Error on signing outbound SAML message
Bogdan Albei
bogdan.albei at callsign.com
Wed Jan 6 10:56:07 EST 2016
This is the response sent to the SP:
<saml2p:Response Destination="https://sp.testshib.org/Shibboleth.sso/SAML2/POST"
ID="_d6cf60550650affba554471ff5c19848"
InResponseTo="_7b53d45db57c6b5176e0c245fa860983"
IssueInstant="2016-01-06T15:53:08.544Z"
Version="2.0"
xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"
xmlns:xsd="http://www.w3.org/2001/XMLSchema"
>
<saml2:Issuer
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">http://localhost:8080/saml/2e/shibboleth</saml2:Issuer>
<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo>
<ds:CanonicalizationMethod
Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
<ds:SignatureMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512" />
<ds:Reference URI="#_d6cf60550650affba554471ff5c19848">
<ds:Transforms>
<ds:Transform
Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" />
<ds:Transform
Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#">
<ec:InclusiveNamespaces PrefixList="xsd"
xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#"
/>
</ds:Transform>
</ds:Transforms>
<ds:DigestMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#sha512" />
<ds:DigestValue>zz/MXzGmNE08H+0j1JdLEMgfa0LghkP9ftGr+zYWXoiWgVh4nr+vyXP6zONDe1BPZth4SEHiqUk+
FNR0+hvZZg==</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>
G9KQ5FKHHQRRB5in3/1Qv5Zt1Al5QizCEXr3LHiLQUCrMps+RYHmCnK5SgpXLEF/tPWxKPnAOnpf
dY3h+uJDNwZTD9j8TL+Xs167p4YcVOimYus/3mkMrebIxqstEhdu8ClcNyihirHmQ6JbiaUsJBff
AUJsAOD4tIM9r9znTKYCYJOqqW/0xm+RHqVu4uvroGJK4wfeBGbMLKnRs7cq59xee2cXrzNz2zyh
8PzxlzpQj2NC9nnyHJaA7x1WNqZrZL5r/WUAqpi10jWPXEI5nM342sUWNy6Bx7JFEYO/c1zF3SnC
Dfa4BpK7DP0m1KgIk+C4LcTSfloGqQ5oNiFiOQ==
</ds:SignatureValue>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>MIIC7jCCAdagAwIBAgIVAMitRIDQ/S+pmNiWOrCRMawt0kz0MA0GCSqGSIb3DQEBCwUAMBQxEjAQ
BgNVBAMMCWxvY2FsaG9zdDAeFw0xNjAxMDQxMDU3NDBaFw0xOTAxMDQxMDU3NDBaMBQxEjAQBgNV
BAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKFp3sHDj1O5jVVN
TbzImTSKHsaWIvDH3OrTX9ViuSf+lXyvqcYQVUQAp70P8kqIaeAlDdpU7bqTfNuDJ9eD/TE1xgZK
7KtR5rx/MHEiTcV10XMPgiAem9K5egnDKtElYT6K02pYGMPCBAq+BMmS0IqjA1GuOox999MdV3Rs
eCisStJlzWSxa0qcKcwAyTODzQ1mTq1/B5ng7E8QZsgUbYLELWnt6TdssmIBGuxCWDI9Tn2ozo92
mJwjXVP0ghF8lfNR6+HRuLm56oEa4U1l54HNdbBixLrE6NReUd/mERzDKO/pjUI3eCD4aC0JanbS
UmzrzrKVvBYZ6hwX1CdQuUUCAwEAAaM3MDUwHQYDVR0OBBYEFLUMx35bNYzZdQeRraahy1ThLoG8
MBQGA1UdEQQNMAuCCWxvY2FsaG9zdDANBgkqhkiG9w0BAQsFAAOCAQEAIjOwlHqvxG7RVDgRe0iw
v+P4oRaJxHV2WkIfo0z/Jn+kX+w2HyXfGiJyAFnS/vwcsZR/hGvD1q5EIsqBWFLH2iQXdDXC6o/Q
0cXXlLT4bp1dHJ3yyG5h3wWJbJYO8Br4E2l4T0tvGlHk26OZs0T69ycC9xkKW1zbfCEYSFj8OL2J
Yq/KQGQeUWdKtakBjP4sikP6739imAgPkNIfsaJBu2Qd7FjPrrJf1CZD9gFieE/VO/hioWObkSsG
enMQ37aCkrXgotgkFXqGiUJodHht9Ge///xU0irD6O7zkI6896RsmNunf+iSqFIdc7/apc/ytSMz
0quyqFLk9s0stMDoEg==</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</ds:Signature>
<saml2p:Status>
<saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success" />
</saml2p:Status>
<saml2:Assertion ID="_027833a60d09dff2a18540868d93d4f4"
IssueInstant="2016-01-06T15:53:08.544Z"
Version="2.0"
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
>
<saml2:Issuer>http://localhost:8080/saml/2e/shibboleth</saml2:Issuer>
<saml2:Subject>
<saml2:NameID
Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"
NameQualifier="http://localhost:8080/saml/2e/shibboleth"
SPNameQualifier="https://sp.testshib.org/shibboleth-sp"
