Box.net integration with shib 2.x

Rob Gorrell rwgorrel at uncg.edu
Thu Jun 11 14:45:43 EDT 2015


If I recall from our setup, Box does not expect to deal with encrypted
assertions by default, but are capable of doing so. If I remember
correctly, this was something I had to ask for from my Box account rep,
they flipped a switch on their end, provided alternate metadata, and then
we were off to the races.

-Rob


On Thu, Jun 11, 2015 at 1:15 PM, Rich Graves <rgraves at carleton.edu> wrote:

> When I turn off assertion encryption, it fails at "Not checking signature
> with configured verification cert 04:3B because it does not match the
> embeded certificate in the signature".
>
> The fragment "<ds:KeyInfo> <ds:X509Data>
> <ds:X509Certificate>MIIDujCCAqICCQCPaJ8ioTbhuDANBgkqhkiG9w0BAQUFADCBnjELMAkGA1UEBhMCVVMxEjAQBgNV"
> is the InCommon Federation Metadata Signing Key. What's that doing in
> there? I have pretty-printed the XML and *'d out signatures, otherwise this
> is what is echoed back to me by https://sso.services.box.net/sp/ACS.saml2
> after successful IdP authentication.
>
> Error - Single Sign-On
>
> Missing or invalid signature (UNVERIFIED commentary: [Not checking
> signature with configured verification cert 04:3B because it does not match
> the embeded certificate in the signature.]) on assertion
> (ID=_11822ead91053e4308987c3f8a660ff3). All assertions must have valid
> signatures because the Response was not signed or the system is configured
> to require a signed assertion from urn:mace:incommon:carleton.edu.
> InMessageContext XML:
>
> <?xml version="1.0"?>
> <saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"
> Destination="https://sso.services.box.net/sp/ACS.saml2"
> ID="_a94b91185ca73a9071c0c966932acb7c"
> InResponseTo="U7OpDG8_.Lp8bQkLkfFbRJ6AY9i"
> IssueInstant="2015-06-11T16:52:58.101Z" Version="2.0">
> <saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
> Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">urn:mace:incommon:
> carleton.edu</saml2:Issuer>
> <saml2p:Status>
>     <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
> </saml2p:Status>
> <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
> xmlns:xs="http://www.w3.org/2001/XMLSchema"
> ID="_11822ead91053e4308987c3f8a660ff3"
> IssueInstant="2015-06-11T16:52:58.101Z" Version="2.0">
> <saml2:Issuer
> Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">urn:mace:incommon:
> carleton.edu</saml2:Issuer>
> <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
> <ds:SignedInfo>
>     <ds:CanonicalizationMethod Algorithm="
> http://www.w3.org/2001/10/xml-exc-c14n#"/>
>     <ds:SignatureMethod Algorithm="
> http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
>     <ds:Reference URI="#_11822ead91053e4308987c3f8a660ff3">
>         <ds:Transforms>
>             <ds:Transform Algorithm="
> http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
>             <ds:Transform Algorithm="
> http://www.w3.org/2001/10/xml-exc-c14n#">
>             <ec:InclusiveNamespaces xmlns:ec="
> http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="xs"/>
>         </ds:Transform>
>     </ds:Transforms>
>     <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
>     <ds:DigestValue>BtA9Aqir/t4FN0ojzRc1pyv4hmM=</ds:DigestValue>
> </ds:Reference>
> </ds:SignedInfo>
>
> <ds:SignatureValue>BdGZ+tUISGxAZMf/0/**+qIhLWh9/icDj7XiAcESMK9bDkn3pKb/JQCe9rWokXz9cZehMiyIgvRC1S/vpnkxTAbY3Ib41Y2skiO6ePpgvyAET+0JRwwOHorPr3IRDavFBOCpt2k8HFyuA8RPiwssuLI4MMnYEbrhTupLZtsmeEm/X+mX3FVtotb/BD68rwLDaDUkyoK63bVdoilBoJf52AumJU+RUW0o/6KUQpcEO3gHm1tBsb+F10kSgWhiAayAPYbR1hdMC4olxpF10CamO4dXX6hdSDO3CWJXC4Trw==</ds:SignatureValue>
> <ds:KeyInfo>
>     <ds:X509Data>
>
> <ds:X509Certificate>MIIDujCCAqICCQCPaJ8ioTbhuDANBgkqhkiG9w0BAQUFADCBnjELMAkGA1UEBhMCVVMxEjAQBgNV
> BAgTCU1pbm5lc290YTETMBEGA1UEBxMKTm9ydGhmaWVsZDEZMBcGA1UEChMQQ2FybGV0b24gQ29s
> bGVnZTEMMAoGA1UECxMDSVRTMRswGQYDVQQDExJsb2dpbi5jYXJsZXRvbi5lZHUxIDAeBgkqhkiG
> 9w0BCQEWEXdsZWVAY2FybGV0b24uZWR1MB4XDTEzMDIyMTIxNTEyMloXDTIzMDIxOTIxNTEyMlow
> gZ4xCzAJBgNVBAYTAlVTMRIwEAYDVQQIEwlNaW5uZXNvdGExEzARBgNVBAcTCk5vcnRoZmllbGQx
