Unable to establish security of incoming assertion
Dewberry, James
JDewberry at nfp.com
Wed Feb 19 11:41:22 EST 2014
Thanks Scott.
They are not an established Idp. They say they are using SSO with a
different SP, but I had to correct several problems in their assertion to
get it to unmarshall: using ※IssueInstant" instead of ※AuthnInstant§, etc.
I would not be surprised if the problem is with their metadata/key, I just
have to prove it to them. So thanks for all your suggested next steps.
Jim
On 2/19/14, 10:34 AM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
>On 2/19/14, 10:16 AM, "Dewberry, James" <JDewberry at nfp.com> wrote:
>>
>>The client swears up and down that the signature is valid, but I易m not
>>too familiar with how the signature stuff works.
>
>Well, either they're wrong, or their metadata/key is.
>
>>Do you have any suggestions on:
>>
>>1. How can I validate the signature myself?
>
>At minimum you have to recover the raw unmolested XML from the submission
>or from the log (catching it in the form is the best, since there's no
>possibility of getting corruption when you directly decode the base64).
>You can try feeding it into tools like Oxygen, or possibly the xmlsec
>project's web page.
>
>>2. Is there any configuration I can do to get the signature verified?
>
>Not likely, no.
>
>>3. Any thoughts on what I can do next?
>
>https://wiki.shibboleth.net/confluence/display/OpenSAML/OSTwoUserManSigErr
>o
>rs
>
>>4. Are they using a signature method that Shibboleth doesn易t like?
>
>No. The signature they provided is not technically valid SAML (it's
>missing a Reference ID) but it's a common thing to do it the way they did
>it and Shibboleth wouldn't reject it. The problem here is the signature
>computation or the key.
>
>Practically speaking, the question to ask is what the IdP is. If it's a
>known-good implementation, then the problem is the key/metadata. If not,
>there is no way to know easily.
>
>-- Scott
>
>
>--
>To unsubscribe from this list send an email to
>users-unsubscribe at shibboleth.net
**********************************************************************
This e-mail may contain information that is privileged, confidential or protected under state or federal law. If you are not an intended recipient of this email, please delete it, notify the sender immediately, and do not copy, use or disseminate any information in the e-mail. Pursuant to IRS Circular 230, any tax advice in this email may not be used to avoid any penalties imposed under U.S. tax laws. E-mail sent to or from this e-mail address may be monitored, reviewed and archived.
More information about the users
mailing list