Shibboleth SP Logout with encryption enabled
Jose Luis Canales Gasco
jlcanales at paradigmadigital.com
Wed Dec 14 08:53:16 EST 2016
Hi all,
I'm integrating Shibboleth SP with Idp 3.2.1. Signing and encryption is
enabled in SP shibboleth2.xml file in this way:
<ApplicationDefaults entityID="https://sp.local:8443/shibboleth-sp"
REMOTE_USER="eppn persistent-id targeted-id"
signing="true" encryption="true">
SSO works fine but when I try to logout from SP (
https://sp.host/Shibboleth.sso/Logout) the LogoutRequest cannot be
processed by the Idp and logout fails. I tried it with SP version 2.5.6 and
2.6.0 without success.
This is an extract from idp-process.log
2016-12-14 13:13:44,608 - INFO
[org.springframework.beans.factory.xml.XmlBeanDefinitionReader:317]-
Loading XML bean definitions from file
[/opt/tomcat/webapps/idp/idp/system/flows/saml/saml2/../security-beans.xml]
2016-12-14 13:13:44,624 - INFO
[org.springframework.web.context.support.GenericWebApplicationContext:578]-
Refreshing Flow ApplicationContext [intercept/security-policy/saml2-slo]:
startup date [Wed Dec 14 13:13:44 GMT 2016]; parent: WebApplicationContext
for namespace 'idp-servlet'
2016-12-14 13:13:44,625 - INFO
[org.springframework.beans.factory.support.DefaultListableBeanFactory:869]-
Replacing scope 'request' from
[org.springframework.web.context.request.RequestScope at 4011eb3] to
[org.springframework.web.context.request.RequestScope at 324bcfff]
2016-12-14 13:13:44,695 - INFO
[org.opensaml.xmlsec.keyinfo.impl.BasicProviderKeyInfoCredentialResolver:164]-
KeyInfo was null, any credentials will be resolved by post-processing hooks
only
2016-12-14 13:13:44,720 - ERROR
[org.opensaml.xmlsec.encryption.support.Decrypter:603]- Error decrypting
the encrypted data element
org.apache.xml.security.encryption.XMLEncryptionException: Illegal key size
at
org.apache.xml.security.encryption.XMLCipher.decryptToByteArray(XMLCipher.java:1852)
Caused by: java.security.InvalidKeyException: Illegal key size
at javax.crypto.Cipher.checkCryptoPerm(Cipher.java:1039)
2016-12-14 13:13:44,721 - ERROR
[org.opensaml.xmlsec.encryption.support.Decrypter:547]- Failed to decrypt
EncryptedData using either EncryptedData KeyInfoCredentialResolver or
EncryptedKeyResolver + EncryptedKey KeyInfoCredentialResolver
2016-12-14 13:13:44,722 - ERROR
[org.opensaml.saml.saml2.encryption.Decrypter:178]- SAML Decrypter
encountered an error decrypting element content
org.opensaml.xmlsec.encryption.support.DecryptionException: Failed to
decrypt EncryptedData
at
org.opensaml.xmlsec.encryption.support.Decrypter.decryptDataToDOM(Decrypter.java:550)
2016-12-14 13:13:44,722 - WARN
[org.opensaml.saml.saml2.profile.impl.DecryptNameIDs:99]- Profile Action
DecryptNameIDs: Failure performing decryption
org.opensaml.xmlsec.encryption.support.DecryptionException: Failed to
decrypt EncryptedData
at
org.opensaml.xmlsec.encryption.support.Decrypter.decryptDataToDOM(Decrypter.java:550)
2016-12-14 13:13:44,728 - WARN
[org.opensaml.profile.action.impl.LogEvent:76]- An error event occurred
while processing the request: DecryptNameIDFailed
This is the LogoutRequest sent by Shibboleth SP:
<?xml version="1.0" encoding="UTF-8"?>
<samlp:LogoutRequest
Destination="https://idp.local/idp/profile/SAML2/Redirect/SLO"
ID="_44c87f81bab5e6108be3ce67751df9ac"
IssueInstant="2016-12-14T13:13:44Z" Version="2.0"
xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol">
<saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">
https://sp.local:8443/shibboleth-sp</saml:Issuer>
<saml:EncryptedID xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">
<xenc:EncryptedData
Type="http://www.w3.org/2001/04/xmlenc#Element"
xmlns:xenc="http://www.w3.org/2001/04/xmlenc#">
<xenc:EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc
"/>
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<xenc:EncryptedKey xmlns:xenc="
http://www.w3.org/2001/04/xmlenc#">
<xenc:EncryptionMethod Algorithm="
http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p">
<ds:DigestMethod Algorithm="
http://www.w3.org/2000/09/xmldsig#sha1" xmlns:ds="
http://www.w3.org/2000/09/xmldsig#"/>
</xenc:EncryptionMethod>
<xenc:CipherData>
<xenc:CipherValue>FsfEPW0Q5JZk3Im+4tf2NXbYIafNCdaWlEC3/2kuvOMZVLLV/RoMw1RsIl7OUYl7Or/hgTzhLB9Y
37jf/qTk4gPv5R4VZ6l62yJHakQtDk3lZjMeubSn6BuPOF8wvnHuyYNCyiRcFWP8MtzAVQFBeiYw
RvcKM3y5x0BHpnjrh2eAbzigIftNF/U+1H4U++q6Tr4LR7lRcTi8We07Jv68uw/+Gab8zoRFiULK
vOnVK89A5Kb61vU0pXdYtCtAcJUbjwVv5pmfe9V1jI6qUWEx9Q28Rg5Sp7M1+LyOgE+Ml1jhNPLr
v3jBBDlJSCr8KWpwvgZ5HbUzlSsYTE5bE/uwhA==</xenc:CipherValue>
</xenc:CipherData>
</xenc:EncryptedKey>
</ds:KeyInfo>
<xenc:CipherData>
<xenc:CipherValue>7IbLRF02XwgdX8LmpsEdNKU2ri6e9XVD6KG8NVMxa5T9H7u+CaMal2qXi1k00PWX0m+cvOzGj/t5
TL1KQYTJxvcpp0XcxJwd8m0voI3VGCdOCBhUlEjg0AufyhGYgP7X6KEllZTFv4kAHLoWA+hw2IZg
MR3/e1nX8v+oxwZP9ujOQ6HYCbWup1L6ziJMo5s8IbX6460hT/hoTGCP/1BzqBCySqwYOJf01qaa
RKj2AEE3ws7imeTfc8p8jE28FrFluUZKIsokSc1LAsSvjAiUTa8++5dCODF/PFHAR7dD/CUEOTGQ
4u82oEtbk5Zs4+Ff8Xosrhl4/sZOB5wDwDiJUcbdn6tt9EE0pIoaxQ9dYomD6SHtGyOtgJtxnZRx
sKm/EImVuo8dr9Es1icr9ZFSmg==</xenc:CipherValue>
</xenc:CipherData>
</xenc:EncryptedData>
</saml:EncryptedID>
<samlp:SessionIndex>_299489b8cabc2f4dbdfe503ffff326eb</samlp:SessionIndex>
</samlp:LogoutRequest>
I suppose SP or Idp has some kind of configuration issue, but I cannot find
it.
Could you give some ideas to solve it?
Thanks,
--
----------------------------------------------------------
José Luis Canales Gasco
Vía de las Dos Castillas, 33. Ática 4. 2ª Planta
28224 Pozuelo de Alarcón, Madrid
Tel.: 91 352 59 42 // @paradigmate
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161214/8db0d4d5/attachment.html>
More information about the users
mailing list