Shibboleth 3 SAML Response Debugging

McKean, Brandon Scott - mckeanbs mckeanbs at jmu.edu
Thu Jul 16 09:46:55 EDT 2015


I think I've managed to get past this part, though now I'm getting
failures on more or less all SPs, though none of them are really
printing an error message to go on.
Perhaps you guys could look at the SAML assertion I'm getting and point
me in the right direction to fix this.
Here's the one from the existing v2 IDP that works:
<saml1p:Response xmlns:saml1p="urn:oasis:names:tc:SAML:1.0:protocol"
                 IssueInstant="2015-07-16T13:37:32.724Z"
                 MajorVersion="1"
                 MinorVersion="1"
                 Recipient="
https://www.zimride.com/Shibboleth.sso/SAML/POST"
                 ResponseID="_ca43239c3f02bc89ec02482a725fd521"
                 >
    <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">;
        <ds:SignedInfo>
            <ds:CanonicalizationMethod Algorithm="
http://www.w3.org/2001/10/xml-exc-c14n#" />
            <ds:SignatureMethod Algorithm="
http://www.w3.org/2000/09/xmldsig#rsa-sha1" />
            <ds:Reference URI="#_ca43239c3f02bc89ec02482a725fd521">
                <ds:Transforms>
                    <ds:Transform Algorithm="
http://www.w3.org/2000/09/xmldsig#enveloped-signature" />
                    <ds:Transform Algorithm="
http://www.w3.org/2001/10/xml-exc-c14n#" />
                </ds:Transforms>
                <ds:DigestMethod Algorithm="
http://www.w3.org/2000/09/xmldsig#sha1" />
               
 <ds:DigestValue>DeeHpKPnpqW/sMr166OnPzuRhCo=</ds:DigestValue>
            </ds:Reference>
        </ds:SignedInfo>
       
 <ds:SignatureValue>aCUtDHxvSYVpizf0wYvuK3+18+gzNY5L1K1frMHVMEV/OGNCz8P
CKZBLeD1O6LuKHMe0cm984n3U9NAc4HVPXBy1BTtq8gmbnPu/HAfBqQKMCzXzHayGs0aDyP
zfa+/PFmeCitv/8uMuKYcpZsTGeCrXgvLeNtC6w6D6Jm5yMKSh60tQhyGdbP2xRzE01o7q1
AfwSOptlfJ0jlZ5kgdnRThvYkKsKu0Pea+h994F/3jqssnNNEdGNa7HQOa5cizJXgc3D+Bo
qLAvkN09NWy5Emj0qqLUZ9ToLnpmxDQdG2dQ5MdFEThtXssBdZbGn/PwBVcJ80QoKRZPqtk
50nzXWQ==</ds:SignatureValue>
        <ds:KeyInfo>
            <ds:X509Data>
               
