Detected a problem with assertion: Unable to establish security of incoming assertion.

kripp kripp at compsych.com
Mon Dec 1 10:54:15 EST 2014


Peter & Scott thank you for the responses.  I did review the documentation
and logs but I didn't see any specific message that stuck out to me.  Below
is the full log entry for this interaction with some data hidden.  So the
issue is that the samlp:Response doesn't contain the ds:Signature from the
IDP?

2014-11-26 10:48:23 DEBUG Shibboleth.Listener [1]: dispatching message
(**HIDDEN**/SAML2/POST)
2014-11-26 10:48:23 DEBUG OpenSAML.MessageDecoder.SAML2POST [1]: validating
input
2014-11-26 10:48:23 DEBUG OpenSAML.MessageDecoder.SAML2POST [1]: decoded
SAML message:
<samlp:Response ID="_a077afa6-b54f-427f-94bd-47014aa11524" Version="2.0"
IssueInstant="2014-11-26T16:47:23.756Z"
Destination="https://**HIDDEN**saml/**HIDDEN**/Shibboleth.sso/SAML2/POST"
xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"><saml:Issuer
xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">**HIDDEN**</saml:Issuer><samlp:Status><samlp:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:Success"
/></samlp:Status><saml:EncryptedAssertion
xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><EncryptedData
Type="http://www.w3.org/2001/04/xmlenc#Element"
xmlns="http://www.w3.org/2001/04/xmlenc#"><EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc" /><KeyInfo
xmlns="http://www.w3.org/2000/09/xmldsig#"><EncryptedKey
xmlns="http://www.w3.org/2001/04/xmlenc#"><EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p" /><KeyInfo
xmlns="http://www.w3.org/2000/09/xmldsig#"><X509Data><X509Certificate>**HIDDEN**</X509Certificate></X509Data></KeyInfo><CipherData><CipherValue>CEXh/ft13Zn7RIhyUKmcNnHQOTmcPha4/ORwfAoqYSfLz1kOQinQcDl7LRuFK4tyg1OrrDfOuZv+cL9q58Yhy5jyUFWhdtOFm3T0fNYLpzGO7hiXoUED1XozSBjiJErLf8ZXAu62NZPQuNkpJHidXFNIZJU3NZhN1jzbFwMPwgXrBcU+lwevg/nGg16Ait6BpFOjmIG3h00EJE/tl8H/o1tmMskk0ww6xxFRV7ytzU/jR0l7AzcGrlCu8DEs8Qj7Dt6fyckSNI24g6zJ6GAhH46hb9tpMzhGUZW0ZlbLHjcG2UyfCSblP8hq1tdKhWgRdLqj9iGf877vLRt9FeeYUg==</CipherValue></CipherData></EncryptedKey></KeyInfo><CipherData><CipherValue>P1erHYNMFOjVAAbq41D9fr3Zv8MwlyLsjw8JJQy/ul3raDrcop7doHbubAxwfSFF5vSBtuGYbykipss7I7B6yNhRMmjfsq2/+BWpGT57xbOzM9N9m4qsjHL2vWO1LWf6IleEAKFEu+/FRjhZ+LvAHUlmbx/xuTQsit8pFY26XsaRLgoAXHqMlRRN9bUB4lGMOBCWQGATtCb4WJa32O7gHeM6jeqt2W9ba6wNf0ijLfGRJw2IawU5CqvDl6j2PSoaxG1hJq+BzIj6JJswGfwH/gd2nKF7VBeLPJb8K33j6ZDVWTJoNz9VzDuQ6Flxe+djwjwkrJGPU7RkGxkJQfXb34Ys2354CoekdBliVylFMnaUV/IPlkRyzmQQRznDTBY+Anx1hHbW3by5YlOplPb/lbjdGG9OdYcdsftIQJmBqmsfLT7hHf/hHVBsewUAv7JkR8kPyU+zw1bOkaz7E3LuZ6WRX11IiLgocAssNKNQgT4nQ4pA331tF1yWAnz254Kg0jOQ5WDYju7SBC84nTkIj6gBc7pps1DI5ktAulxNCxrNi1ykK6WSy8WiL3uUDoKM7HcQ0sSe8pi5EMOac9rEMwvhVKydOSIZ2b84CL1HTw1SIcxIa4okh0jYKdXqpF+n0RfFIvMs5RXSI6adKoKHHG8loi7y7kPu6fJN/o3A7h6JzADbzKqSFHCnuY1vd3ECEcZ0UtKlhhIqT/IIRHAnqptZ+q1dPHWt/4WgvllUKiItWDHrDnDoDxypGOUOs6XWeSY9rRWU8PxunNufSAQvD0hbwniFk0HwjCrdZpFy8CCJMuc3WlPSuosz4Dqo1elxjy7ULhEfndAl7WgXVjsbWK8ouU+4tTdhXKUIKDlA7jvFqOypbh3451uHD93RjEMigE+QfV9k2SchHqVJtRl5W8XdDMTAilCYKUHHrN7pABfESTC4CL3hQaeGmZjpLqF63erfgXkbwsTNyQ/+B9NXhpjNxBG9nGCkY4sm1uBgw/s2oYmciyOL1Sw9cSx9VHfLyqVLxyV9DhvZuk+tdS/e5yfQDYwCxIwPvlmsBtH8PGoJ8+qtLyJWjt/3KxicPHjSQlYZ1a+ywC1T+4WMmIEgPbxmhw8QZwQR2rFVcXMsa/jBtHsZoabH2rHahLrbFxsL0ZO/DJ0jLMgM8MPHM2rv4jATYqXQfOa72WIjzut0kwNawdyZ8Qbb5NbCupZ9vmk0VPjOqMEwGWS+tvN1EaFBGNxM1Cw10eQf/uDkkGiTqjQRsbv1WyuaGQWncGGojXWo6HWN930iwvaaxAIN/qCjg/mFoPnynXbKJFGT44zhm1gOD6p2rT/iEaL74Hrlu/9VhwK3NFtJ7Xie5h1YwVUsbdSXyUCzsBt6IV8QNkuNb7/I2npZKh6XswBxq7KvofSZIGw8bzSZgR+jsGPdgqboRCwz/8eglhKBVgqOMlnK7BfEn4je+v9Yxm1bLTk95LUFXT1bM2v+L1YfcFGBI7q7sfk0MK2ZkE72uR3miEkl0c7RpG4N24+hbpKTZPwqmDFjL27gIJh5gkGZ3JNT72wdQGK+FXTMbrSA0bl5u63/Pk4GIimUg/e4h+UiM7FpY454BHI9cezpAvvOb+UMS6/brINYPMQZqb/1x0siqpeiUA+i51bdVn6uUd8gWRkltnp2NbnMgzwwa2OdJCSfqtHDb3LRgX/4nWMIrTXTuJOQL2o/nuJTritvJcalgkNchPQ4yXk1pCK+COfaJ61w2/D+GSPUq/FJIqKc1K+uAXw4FJGk3DNC8NhiPbhUjzPWBW6hXT+MceoEWdSW9u2Od8qNMQWqSR4QopFa9wHlEzJbFgmvMR0jEDwr701ugWkwO4rz6wCQSfRc9+6MvmurfB7Xf4Nehoiczt8JDZUw946W4dMPkDytiUuVhHQJBYBCumuMjF+CflK2i16P7TUl1G+ynDP2PeJSuPA4duhLipZge9u8Dfz3kx5gHIwZEo36fgdpMacB6+vj0i3tYB1lcRJQ0GNQTewjlxBmSuUOJw6IMxbGpYuGVv2WVaNvGV/OQpULlFqGKANEq24DiJZXUtt5oNLwLPIq/50IOC+GgQ7RzTfF8B/UG6+PfJwZhyJSv9Ju2ttxxtmRLS6oei3roRezuaSMtGYL0wFUKKbHdf/DXf/31zOZJswkBCB2xu4INsJFyTuGHJYdkVZQxXE02zNMTLsbqfxvjmK3wKLVY0qPn7DOY3p6hc3hcnC4Nli0LCO+w4Rq4qd0ofmSdA2GiF9IkY6baQDv8Hm/81pxEJBUuCRPP3bLpwW5O2EferJ+Lg/9v7Imib5XveeFSZGk+OlvR8xZRIEliQMOB4SCi04yiwAZeGTB307pjR0dReXXfPTWF3Yt8gMJD/sysLu/LvGyVpVmG1ntlcRDO9pxiwdVDLuHk9YJ2bNTg/gUS6YKUuk3pFU67aOaQ9zg2LMcJDdXQn3DVCSFq5Vrpm+8YcHHYzs1j/B9IoaWIUDjBYlzjL2m1UPrbBRk1TsTytnihFVPyQN2bWc+9/5rgdd0VoAd4Nrx3+R1lpgkm7hHGm4E4LJLzuS0XzEWmPoIeOWNqxegK9KC9TkvywoZnoyt0poppJO9vWuhlE7hbtFbpCejSIgKdsItk1gmpoSuhbT1iUhqLAoWglmopbNaV1YniCfUq/O1reZJGqVBh+xqKfJpuxzY2/lf7zv+Snfcpl66nt6/f+0TsxRvrcPRZsYRd81hBDmP1Q3zYNH3ctcWSg0/rFABI/LzsQy8QuJuNVfZw/JyvA==</CipherValue></CipherData></EncryptedData></saml:EncryptedAssertion></samlp:Response>

