Box.net integration with shib 2.x

Rich Graves rgraves at carleton.edu
Thu Jun 11 13:15:25 EDT 2015


When I turn off assertion encryption, it fails at "Not checking signature with configured verification cert 04:3B because it does not match the embeded certificate in the signature".

The fragment "<ds:KeyInfo> <ds:X509Data> <ds:X509Certificate>MIIDujCCAqICCQCPaJ8ioTbhuDANBgkqhkiG9w0BAQUFADCBnjELMAkGA1UEBhMCVVMxEjAQBgNV" is the InCommon Federation Metadata Signing Key. What's that doing in there? I have pretty-printed the XML and *'d out signatures, otherwise this is what is echoed back to me by https://sso.services.box.net/sp/ACS.saml2 after successful IdP authentication.

Error - Single Sign-On

Missing or invalid signature (UNVERIFIED commentary: [Not checking signature with configured verification cert 04:3B because it does not match the embeded certificate in the signature.]) on assertion (ID=_11822ead91053e4308987c3f8a660ff3). All assertions must have valid signatures because the Response was not signed or the system is configured to require a signed assertion from urn:mace:incommon:carleton.edu. InMessageContext XML: 

<?xml version="1.0"?>
<saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="https://sso.services.box.net/sp/ACS.saml2" ID="_a94b91185ca73a9071c0c966932acb7c" InResponseTo="U7OpDG8_.Lp8bQkLkfFbRJ6AY9i" IssueInstant="2015-06-11T16:52:58.101Z" Version="2.0">
<saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">urn:mace:incommon:carleton.edu</saml2:Issuer>
<saml2p:Status>
    <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
</saml2p:Status>
<saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:xs="http://www.w3.org/2001/XMLSchema" ID="_11822ead91053e4308987c3f8a660ff3" IssueInstant="2015-06-11T16:52:58.101Z" Version="2.0">
<saml2:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">urn:mace:incommon:carleton.edu</saml2:Issuer>
<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo>
    <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
    <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
    <ds:Reference URI="#_11822ead91053e4308987c3f8a660ff3">
        <ds:Transforms>
            <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
            <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#">
            <ec:InclusiveNamespaces xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="xs"/>
        </ds:Transform>
    </ds:Transforms>
    <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
    <ds:DigestValue>BtA9Aqir/t4FN0ojzRc1pyv4hmM=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>BdGZ+tUISGxAZMf/0/**+qIhLWh9/icDj7XiAcESMK9bDkn3pKb/JQCe9rWokXz9cZehMiyIgvRC1S/vpnkxTAbY3Ib41Y2skiO6ePpgvyAET+0JRwwOHorPr3IRDavFBOCpt2k8HFyuA8RPiwssuLI4MMnYEbrhTupLZtsmeEm/X+mX3FVtotb/BD68rwLDaDUkyoK63bVdoilBoJf52AumJU+RUW0o/6KUQpcEO3gHm1tBsb+F10kSgWhiAayAPYbR1hdMC4olxpF10CamO4dXX6hdSDO3CWJXC4Trw==</ds:SignatureValue>
<ds:KeyInfo>
    <ds:X509Data>