 <ds:X509Certificate>MIIEvTCCA6WgAwIBAgIJAMwnlWaj6tOPMA0GCSqGSIb3DQEBBQ
UAMIGaMQswCQYDVQQGEwJVUzER
MA8GA1UECBMIVmlyZ2luaWExFTATBgNVBAcTDEhhcnJpc29uYnVyZzEhMB8GA1UEChMYSmF
tZXMg
TWFkaXNvbiBVbml2ZXJzaXR5MR8wHQYDVQQLExZJbmZvcm1hdGlvbiBUZWNobm9sb2d5MR0
wGwYD
VQQDExRpdGZlZGVyYXRpb24uam11LmVkdTAeFw0xMjA2MDUxNTExMTRaFw0yMjA2MDUxNTE
xMTRa
MIGaMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWExFTATBgNVBAcTDEhhcnJpc29
uYnVy
ZzEhMB8GA1UEChMYSmFtZXMgTWFkaXNvbiBVbml2ZXJzaXR5MR8wHQYDVQQLExZJbmZvcm1
hdGlv
biBUZWNobm9sb2d5MR0wGwYDVQQDExRpdGZlZGVyYXRpb24uam11LmVkdTCCASIwDQYJKoZ
IhvcN
AQEBBQADggEPADCCAQoCggEBAMoRMpZ+1Y8Z6de8v1Zj3UYNEj0b2V/mSd9rseQtcAgPMwL
2khVt
/GJoPpdG7DGmRCATuVpkzD/k1vA06cBOknCHpOhHvn2AgYyfPFqbHY1bBLE0sKqynnj2W5S
19Sb+
9DYl5lY7gQsoXCX5o0qliBjp7Yqo1aMT/rImOZlcw4r7GL/dTi+0Q1ScWUX+YNCJF22sAg/
HctNj
qCkEwPqVv5K0UHZ96YpdOXmC+pzQ9oo33RANpaMGHpA63eM70rzVZccVspb0LG8sZZLuTav
HXTpG
f2tR2TauKS1zP9ok0ZD5rweDem3BKtRP7i9R+tuejzHi3JH2Dur59At616y1jN0CAwEAAaO
CAQIw
gf8wHQYDVR0OBBYEFJ50wNaJkgk5WSLNo0w/NhDjxmYpMIHPBgNVHSMEgccwgcSAFJ50wNa
Jkgk5
WSLNo0w/NhDjxmYpoYGgpIGdMIGaMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWE
xFTAT
BgNVBAcTDEhhcnJpc29uYnVyZzEhMB8GA1UEChMYSmFtZXMgTWFkaXNvbiBVbml2ZXJzaXR
5MR8w
HQYDVQQLExZJbmZvcm1hdGlvbiBUZWNobm9sb2d5MR0wGwYDVQQDExRpdGZlZGVyYXRpb24
uam11
LmVkdYIJAMwnlWaj6tOPMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEFBQADggEBAK8EXe8
Og7W6
M384gTsVNHcG1h6B6pmXhHZfVwVucYEenggcSQ7ErWCZliCE0Ae8hfiqPZDdLrrzaF6/gp6
sfueu
RbKXaa41FfcuvOGaUs25TD3hf7tH2N4Voq7akAtPYCdtupLvbB7eM8CFJwKdOc43tLUO3eG
4eJzM
WV6hX+PwwqCbZIvcKbFpFhzMSN/uMsH+FBVwtyV/jxAkRpw/MRczHruwPObYT6mKoVMdOaP
0NvAE
tqQRFBuJQh760wpzQzYSjyLb8gehpoRs8nWw73l8FgKhXa/hz06Vp9hibCfxxSWb8bktOu8
MruAM
4zVeItgUieNNRzPjqrr/K8B4rWo=</ds:X509Certificate>
            </ds:X509Data>
        </ds:KeyInfo>
    </ds:Signature>
    <saml1p:Status>
        <saml1p:StatusCode Value="saml1p:Success" />
    </saml1p:Status>
    <saml1:Assertion
xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion"
                     AssertionID="_1f2513d5a3b297f810798f2f3d471ec0"
                     IssueInstant="2015-07-16T13:37:32.724Z"
                     Issuer="urn:mace:incommon:jmu.edu"
                     MajorVersion="1"
                     MinorVersion="1"
                     >
        <saml1:Conditions NotBefore="2015-07-16T13:37:32.724Z"
                          NotOnOrAfter="2015-07-16T13:42:32.724Z"
                          >
            <saml1:AudienceRestrictionCondition>
                <saml1:Audience>
https://www.zimride.com/shibboleth</saml1:Audience>;
            </saml1:AudienceRestrictionCondition>
        </saml1:Conditions>
        <saml1:AuthenticationStatement AuthenticationInstant="2015-07
-16T13:37:32.507Z"
                                      
 AuthenticationMethod="urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordP
rotectedTransport"
                                       >
            <saml1:Subject>
                <saml1:NameIdentifier
Format="urn:mace:shibboleth:1.0:nameIdentifier"
                                     
 NameQualifier="urn:mace:incommon:jmu.edu"
                                     
 >_1f3da579407d93d78d8a9d811214c644</saml1:NameIdentifier>
                <saml1:SubjectConfirmation>
                   
 <saml1:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:bearer</saml1
:ConfirmationMethod>
                </saml1:SubjectConfirmation>
            </saml1:Subject>
            <saml1:SubjectLocality IPAddress="134.126.38.114" />
        </saml1:AuthenticationStatement>
    </saml1:Assertion>
</saml1p:Response>
And here's the new one that isn't liked by the SP:
<saml1p:Response IssueInstant="2015-07-16T13:36:32.460Z"
                 MajorVersion="1"
                 MinorVersion="1"
                 Recipient="
https://www.zimride.com/Shibboleth.sso/SAML/POST"
                 ResponseID="_60adadba18a05747f120578c162a06cd"
                 xmlns:saml1p="urn:oasis:names:tc:SAML:1.0:protocol"
                 >
    <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">;
        <ds:SignedInfo>
            <ds:CanonicalizationMethod Algorithm="
http://www.w3.org/2001/10/xml-exc-c14n#" />
            <ds:SignatureMethod Algorithm="
http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" />
            <ds:Reference URI="#_60adadba18a05747f120578c162a06cd">
                <ds:Transforms>
                    <ds:Transform Algorithm="
http://www.w3.org/2000/09/xmldsig#enveloped-signature" />
                    <ds:Transform Algorithm="
http://www.w3.org/2001/10/xml-exc-c14n#" />
                </ds:Transforms>
                <ds:DigestMethod Algorithm="
http://www.w3.org/2001/04/xmlenc#sha256" />
               