2014-11-26 10:48:23 DEBUG OpenSAML.MessageDecoder.SAML2 [1]: extracting
issuer from SAML 2.0 protocol message
2014-11-26 10:48:23 DEBUG OpenSAML.MessageDecoder.SAML2 [1]: message from
(**HIDDEN**)
2014-11-26 10:48:23 DEBUG OpenSAML.MessageDecoder.SAML2 [1]: searching
metadata for message issuer...
2014-11-26 10:48:23 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [1]:
evaluating message flow policy (replay checking on, expiration 60)
2014-11-26 10:48:23 DEBUG XMLTooling.StorageService [1]: inserted record
(_a077afa6-b54f-427f-94bd-47014aa11524) in context (MessageFlow) with
expiration (1417020683)
2014-11-26 10:48:23 DEBUG Shibboleth.SSO.SAML2 [1]: processing message
against SAML 2.0 SSO profile
2014-11-26 10:48:23 DEBUG XMLTooling.CredentialCriteria [1]: key algorithm
didn't match ('AES' != 'RSA')
2014-11-26 10:48:23 DEBUG Shibboleth.SSO.SAML2 [1]: decrypted Assertion:
<saml:Assertion xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
ID="_ad1fefc0-53d9-4fea-98ae-77fb5bb83191"
IssueInstant="2014-11-26T16:47:23.758Z"
Version="2.0"><saml:Issuer>**HIDDEN**</saml:Issuer><saml:Subject><saml:NameID
Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">delta</saml:NameID><saml:SubjectConfirmation
Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><saml:SubjectConfirmationData
NotOnOrAfter="2014-11-26T16:50:23.76Z"
Recipient="https://**HIDDEN**/saml/**HIDDEN**/Shibboleth.sso/SAML2/POST"/></saml:SubjectConfirmation></saml:Subject><saml:Conditions
NotBefore="2014-11-26T16:44:23.758Z"
NotOnOrAfter="2014-11-26T16:50:23.758Z"><saml:AudienceRestriction><saml:Audience>**HIDDEN</saml:Audience></saml:AudienceRestriction></saml:Conditions><saml:AuthnStatement
AuthnInstant="2014-11-26T16:47:23.76Z"
SessionIndex="_ad1fefc0-53d9-4fea-98ae-77fb5bb83191"><saml:AuthnContext><saml:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified</saml:AuthnContextClassRef></saml:AuthnContext></saml:AuthnStatement><saml:AttributeStatement><saml:Attribute
Name="FirstName"><saml:AttributeValue
xmlns:xs="http://www.w3.org/2001/XMLSchema"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:type="xs:string">Delta</saml:AttributeValue></saml:Attribute><saml:Attribute
Name="LastName"><saml:AttributeValue
xmlns:xs="http://www.w3.org/2001/XMLSchema"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:type="xs:string">One</saml:AttributeValue></saml:Attribute><saml:Attribute
Name="Email"><saml:AttributeValue
xmlns:xs="http://www.w3.org/2001/XMLSchema"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:type="xs:string">**HIDDEN**</saml:AttributeValue></saml:Attribute><saml:Attribute
Name="EmployeeId"><saml:AttributeValue
xmlns:xs="http://www.w3.org/2001/XMLSchema"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:type="xs:string">**HIDDEN**</saml:AttributeValue></saml:Attribute></saml:AttributeStatement></saml:Assertion>
2014-11-26 10:48:23 DEBUG Shibboleth.SSO.SAML2 [1]: extracting issuer from
SAML 2.0 assertion
2014-11-26 10:48:23 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [1]:
evaluating message flow policy (replay checking on, expiration 60)
2014-11-26 10:48:23 DEBUG XMLTooling.StorageService [1]: inserted record
(_ad1fefc0-53d9-4fea-98ae-77fb5bb83191) in context (MessageFlow) with
expiration (1417020683)
2014-11-26 10:48:23 DEBUG OpenSAML.SecurityPolicyRule.BearerConfirmation
[1]: assertion satisfied bearer confirmation requirements
2014-11-26 10:48:23 WARN Shibboleth.SSO.SAML2 [1]: detected a problem with
assertion: Unable to establish security of incoming assertion.
2014-11-26 10:54:52 INFO XMLTooling.StorageService : purged 2 expired
record(s) from storage
2014-11-30 04:02:07 INFO Shibboleth.Listener [1]: detected socket closure,
shutting down worker thread


Thanks!



--
View this message in context: http://shibboleth.1660669.n2.nabble.com/Detected-a-problem-with-assertion-Unable-to-establish-security-of-incoming-assertion-tp7609484p7609498.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.


More information about the users mailing list