Shibboleth SP Logout with encryption enabled

Jose Luis Canales Gasco jlcanales at paradigmadigital.com
Wed Dec 14 08:53:16 EST 2016


Hi all,

  I'm integrating Shibboleth SP with Idp 3.2.1.  Signing and encryption is
enabled in SP shibboleth2.xml file in this way:

      <ApplicationDefaults entityID="https://sp.local:8443/shibboleth-sp"
                         REMOTE_USER="eppn persistent-id targeted-id"
signing="true" encryption="true">

 SSO works fine but when I try to logout from SP (
https://sp.host/Shibboleth.sso/Logout) the LogoutRequest cannot be
processed by the Idp and logout fails. I tried it with SP version 2.5.6 and
2.6.0 without success.


This is an extract from idp-process.log

 2016-12-14 13:13:44,608 - INFO
[org.springframework.beans.factory.xml.XmlBeanDefinitionReader:317]-
Loading XML bean definitions from file
[/opt/tomcat/webapps/idp/idp/system/flows/saml/saml2/../security-beans.xml]
2016-12-14 13:13:44,624 - INFO
[org.springframework.web.context.support.GenericWebApplicationContext:578]-
Refreshing Flow ApplicationContext [intercept/security-policy/saml2-slo]:
startup date [Wed Dec 14 13:13:44 GMT 2016]; parent: WebApplicationContext
for namespace 'idp-servlet'
2016-12-14 13:13:44,625 - INFO
[org.springframework.beans.factory.support.DefaultListableBeanFactory:869]-
Replacing scope 'request' from
[org.springframework.web.context.request.RequestScope at 4011eb3] to
[org.springframework.web.context.request.RequestScope at 324bcfff]
2016-12-14 13:13:44,695 - INFO
[org.opensaml.xmlsec.keyinfo.impl.BasicProviderKeyInfoCredentialResolver:164]-
KeyInfo was null, any credentials will be resolved by post-processing hooks
only
2016-12-14 13:13:44,720 - ERROR
[org.opensaml.xmlsec.encryption.support.Decrypter:603]- Error decrypting
the encrypted data element
org.apache.xml.security.encryption.XMLEncryptionException: Illegal key size
    at
org.apache.xml.security.encryption.XMLCipher.decryptToByteArray(XMLCipher.java:1852)
Caused by: java.security.InvalidKeyException: Illegal key size
    at javax.crypto.Cipher.checkCryptoPerm(Cipher.java:1039)
2016-12-14 13:13:44,721 - ERROR
[org.opensaml.xmlsec.encryption.support.Decrypter:547]- Failed to decrypt
EncryptedData using either EncryptedData KeyInfoCredentialResolver or
EncryptedKeyResolver + EncryptedKey KeyInfoCredentialResolver
2016-12-14 13:13:44,722 - ERROR
[org.opensaml.saml.saml2.encryption.Decrypter:178]- SAML Decrypter
encountered an error decrypting element content
org.opensaml.xmlsec.encryption.support.DecryptionException: Failed to
decrypt EncryptedData
    at
org.opensaml.xmlsec.encryption.support.Decrypter.decryptDataToDOM(Decrypter.java:550)
2016-12-14 13:13:44,722 - WARN
[org.opensaml.saml.saml2.profile.impl.DecryptNameIDs:99]- Profile Action
DecryptNameIDs: Failure performing decryption
org.opensaml.xmlsec.encryption.support.DecryptionException: Failed to
decrypt EncryptedData
    at
org.opensaml.xmlsec.encryption.support.Decrypter.decryptDataToDOM(Decrypter.java:550)
2016-12-14 13:13:44,728 - WARN
[org.opensaml.profile.action.impl.LogEvent:76]- An error event occurred
while processing the request: DecryptNameIDFailed


This is the LogoutRequest sent by Shibboleth SP:

