Spring-Security-SAML & test-shib, Unable to encrypt assertion
Kevin Foote
kpfoote at uoregon.edu
Thu Oct 30 09:40:30 EDT 2014
Dan - Please try again using myself:myself
--------
thanks
kevin.foote
> On Oct 30, 2014, at 8:02 AM, Dan Turner <dan.turner at york.ac.uk> wrote:
>
> Hi all,
>
> I'm trying to integrate Spring Security SAML into our product for
> Shibboleth SSO, and I'm bumping my head against an issue which I can't
> seem to pin down.
>
> I am running a test system, with metadata registered at testshib.org,
> and attempting a login. The redirect to testshib works as expected,
> testshib accepts the myself:myself credential and attempts to encrypt
> the assertions for return to our system, however, at this point it
> falls over, with an Unable to encrypt assertion status message turning
> up in our system's logs. From testshib's public logs:
>
> 07:42:38.812 - ERROR
> [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:927]
> - Could not resolve a key encryption credential for peer entity:
> https://sforge0.york.ac.uk/sf/saml/
> 07:42:38.812 - ERROR
> [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:289]
> - Unable to construct encrypter
> org.opensaml.xml.security.SecurityException: Could not resolve key
> encryption credential
> at
> edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler.getEncrypter(AbstractSAML2ProfileHandler.java:928)
> ~[shibboleth-identityprovider-2.4.0.jar:na]
> at ... [truncated]
>
> I believe that I have the correct metadata, but clearly, this is not
> the case. As per other (older) questions, and the shibboleth.net wiki,
> I have ensured that the metadata has the namespace for KeyDescriptors,
> and both use="encryption" and use="signing":
>
> <?xml version="1.0" encoding="UTF-8"?>
> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
> ID="https___sforge0.york.ac.uk_sf_saml"
> entityID="https://sforge0.york.ac.uk/sf/saml">
> <md:SPSSODescriptor AuthnRequestsSigned="true"
> WantAssertionsSigned="true"
> protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
> <md:KeyDescriptor use="signing">
> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
> <ds:X509Data>
> <ds:X509Certificate>MIIDNj... [snip] ...</ds:X509Certificate>
> </ds:X509Data>
> </ds:KeyInfo>
> </md:KeyDescriptor>
> <md:KeyDescriptor use="encryption">
> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
> <ds:X509Data>
> <ds:X509Certificate>MIIDNjCC... [snip] ...</ds:X509Certificate>
> </ds:X509Data>
> </ds:KeyInfo>
> </md:KeyDescriptor>
> <md:SingleLogoutService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
> Location="https://sforge0.york.ac.uk:443/sf/saml/SingleLogout"/>
> <md:SingleLogoutService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
> Location="https://sforge0.york.ac.uk:443/sf/saml/SingleLogout"/>
>
> <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</md:NameIDFormat>
>
> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
>
> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat>
>
> <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</md:NameIDFormat>
>
> <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName</md:NameIDFormat>
> <md:AssertionConsumerService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
> Location="https://sforge0.york.ac.uk:443/sf/saml/SSO" index="0"
> isDefault="true"/>
> </md:SPSSODescriptor>
> </md:EntityDescriptor>
>
> For the purposes of testing, I am providing the same key for both
> encryption and signing (I know, _really_ bad from a sec. stand point,
> will be corrected in production).
>
> Each time that I upload the metadata to testshib.org, I manually
> inspect it to check that it appears correct (e.g. has KeyDescriptor,
> correct namespaces, etc.), but obviously, I'm missing something here.
>
> Regards,
>
> Dan Turner
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list