        <ds:X509Certificate>MIIDujCCAqICCQCPaJ8ioTbhuDANBgkqhkiG9w0BAQUFADCBnjELMAkGA1UEBhMCVVMxEjAQBgNV BAgTCU1pbm5lc290YTETMBEGA1UEBxMKTm9ydGhmaWVsZDEZMBcGA1UEChMQQ2FybGV0b24gQ29s bGVnZTEMMAoGA1UECxMDSVRTMRswGQYDVQQDExJsb2dpbi5jYXJsZXRvbi5lZHUxIDAeBgkqhkiG 9w0BCQEWEXdsZWVAY2FybGV0b24uZWR1MB4XDTEzMDIyMTIxNTEyMloXDTIzMDIxOTIxNTEyMlow gZ4xCzAJBgNVBAYTAlVTMRIwEAYDVQQIEwlNaW5uZXNvdGExEzARBgNVBAcTCk5vcnRoZmllbGQx GTAXBgNVBAoTEENhcmxldG9uIENvbGxlZ2UxDDAKBgNVBAsTA0lUUzEbMBkGA1UEAxMSbG9naW4u Y2FybGV0b24uZWR1MSAwHgYJKoZIhvcNAQkBFhF3bGVlQGNhcmxldG9uLmVkdTCCASIwDQYJKoZI hvcNAQEBBQADggEPADCCAQoCggEBAJJR4aGU0T4Rs+raiaCBqBp75XUZ+W0rnXVuP4oainijV8oe pLVo0trGRjYgIHhNKufhtuFtvxkgsq/QqaSR6mmCgKU8YH32gGggjwLBRbMn7aNiJu2PNi03g+Nx FW+k3iz/qcuyrkb9CGO5QcqMlWznphotRXXXscm94+SBmJ9aeTL4XIUXfEIOdeDdNqZRjjvuKck8 3Mbqn/4t69uZcrOM0BFQFhJOE5vgJ9kOEBnsS+3dYbEndfK1dXnxp88gLaWY/4GvvOUwQTubsuvy 9/hlyLUpNz/sZFNM7KekQUjKv2/qu3hi+gvl4Dl5LuEbug38XKZDQ75pZOm5PROnhKMCAwEAATAN BgkqhkiG9w0BAQUFAAOCAQEAdTupllJ0sDvllI+4Jgn+DwPTlzOM5I7Y2MVkHtodZCyrT6qRaP4o X369LVG0S3vQbChVi1gW0CljeUl9e616nkaNJ89UhUhN3r9t5412qQ8/Lyq+LX1912yUyCuW8JMQ XFbVlMS0b/FvJmXPYlLpFIf1DGbJW/HYJ07x+5V7hONXUmEvh8SZo+JXmTO37hLOBGSyteXbWJv7 VptIm/fD6411cYLejujXijfbVj38Ijcucjrel7dJ2Zl8nnmkn3VlRFdEuRScuWudI+7rS6Ux+Dwc 25Ls34lI9+W9mXyA7ix0qDjNmpRccdkzLcvfTgYC7q5VGzyToU4S2u7AZvcxeA==</ds:X509Certificate>
    </ds:X509Data>
</ds:KeyInfo>
</ds:Signature>
<saml2:Subject>
    <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" NameQualifier="urn:mace:incommon:carleton.edu" SPNameQualifier="https://services.box.com/sp">_ae9e30e7df39432335f58006eeda7130</saml2:NameID>
    <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
        <saml2:SubjectConfirmationData Address="**" InResponseTo="U7OpDG8_.Lp8bQkLkfFbRJ6AY9i" NotOnOrAfter="2015-06-11T16:57:58.101Z" Recipient="https://sso.services.box.net/sp/ACS.saml2"/>
    </saml2:SubjectConfirmation>
</saml2:Subject>
<saml2:Conditions NotBefore="2015-06-11T16:52:58.101Z" NotOnOrAfter="2015-06-11T16:57:58.101Z">
    <saml2:AudienceRestriction>
        <saml2:Audience>https://services.box.com/sp</saml2:Audience>
    </saml2:AudienceRestriction>
</saml2:Conditions>
<saml2:AuthnStatement AuthnInstant="2015-06-11T16:49:44.586Z" SessionIndex="_edd04d9c807ec9584ced4afff65ba89f">
    <saml2:SubjectLocality Address="**"/>
    <saml2:AuthnContext>
        <saml2:AuthnContextClassRef>duo</saml2:AuthnContextClassRef>
    </saml2:AuthnContext>
</saml2:AuthnStatement>
<saml2:AttributeStatement>
    <saml2:Attribute FriendlyName="sn" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
        <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">Graves</saml2:AttributeValue>
    </saml2:Attribute>
    <saml2:Attribute FriendlyName="givenName" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
        <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">Rich</saml2:AttributeValue>
    </saml2:Attribute>
    <saml2:Attribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
        <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">rgraves at carleton.edu</saml2:AttributeValue>
    </saml2:Attribute>
    <saml2:Attribute FriendlyName="organizationalUnit" Name="urn:oid:2.5.4.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
        <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">Information Technology Service</saml2:AttributeValue>
    </saml2:Attribute>
</saml2:AttributeStatement>
</saml2:Assertion>
</saml2p:Response>

 entityId: urn:mace:incommon:carleton.edu (IDP) Binding: urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST relayState: Ir8tVTR5NDHyZkHoc3ubo2iXxIMitE SignatureStatus: NOT_PRESENT Binding says to sign: true
Partner: urn:mace:incommon:carleton.edu
Target Resource: https://app.box.com/sso/ping_federate


More information about the users mailing list