Google Apps SSO with OpenSAML IDP + Sending Unsigned SAML Responses?

Rohit Turumella rohit.turumella at resilient-networks.com
Tue Sep 3 18:24:54 EDT 2013


Hi,

I am working on integrating an OpenSAML IDP with Google's SP for Google
Apps SSO. I'm running into the following issue however: "*Google Apps -- **This
account cannot be accessed because we could not parse the login request.*"

Has anyone run into the following issue? I've run my authnresponse against
various XML validators which don't report any errors.

I was also wondering how to send an unencrypted SAML Message. It looks like
the OpenSAML SAMLMessageEncoder sends encrypted SAML responses by default. *How
can I send an unencrypted SAML response?*

*Here's the AuthnResponse my OpenSAML IDP is Generating:*

<?xml version="1.0" encoding="UTF-8"?><saml2p:Response
xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="
https://www.google.com/a/mysite.com/acs"
ID="44859d3d-6e72-4ce1-ae2f-9c5420f1e29f"
InResponseTo="kmljhpobfepghlhlajipoodlenilbficclihpmfp"
IssueInstant="2013-09-03T20:56:43.462Z" Version="2.0" xmlns:xs="
http://www.w3.org/2001/XMLSchema">
   <saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">testrnsidptn</saml2:Issuer>
   <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
      <ds:SignedInfo>
         <ds:CanonicalizationMethod Algorithm="
http://www.w3.org/2001/10/xml-exc-c14n#"/>
         <ds:SignatureMethod Algorithm="
http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
         <ds:Reference URI="#44859d3d-6e72-4ce1-ae2f-9c5420f1e29f">
            <ds:Transforms>
               <ds:Transform Algorithm="
http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
               <ds:Transform Algorithm="
http://www.w3.org/2001/10/xml-exc-c14n#">
                  <ec:InclusiveNamespaces xmlns:ec="
http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="xs"/>
               </ds:Transform>
            </ds:Transforms>
            <ds:DigestMethod Algorithm="
http://www.w3.org/2000/09/xmldsig#sha1"/>
            <ds:DigestValue>6SUQDg+IsAsdGPGb1l2zbHEE6Es=</ds:DigestValue>
         </ds:Reference>
      </ds:SignedInfo>

<ds:SignatureValue>FH5LcHVerraDormvl1guXthfrQZuseJPQeLhDEf1lsak1nu0/HShhYRCsN3JxwPRDNIeyrAcxzTztMkWLwXTG2D1uuDYFJHVKkxO9dkXDSYh1kc6aL7U95yML2nBWQBP2ffG4PbZ3xWJ0Ic4Km10wMAhyBCCPHQb7QPn2fBMpMckf77SJCh73L3v3eaM/cGQJGiOujGQorLcSAfvqIc8nx1fwM5H+k0oW+itRLRRlEVJ60b7xfYHXFM45U6S4sIhRF+K5dx8UfGguVkyCzDcHtzdkZyfYvrOvrzx0EE3hqcDR7PgCOsZ6yhSDNTnYtB62eoFxX80rojM7cte+L9UnQ==</ds:SignatureValue>
      <ds:KeyInfo>
         <ds:X509Data>

<ds:X509Certificate>MIIDejCCAmKgAwIBAgIEUgv21TANBgkqhkiG9w0BAQUFADB/MQswCQYDVQQGEwJVUzETMBEGA1UE
CBMKQ2FsaWZvcm5pYTEWMBQGA1UEBxMNU2FuIEZyYW5jaXNjbzEbMBkGA1UEChMSUmVzaWxpZW50
IE5ldHdvcmtzMQ8wDQYDVQQLEwZEZXZvcHMxFTATBgNVBAMTDFNsb2FuIExvb25leTAeFw0xMzA4
MTQyMTI5NTdaFw0xNDA4MTQyMTI5NTdaMH8xCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9y
bmlhMRYwFAYDVQQHEw1TYW4gRnJhbmNpc2NvMRswGQYDVQQKExJSZXNpbGllbnQgTmV0d29ya3Mx
DzANBgNVBAsTBkRldm9wczEVMBMGA1UEAxMMU2xvYW4gTG9vbmV5MIIBIjANBgkqhkiG9w0BAQEF
AAOCAQ8AMIIBCgKCAQEAnqLAiMgGWk3GUgEy2rvZiOfvpVvsIR946FCBwPKHPKeDpK3dO3vcVg+S
P5lbGijOPIsBy8oS8RnOalU+f4W1TF8PjiOhgpH0FDcM6Sl/LWFTMS3PHbU5E/TuhfAoFM7/5JvJ
Y2ncSd6jrJepYS9FdGE+V6PIAZ/tGexFZYDIaVhJecH0fy/rFYAOn4kb3yETSCju0sdvY9ieye1+
kp/ZM2uiXutO3VsAq2OMRyy/C9lmqxfsYMwzoZ0iqQ4mTK/imPVukXzw65e+IjMi7oz/McMiyECr
cPf0d//Zqrb6NF8wlsh2O5uRMAgJn+Hm3hEnM9FxIKHIhWoIggF21cgUPwIDAQABMA0GCSqGSIb3
DQEBBQUAA4IBAQASni6M0jdk4I3QUKHBdD/W/1Y2v9m21SgKuj8kg4qNTT8tmIGLtHK3F8bVy61E
0DGpIUyfq8ZXfE16szvT6U8cEHC6sA/hyWuwf6guu+4Y7Xr/DEFO7zBtSDLkFr9llsNCSp/QkBkg
DeE0AYFfx95k7KBuk6OUKUodQ7VIMyOIeE8qYXqBnHQU+1hrXeGQ1Qf5fe62q2IivZEoKALZPR9e
mDeAYjxEagIfizy01fr8rbWW0apjOX3xCkF35qDWNQLRS8ZViuhqd+mS2hrZzCy3IKs/Un4xR8oz
035qvpwWk8gDK1fEuK2cazRJfSDanWLGA620xY13fShNG4dBw79E</ds:X509Certificate>
         </ds:X509Data>
      </ds:KeyInfo>
   </ds:Signature>
   <saml2p:Status>
      <saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
   </saml2p:Status>
   <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
ID="47b0b83f-3a77-4ed3-877f-37957cd0c710"
IssueInstant="2013-09-03T20:56:43.461Z" Version="2.0">
      <saml2:Issuer
Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">testrnsidptn</saml2:Issuer>
      <saml2:Subject>
         <saml2:NameID
Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">
sptester at mysite.com</saml2:NameID>
         <saml2:SubjectConfirmation
Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
            <saml2:SubjectConfirmationData Address="199.188.194.207"
InResponseTo="kmljhpobfepghlhlajipoodlenilbficclihpmfp"
NotOnOrAfter="2013-09-03T20:58:13.444Z" Recipient="
https://www.google.com/a/mysite.com/acs"/>
         </saml2:SubjectConfirmation>
      </saml2:Subject>
      <saml2:AuthnStatement AuthnInstant="2013-09-03T20:56:16.961Z">
         <saml2:AuthnContext>

<saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:Password</saml2:AuthnContextClassRef>
         </saml2:AuthnContext>
      </saml2:AuthnStatement>
      <saml2:AttributeStatement>
         <saml2:Attribute FriendlyName="uid" Name="uid"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified">
            <saml2:AttributeValue xmlns:xsi="
http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">
sptester at mysite.com</saml2:AttributeValue>
         </saml2:Attribute>
      </saml2:AttributeStatement>
   </saml2:Assertion>
</saml2p:Response>


Thanks,

Rohit
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130903/83e06959/attachment.html 


More information about the users mailing list