 <ds:DigestValue>5rkixDu6J+IpEg9uqhE4RryKc6Sis+jb/N+QH1Kqto4=</ds:Diges
tValue>
            </ds:Reference>
        </ds:SignedInfo>
        <ds:SignatureValue>
Bu3/5mZtdg88Dhkju5YwUL20tj5bl9IpAJm/aHWSClX2Hex60q7pIH1t83LMNtOpAxeP1hf
cHgme
MkeZo2o86o+nFRuTi5KTlgYhyZ54r/pFRxjgVTuo6Pe3WDY8ESJX7DEIwZ/GUhGlcDI7Grb
dfzQc
NqtdHuJ35vbEl4qrKq7UwBCN2yqe9IlYI8XXuNXIKQhIMqP95P0+N/BOlW9/k1QeTqXmdX0
u8pvf
l6pqTkt5YIgZ5Ibc1n8/EHYwDs2jYOmUxF2G/AbXul43tQb9fLYECc3GAYP13OVKxezS9op
j66lb
jWY2l9SkXs+wLuewNu0taOTDsOdaH5ZOl3dVBA==
</ds:SignatureValue>
        <ds:KeyInfo>
            <ds:X509Data>
               
 <ds:X509Certificate>MIIEvTCCA6WgAwIBAgIJAMwnlWaj6tOPMA0GCSqGSIb3DQEBBQ
UAMIGaMQswCQYDVQQGEwJVUzER
MA8GA1UECBMIVmlyZ2luaWExFTATBgNVBAcTDEhhcnJpc29uYnVyZzEhMB8GA1UEChMYSmF
tZXMg
TWFkaXNvbiBVbml2ZXJzaXR5MR8wHQYDVQQLExZJbmZvcm1hdGlvbiBUZWNobm9sb2d5MR0
wGwYD
VQQDExRpdGZlZGVyYXRpb24uam11LmVkdTAeFw0xMjA2MDUxNTExMTRaFw0yMjA2MDUxNTE
xMTRa
MIGaMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWExFTATBgNVBAcTDEhhcnJpc29
uYnVy
ZzEhMB8GA1UEChMYSmFtZXMgTWFkaXNvbiBVbml2ZXJzaXR5MR8wHQYDVQQLExZJbmZvcm1
hdGlv
biBUZWNobm9sb2d5MR0wGwYDVQQDExRpdGZlZGVyYXRpb24uam11LmVkdTCCASIwDQYJKoZ
IhvcN
AQEBBQADggEPADCCAQoCggEBAMoRMpZ+1Y8Z6de8v1Zj3UYNEj0b2V/mSd9rseQtcAgPMwL
2khVt
/GJoPpdG7DGmRCATuVpkzD/k1vA06cBOknCHpOhHvn2AgYyfPFqbHY1bBLE0sKqynnj2W5S
19Sb+
9DYl5lY7gQsoXCX5o0qliBjp7Yqo1aMT/rImOZlcw4r7GL/dTi+0Q1ScWUX+YNCJF22sAg/
HctNj
qCkEwPqVv5K0UHZ96YpdOXmC+pzQ9oo33RANpaMGHpA63eM70rzVZccVspb0LG8sZZLuTav
HXTpG
f2tR2TauKS1zP9ok0ZD5rweDem3BKtRP7i9R+tuejzHi3JH2Dur59At616y1jN0CAwEAAaO
CAQIw
gf8wHQYDVR0OBBYEFJ50wNaJkgk5WSLNo0w/NhDjxmYpMIHPBgNVHSMEgccwgcSAFJ50wNa
Jkgk5
WSLNo0w/NhDjxmYpoYGgpIGdMIGaMQswCQYDVQQGEwJVUzERMA8GA1UECBMIVmlyZ2luaWE
xFTAT
BgNVBAcTDEhhcnJpc29uYnVyZzEhMB8GA1UEChMYSmFtZXMgTWFkaXNvbiBVbml2ZXJzaXR
5MR8w
HQYDVQQLExZJbmZvcm1hdGlvbiBUZWNobm9sb2d5MR0wGwYDVQQDExRpdGZlZGVyYXRpb24
uam11
LmVkdYIJAMwnlWaj6tOPMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEFBQADggEBAK8EXe8
Og7W6
M384gTsVNHcG1h6B6pmXhHZfVwVucYEenggcSQ7ErWCZliCE0Ae8hfiqPZDdLrrzaF6/gp6
sfueu
RbKXaa41FfcuvOGaUs25TD3hf7tH2N4Voq7akAtPYCdtupLvbB7eM8CFJwKdOc43tLUO3eG
4eJzM
WV6hX+PwwqCbZIvcKbFpFhzMSN/uMsH+FBVwtyV/jxAkRpw/MRczHruwPObYT6mKoVMdOaP
0NvAE
tqQRFBuJQh760wpzQzYSjyLb8gehpoRs8nWw73l8FgKhXa/hz06Vp9hibCfxxSWb8bktOu8
MruAM
4zVeItgUieNNRzPjqrr/K8B4rWo=</ds:X509Certificate>
            </ds:X509Data>
        </ds:KeyInfo>
    </ds:Signature>
    <saml1p:Status>
        <saml1p:StatusCode Value="saml1p:Success" />
    </saml1p:Status>
    <saml1:Assertion AssertionID="_099eb00e3c94a8a6f3347c8ec02fcad4"
                     IssueInstant="2015-07-16T13:36:32.460Z"
                     Issuer="urn:mace:incommon:jmu.edu"
                     MajorVersion="1"
                     MinorVersion="1"
                    
 xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion"
                     >
        <saml1:Conditions NotBefore="2015-07-16T13:36:32.460Z"
                          NotOnOrAfter="2015-07-16T13:41:32.460Z"
                          >
            <saml1:AudienceRestrictionCondition>
                <saml1:Audience>
https://www.zimride.com/shibboleth</saml1:Audience>;
            </saml1:AudienceRestrictionCondition>
        </saml1:Conditions>
        <saml1:AuthenticationStatement AuthenticationInstant="2015-07
-16T13:36:26.419Z"
                                      
 AuthenticationMethod="urn:oasis:names:tc:SAML:1.0:am:password"
                                       >
            <saml1:Subject>
                <saml1:NameIdentifier
Format="urn:mace:shibboleth:1.0:nameIdentifier"
                                     
 NameQualifier="urn:mace:incommon:jmu.edu"
                                     
 >AAdzZWNyZXQxWm65wXv3q//YKZgH8LwWyAs7jtRQFV07iTQxocs7LYKIeBVtCVhFQu4c6
e7yBG9JHY/sPhPAO1Nz/b0rd3lUc8LJJYoyO9KOnBr49wHWqe/zoLFfKUNcDzoztQciLFtm
rIhWEuJPHKev</saml1:NameIdentifier>
                <saml1:SubjectConfirmation>
                   
 <saml1:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:bearer</saml1
:ConfirmationMethod>
                </saml1:SubjectConfirmation>
            </saml1:Subject>
            <saml1:SubjectLocality IPAddress="134.126.38.114" />
        </saml1:AuthenticationStatement>
    </saml1:Assertion>
</saml1p:Response>
As far as I can tell, the IDP hasn't produced errors while creating
those. This is just an example though, it appears none of the SPs like
what they're getting.
Anything that could point me in the right direction is appreciated.
Thanks,

-- 
Brandon McKean
IT / Systems
Linux Administrator
(540)568-4235
On Wed, 2015-07-15 at 20:38 +0000, Cantor, Scott wrote:
> On 7/15/15, 4:28 PM, "users on behalf of McKean, Brandon Scott -
> mckeanbs" <users-bounces at shibboleth.net on behalf of mckeanbs at jmu.edu
> > wrote:
> 
> > Hmm, doing more digging I found that I hadn't commented out the
> > encryption key/cert in credentials.xml
> 
> That file isn't used unless you're using a non-legacy relying party
> file, but if you are, then you need to have that credential defined.
> 
> > Is there something else that needs done for that part?
> 
> Disabling that would be a great deal of work if it's actually even
> possible. If you're concerned about not supporting decryption, just
> don't publish it in your metadata. It won't matter for anything
> you're testing anyway.
> 
> (None of this has anything to do with the error you posted.)
> 
> -- Scott
> 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150716/bfc6f645/attachment-0001.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 5673 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20150716/bfc6f645/attachment-0001.bin>


More information about the users mailing list