> GTAXBgNVBAoTEENhcmxldG9uIENvbGxlZ2UxDDAKBgNVBAsTA0lUUzEbMBkGA1UEAxMSbG9naW4u
> Y2FybGV0b24uZWR1MSAwHgYJKoZIhvcNAQkBFhF3bGVlQGNhcmxldG9uLmVkdTCCASIwDQYJKoZI
> hvcNAQEBBQADggEPADCCAQoCggEBAJJR4aGU0T4Rs+raiaCBqBp75XUZ+W0rnXVuP4oainijV8oe
> pLVo0trGRjYgIHhNKufhtuFtvxkgsq/QqaSR6mmCgKU8YH32gGggjwLBRbMn7aNiJu2PNi03g+Nx
> FW+k3iz/qcuyrkb9CGO5QcqMlWznphotRXXXscm94+SBmJ9aeTL4XIUXfEIOdeDdNqZRjjvuKck8
> 3Mbqn/4t69uZcrOM0BFQFhJOE5vgJ9kOEBnsS+3dYbEndfK1dXnxp88gLaWY/4GvvOUwQTubsuvy
> 9/hlyLUpNz/sZFNM7KekQUjKv2/qu3hi+gvl4Dl5LuEbug38XKZDQ75pZOm5PROnhKMCAwEAATAN
> BgkqhkiG9w0BAQUFAAOCAQEAdTupllJ0sDvllI+4Jgn+Dw
>  PTlzOM5I7Y2MVkHtodZCyrT6qRaP4o
> X369LVG0S3vQbChVi1gW0CljeUl9e616nkaNJ89UhUhN3r9t5412qQ8/Lyq+LX1912yUyCuW8JMQ
> XFbVlMS0b/FvJmXPYlLpFIf1DGbJW/HYJ07x+5V7hONXUmEvh8SZo+JXmTO37hLOBGSyteXbWJv7
> VptIm/fD6411cYLejujXijfbVj38Ijcucjrel7dJ2Zl8nnmkn3VlRFdEuRScuWudI+7rS6Ux+Dwc
> 25Ls34lI9+W9mXyA7ix0qDjNmpRccdkzLcvfTgYC7q5VGzyToU4S2u7AZvcxeA==</ds:X509Certificate>
>     </ds:X509Data>
> </ds:KeyInfo>
> </ds:Signature>
> <saml2:Subject>
>     <saml2:NameID
> Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"
> NameQualifier="urn:mace:incommon:carleton.edu" SPNameQualifier="
> https://services.box.com/sp
> ">_ae9e30e7df39432335f58006eeda7130</saml2:NameID>
>     <saml2:SubjectConfirmation
> Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
>         <saml2:SubjectConfirmationData Address="**"
> InResponseTo="U7OpDG8_.Lp8bQkLkfFbRJ6AY9i"
> NotOnOrAfter="2015-06-11T16:57:58.101Z" Recipient="
> https://sso.services.box.net/sp/ACS.saml2"/>
>     </saml2:SubjectConfirmation>
> </saml2:Subject>
> <saml2:Conditions NotBefore="2015-06-11T16:52:58.101Z"
> NotOnOrAfter="2015-06-11T16:57:58.101Z">
>     <saml2:AudienceRestriction>
>         <saml2:Audience>https://services.box.com/sp</saml2:Audience>
>     </saml2:AudienceRestriction>
> </saml2:Conditions>
> <saml2:AuthnStatement AuthnInstant="2015-06-11T16:49:44.586Z"
> SessionIndex="_edd04d9c807ec9584ced4afff65ba89f">
>     <saml2:SubjectLocality Address="**"/>
>     <saml2:AuthnContext>
>         <saml2:AuthnContextClassRef>duo</saml2:AuthnContextClassRef>
>     </saml2:AuthnContext>
> </saml2:AuthnStatement>
> <saml2:AttributeStatement>
>     <saml2:Attribute FriendlyName="sn" Name="urn:oid:2.5.4.4"
> NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
>         <saml2:AttributeValue xmlns:xsi="
> http://www.w3.org/2001/XMLSchema-instance"
> xsi:type="xs:string">Graves</saml2:AttributeValue>
>     </saml2:Attribute>
>     <saml2:Attribute FriendlyName="givenName" Name="urn:oid:2.5.4.42"
> NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
>         <saml2:AttributeValue xmlns:xsi="
> http://www.w3.org/2001/XMLSchema-instance"
> xsi:type="xs:string">Rich</saml2:AttributeValue>
>     </saml2:Attribute>
>     <saml2:Attribute FriendlyName="mail"
> Name="urn:oid:0.9.2342.19200300.100.1.3"
> NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
>         <saml2:AttributeValue xmlns:xsi="
> http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">
> rgraves at carleton.edu</saml2:AttributeValue>
>     </saml2:Attribute>
>     <saml2:Attribute FriendlyName="organizationalUnit"
> Name="urn:oid:2.5.4.11"
> NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
>         <saml2:AttributeValue xmlns:xsi="
> http://www.w3.org/2001/XMLSchema-instance"
> xsi:type="xs:string">Information Technology Service</saml2:AttributeValue>
>     </saml2:Attribute>
> </saml2:AttributeStatement>
> </saml2:Assertion>
> </saml2p:Response>
>
>  entityId: urn:mace:incommon:carleton.edu (IDP) Binding:
> urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST relayState:
> Ir8tVTR5NDHyZkHoc3ubo2iXxIMitE SignatureStatus: NOT_PRESENT Binding says to
> sign: true
> Partner: urn:mace:incommon:carleton.edu
> Target Resource: https://app.box.com/sso/ping_federate
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>



-- 
Robert W. Gorrell
Systems Architect, Identity and Access Management
University of NC at Greensboro
336-334-5954
PGP Key ID B36DB0CA
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150611/669ed622/attachment-0001.html>


More information about the users mailing list