValue>…..</xenc:CipherValue>
            </xenc:CipherData>
         </xenc:EncryptedData>
      </saml2:EncryptedID>
      <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
         <saml2:SubjectConfirmationData Address="137.229.12.164" InResponseTo="id-f6ea64e95fbae2638f2c975fa6b29809" NotOnOrAfter="2013-11-12T23:25:48.629Z" Recipient="https://www.fuzemeeting.com/fuze/saml_verify/alaskaedu"/>
      </saml2:SubjectConfirmation>
   </saml2:Subject>
   <saml2:Conditions NotBefore="2013-11-12T23:20:48.629Z" NotOnOrAfter="2013-11-12T23:25:48.629Z">
      <saml2:AudienceRestriction>
         <saml2:Audience>www.fuzemeeting.com</saml2:Audience>
      </saml2:AudienceRestriction>
   </saml2:Conditions>
   <saml2:AuthnStatement AuthnInstant="2013-11-12T23:20:47.778Z" SessionIndex="554538ed7e12b0fc733eedbb277bfc4060c7d1d81686b42727b12bb1aa54ea8c">
      <saml2:SubjectLocality Address="137.229.12.164"/>
      <saml2:AuthnContext>
         <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef>
      </saml2:AuthnContext>
   </saml2:AuthnStatement>
   <saml2:AttributeStatement>
      <saml2:Attribute FriendlyName="sn" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
         <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">Bantz</saml2:AttributeValue>
      </saml2:Attribute>
      <saml2:Attribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
         <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">Q at alaska.edu</saml2:AttributeValue>
         <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">db at alaska.edu</saml2:AttributeValue>
      </saml2:Attribute>
      <saml2:Attribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
         <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">dabantz at alaska.edu</saml2:AttributeValue>
      </saml2:Attribute>
      <saml2:Attribute FriendlyName="givenName" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
         <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">David</saml2:AttributeValue>
      </saml2:Attribute>
   </saml2:AttributeStatement>
</saml2:Assertion>


-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131112/c6af45a2/attachment-0001.html 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 163 bytes
Desc: Message signed with OpenPGP using GPGMail
Url : http://shibboleth.net/pipermail/users/attachments/20131112/c6af45a2/attachment-0001.bin 


More information about the users mailing list