<?xml version="1.0" encoding="UTF-8"?>
<samlp:LogoutRequest
        Destination="https://idp.local/idp/profile/SAML2/Redirect/SLO"
        ID="_44c87f81bab5e6108be3ce67751df9ac"
        IssueInstant="2016-12-14T13:13:44Z" Version="2.0"
xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol">
    <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">
https://sp.local:8443/shibboleth-sp</saml:Issuer>
    <saml:EncryptedID xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">
        <xenc:EncryptedData
                Type="http://www.w3.org/2001/04/xmlenc#Element"
                xmlns:xenc="http://www.w3.org/2001/04/xmlenc#">
            <xenc:EncryptionMethod
                    Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc
"/>
            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
                <xenc:EncryptedKey xmlns:xenc="
http://www.w3.org/2001/04/xmlenc#">
                    <xenc:EncryptionMethod Algorithm="
http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p">
                        <ds:DigestMethod Algorithm="
http://www.w3.org/2000/09/xmldsig#sha1" xmlns:ds="
http://www.w3.org/2000/09/xmldsig#"/>
                    </xenc:EncryptionMethod>
                    <xenc:CipherData>

<xenc:CipherValue>FsfEPW0Q5JZk3Im+4tf2NXbYIafNCdaWlEC3/2kuvOMZVLLV/RoMw1RsIl7OUYl7Or/hgTzhLB9Y

37jf/qTk4gPv5R4VZ6l62yJHakQtDk3lZjMeubSn6BuPOF8wvnHuyYNCyiRcFWP8MtzAVQFBeiYw

RvcKM3y5x0BHpnjrh2eAbzigIftNF/U+1H4U++q6Tr4LR7lRcTi8We07Jv68uw/+Gab8zoRFiULK

vOnVK89A5Kb61vU0pXdYtCtAcJUbjwVv5pmfe9V1jI6qUWEx9Q28Rg5Sp7M1+LyOgE+Ml1jhNPLr

v3jBBDlJSCr8KWpwvgZ5HbUzlSsYTE5bE/uwhA==</xenc:CipherValue>
                    </xenc:CipherData>
                </xenc:EncryptedKey>
            </ds:KeyInfo>
            <xenc:CipherData>

<xenc:CipherValue>7IbLRF02XwgdX8LmpsEdNKU2ri6e9XVD6KG8NVMxa5T9H7u+CaMal2qXi1k00PWX0m+cvOzGj/t5

TL1KQYTJxvcpp0XcxJwd8m0voI3VGCdOCBhUlEjg0AufyhGYgP7X6KEllZTFv4kAHLoWA+hw2IZg

MR3/e1nX8v+oxwZP9ujOQ6HYCbWup1L6ziJMo5s8IbX6460hT/hoTGCP/1BzqBCySqwYOJf01qaa

RKj2AEE3ws7imeTfc8p8jE28FrFluUZKIsokSc1LAsSvjAiUTa8++5dCODF/PFHAR7dD/CUEOTGQ

4u82oEtbk5Zs4+Ff8Xosrhl4/sZOB5wDwDiJUcbdn6tt9EE0pIoaxQ9dYomD6SHtGyOtgJtxnZRx
                    sKm/EImVuo8dr9Es1icr9ZFSmg==</xenc:CipherValue>
            </xenc:CipherData>
        </xenc:EncryptedData>
    </saml:EncryptedID>

<samlp:SessionIndex>_299489b8cabc2f4dbdfe503ffff326eb</samlp:SessionIndex>
</samlp:LogoutRequest>


I suppose SP or Idp has some kind of configuration issue, but I cannot find
it.
Could you give some ideas to solve it?

Thanks,

-- 
----------------------------------------------------------
José Luis Canales Gasco


Vía de las Dos Castillas, 33. Ática 4. 2ª Planta
28224 Pozuelo de Alarcón, Madrid
Tel.: 91 352 59 42 // @paradigmate
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161214/8db0d4d5/attachment.html>


More information about the users mailing list