Google Apps SSO with OpenSAML IDP + Sending Unsigned SAML Responses?
Rohit Turumella
rohit.turumella at resilient-networks.com
Tue Sep 3 18:24:54 EDT 2013
Hi,
I am working on integrating an OpenSAML IDP with Google's SP for Google
Apps SSO. I'm running into the following issue however: "*Google Apps -- **This
account cannot be accessed because we could not parse the login request.*"
Has anyone run into the following issue? I've run my authnresponse against
various XML validators which don't report any errors.
I was also wondering how to send an unencrypted SAML Message. It looks like
the OpenSAML SAMLMessageEncoder sends encrypted SAML responses by default. *How
can I send an unencrypted SAML response?*
*Here's the AuthnResponse my OpenSAML IDP is Generating:*
<?xml version="1.0" encoding="UTF-8"?><saml2p:Response
xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="
https://www.google.com/a/mysite.com/acs"
ID="44859d3d-6e72-4ce1-ae2f-9c5420f1e29f"
InResponseTo="kmljhpobfepghlhlajipoodlenilbficclihpmfp"
IssueInstant="2013-09-03T20:56:43.462Z" Version="2.0" xmlns:xs="
http://www.w3.org/2001/XMLSchema">
<saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">testrnsidptn</saml2:Issuer>
<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="
http://www.w3.org/2001/10/xml-exc-c14n#"/>
<ds:SignatureMethod Algorithm="
http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
<ds:Reference URI="#44859d3d-6e72-4ce1-ae2f-9c5420f1e29f">
<ds:Transforms>
<ds:Transform Algorithm="
http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<ds:Transform Algorithm="
http://www.w3.org/2001/10/xml-exc-c14n#">
<ec:InclusiveNamespaces xmlns:ec="
http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="xs"/>
</ds:Transform>
</ds:Transforms>
<ds:DigestMethod Algorithm="
http://www.w3.org/2000/09/xmldsig#sha1"/>
<ds:DigestValue>6SUQDg+IsAsdGPGb1l2zbHEE6Es=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>FH5LcHVerraDormvl1guXthfrQZuseJPQeLhDEf1lsak1nu0/HShhYRCsN3JxwPRDNIeyrAcxzTztMkWLwXTG2D1uuDYFJHVKkxO9dkXDSYh1kc6aL7U95yML2nBWQBP2ffG4PbZ3xWJ0Ic4Km10wMAhyBCCPHQb7QPn2fBMpMckf77SJCh73L3v3eaM/cGQJGiOujGQorLcSAfvqIc8nx1fwM5H+k0oW+itRLRRlEVJ60b7xfYHXFM45U6S4sIhRF+K5dx8UfGguVkyCzDcHtzdkZyfYvrOvrzx0EE3hqcDR7PgCOsZ6yhSDNTnYtB62eoFxX80rojM7cte+L9UnQ==</ds:SignatureValue>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>MIIDejCCAmKgAwIBAgIEUgv21TANBgkqhkiG9w0BAQUFADB/MQswCQYDVQQGEwJVUzETMBEGA1UE
CBMKQ2FsaWZvcm5pYTEWMBQGA1UEBxMNU2FuIEZyYW5jaXNjbzEbMBkGA1UEChMSUmVzaWxpZW50
IE5ldHdvcmtzMQ8wDQYDVQQLEwZEZXZvcHMxFTATBgNVBAMTDFNsb2FuIExvb25leTAeFw0xMzA4
MTQyMTI5NTdaFw0xNDA4MTQyMTI5NTdaMH8xCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9y
bmlhMRYwFAYDVQQHEw1TYW4gRnJhbmNpc2NvMRswGQYDVQQKExJSZXNpbGllbnQgTmV0d29ya3Mx
DzANBgNVBAsTBkRldm9wczEVMBMGA1UEAxMMU2xvYW4gTG9vbmV5MIIBIjANBgkqhkiG9w0BAQEF
AAOCAQ8AMIIBCgKCAQEAnqLAiMgGWk3GUgEy2rvZiOfvpVvsIR946FCBwPKHPKeDpK3dO3vcVg+S
P5lbGijOPIsBy8oS8RnOalU+f4W1TF8PjiOhgpH0FDcM6Sl/LWFTMS3PHbU5E/TuhfAoFM7/5JvJ
Y2ncSd6jrJepYS9FdGE+V6PIAZ/tGexFZYDIaVhJecH0fy/rFYAOn4kb3yETSCju0sdvY9ieye1+
kp/ZM2uiXutO3VsAq2OMRyy/C9lmqxfsYMwzoZ0iqQ4mTK/imPVukXzw65e+IjMi7oz/McMiyECr
cPf0d//Zqrb6NF8wlsh2O5uRMAgJn+Hm3hEnM9FxIKHIhWoIggF21cgUPwIDAQABMA0GCSqGSIb3
DQEBBQUAA4IBAQASni6M0jdk4I3QUKHBdD/W/1Y2v9m21SgKuj8kg4qNTT8tmIGLtHK3F8bVy61E
0DGpIUyfq8ZXfE16szvT6U8cEHC6sA/hyWuwf6guu+4Y7Xr/DEFO7zBtSDLkFr9llsNCSp/QkBkg
DeE0AYFfx95k7KBuk6OUKUodQ7VIMyOIeE8qYXqBnHQU+1hrXeGQ1Qf5fe62q2IivZEoKALZPR9e
mDeAYjxEagIfizy01fr8rbWW0apjOX3xCkF35qDWNQLRS8ZViuhqd+mS2hrZzCy3IKs/Un4xR8oz
035qvpwWk8gDK1fEuK2cazRJfSDanWLGA620xY13fShNG4dBw79E</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</ds:Signature>
<saml2p:Status>
<saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
</saml2p:Status>
<saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
ID="47b0b83f-3a77-4ed3-877f-37957cd0c710"
IssueInstant="2013-09-03T20:56:43.461Z" Version="2.0">
<saml2:Issuer
Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">testrnsidptn</saml2:Issuer>
<saml2:Subject>
<saml2:NameID
Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">
sptester at mysite.com</saml2:NameID>
<saml2:SubjectConfirmation
Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
<saml2:SubjectConfirmationData Address="199.188.194.207"
InResponseTo="kmljhpobfepghlhlajipoodlenilbficclihpmfp"
NotOnOrAfter="2013-09-03T20:58:13.444Z" Recipient="
https://www.google.com/a/mysite.com/acs"/>
</saml2:SubjectConfirmation>
</saml2:Subject>
<saml2:AuthnStatement AuthnInstant="2013-09-03T20:56:16.961Z">
<saml2:AuthnContext>
<saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:Password</saml2:AuthnContextClassRef>
</saml2:AuthnContext>
</saml2:AuthnStatement>
<saml2:AttributeStatement>
<saml2:Attribute FriendlyName="uid" Name="uid"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified">
<saml2:AttributeValue xmlns:xsi="
http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">
sptester at mysite.com</saml2:AttributeValue>
</saml2:Attribute>
</saml2:AttributeStatement>
</saml2:Assertion>
</saml2p:Response>
Thanks,
Rohit
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130903/83e06959/attachment.html
More information about the users
mailing list