>AAdzZWNyZXQxMSJJhBe+HIgXoaaB8i6tZjTQUFBLYfnoUQIi2M3BLhCDSBL/dQy5cp1+SRDYNW5rXGBsq8bG+W7SbrU9xMjcZsfPge9/ySW5En+9Kzv0PfgN0gjrcYN8LSwwydjNmnNv061pdvxQ</saml2:NameID>
<saml2:SubjectConfirmation
Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
<saml2:SubjectConfirmationData Address="0:0:0:0:0:0:0:1"
InResponseTo="_7b53d45db57c6b5176e0c245fa860983"
NotOnOrAfter="2016-01-06T15:58:08.628Z"
Recipient="https://sp.testshib.org/Shibboleth.sso/SAML2/POST"
/>
</saml2:SubjectConfirmation>
</saml2:Subject>
<saml2:Conditions NotBefore="2016-01-06T15:53:08.544Z"
NotOnOrAfter="2016-01-06T15:58:08.544Z"
>
<saml2:AudienceRestriction>
<saml2:Audience>https://sp.testshib.org/shibboleth-sp</saml2:Audience>
</saml2:AudienceRestriction>
</saml2:Conditions>
<saml2:AuthnStatement AuthnInstant="2016-01-06T15:53:08.300Z"
SessionIndex="_f9c8b4b8492327df3e214179029d4111"
>
<saml2:SubjectLocality Address="0:0:0:0:0:0:0:1" />
<saml2:AuthnContext>
<saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef>
</saml2:AuthnContext>
</saml2:AuthnStatement>
<saml2:AttributeStatement>
<saml2:Attribute FriendlyName="lastname"
Name="lastname"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"
>
<saml2:AttributeValue
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:type="xsd:string"
>Albei</saml2:AttributeValue>
</saml2:Attribute>
<saml2:Attribute FriendlyName="firstname"
Name="firstname"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"
>
<saml2:AttributeValue
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:type="xsd:string"
>Bogdan</saml2:AttributeValue>
</saml2:Attribute>
<saml2:Attribute FriendlyName="callsign"
Name="callsign"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"
>
<saml2:AttributeValue
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:type="xsd:string"
>gigi3</saml2:AttributeValue>
</saml2:Attribute>
</saml2:AttributeStatement>
</saml2:Assertion>
</saml2p:Response>
And this is the metadata:
<EntitiesDescriptor Name="urn:mace:shibboleth:callsign"
xmlns="urn:oasis:names:tc:SAML:2.0:metadata"
xmlns:ds="http://www.w3.org/2000f/09/xmldsig#"
xmlns:mdalg="urn:oasis:names:tc:SAML:metadata:algsupport"
xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui"
xmlns:shibmd="urn:mace:shibboleth:metadata:1.0"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<EntityDescriptor entityID="http://localhost:8080/saml/2e/shibboleth">
<Extensions> <mdalg:DigestMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#sha512" />
<mdalg:DigestMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384" />
<mdalg:DigestMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" />
<mdalg:SigningMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512" />
<mdalg:SigningMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384" />
<mdalg:SigningMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" />
</Extensions>
<IDPSSODescriptor
protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol
urn:mace:shibboleth:1.0 urn:oasis:names:tc:SAML:2.0:protocol">
<Extensions> <shibmd:Scope
regexp="false">localhost</shibmd:Scope> <mdui:UIInfo>
<mdui:DisplayName
xml:lang="en">Callsign</mdui:DisplayName>
<mdui:Description xml:lang="en">Callsign IdP</mdui:Description>
<mdui:Logo height="88"
width="253">https://auth.callsign.com/saml/resources/base/images/callsign-logo-full-green.png</mdui:Logo>
</mdui:UIInfo>
</Extensions> <KeyDescriptor>
<ds:KeyInfo> <ds:X509Data>
<ds:X509Certificate>
MIIC7jCCAdagAwIBAgIVAMitRIDQ/S+pmNiWOrCRMawt0kz0MA0GCSqGSIb3DQEB
CwUAMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDAeFw0xNjAxMDQxMDU3NDBaFw0xOTAx
MDQxMDU3NDBaMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAKFp3sHDj1O5jVVNTbzImTSKHsaWIvDH3OrTX9ViuSf+
lXyvqcYQVUQAp70P8kqIaeAlDdpU7bqTfNuDJ9eD/TE1xgZK7KtR5rx/MHEiTcV1
0XMPgiAem9K5egnDKtElYT6K02pYGMPCBAq+BMmS0IqjA1GuOox999MdV3RseCis
StJlzWSxa0qcKcwAyTODzQ1mTq1/B5ng7E8QZsgUbYLELWnt6TdssmIBGuxCWDI9
Tn2ozo92mJwjXVP0ghF8lfNR6+HRuLm56oEa4U1l54HNdbBixLrE6NReUd/mERzD
KO/pjUI3eCD4aC0JanbSUmzrzrKVvBYZ6hwX1CdQuUUCAwEAAaM3MDUwHQYDVR0O
BBYEFLUMx35bNYzZdQeRraahy1ThLoG8MBQGA1UdEQQNMAuCCWxvY2FsaG9zdDAN
BgkqhkiG9w0BAQsFAAOCAQEAIjOwlHqvxG7RVDgRe0iwv+P4oRaJxHV2WkIfo0z/
Jn+kX+w2HyXfGiJyAFnS/vwcsZR/hGvD1q5EIsqBWFLH2iQXdDXC6o/Q0cXXlLT4
bp1dHJ3yyG5h3wWJbJYO8Br4E2l4T0tvGlHk26OZs0T69ycC9xkKW1zbfCEYSFj8
OL2JYq/KQGQeUWdKtakBjP4sikP6739imAgPkNIfsaJBu2Qd7FjPrrJf1CZD9gFi
eE/VO/hioWObkSsGenMQ37aCkrXgotgkFXqGiUJodHht9Ge///xU0irD6O7zkI68
96RsmNunf+iSqFIdc7/apc/ytSMz0quyqFLk9s0stMDoEg==
</ds:X509Certificate>
</ds:X509Data> </ds:KeyInfo>
<EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/>
<EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc" />
<EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
<EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
<EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
<EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-1_5"/>
</KeyDescriptor>
<ArtifactResolutionService
Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
Location="https://idp.testshib.org:8443/idp/profile/SAML1/SOAP/ArtifactResolution"
index="1"/>
<ArtifactResolutionService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"
Location="https://idp.testshib.org:8443/idp/profile/SAML2/SOAP/ArtifactResolution"
index="2"/>
<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
<SingleSignOnService
Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest"
Location="http://localhost:8080/saml/2e/profile/Shibboleth/SSO"/>
<SingleSignOnService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
Location="http://localhost:8080/saml/2e/profile/SAML2/POST/SSO"/>
<SingleSignOnService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
Location="http://localhost:8080/saml/2e/profile/SAML2/Redirect/SSO"/>
<SingleSignOnService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"
Location="http://localhost:8080/saml/2e/profile/SAML2/SOAP/ECP"/>
</IDPSSODescriptor>
<AttributeAuthorityDescriptor
protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol
urn:oasis:names:tc:SAML:2.0:protocol">
<KeyDescriptor> <ds:KeyInfo>
<ds:X509Data> <ds:X509Certificate>
MIIC7jCCAdagAwIBAgIVAMitRIDQ/S+pmNiWOrCRMawt0kz0MA0GCSqGSIb3DQEB
CwUAMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDAeFw0xNjAxMDQxMDU3NDBaFw0xOTAx
MDQxMDU3NDBaMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAKFp3sHDj1O5jVVNTbzImTSKHsaWIvDH3OrTX9ViuSf+
lXyvqcYQVUQAp70P8kqIaeAlDdpU7bqTfNuDJ9eD/TE1xgZK7KtR5rx/MHEiTcV1
0XMPgiAem9K5egnDKtElYT6K02pYGMPCBAq+BMmS0IqjA1GuOox999MdV3RseCis
StJlzWSxa0qcKcwAyTODzQ1mTq1/B5ng7E8QZsgUbYLELWnt6TdssmIBGuxCWDI9
Tn2ozo92mJwjXVP0ghF8lfNR6+HRuLm56oEa4U1l54HNdbBixLrE6NReUd/mERzD
KO/pjUI3eCD4aC0JanbSUmzrzrKVvBYZ6hwX1CdQuUUCAwEAAaM3MDUwHQYDVR0O
BBYEFLUMx35bNYzZdQeRraahy1ThLoG8MBQGA1UdEQQNMAuCCWxvY2FsaG9zdDAN
BgkqhkiG9w0BAQsFAAOCAQEAIjOwlHqvxG7RVDgRe0iwv+P4oRaJxHV2WkIfo0z/
Jn+kX+w2HyXfGiJyAFnS/vwcsZR/hGvD1q5EIsqBWFLH2iQXdDXC6o/Q0cXXlLT4
bp1dHJ3yyG5h3wWJbJYO8Br4E2l4T0tvGlHk26OZs0T69ycC9xkKW1zbfCEYSFj8
OL2JYq/KQGQeUWdKtakBjP4sikP6739imAgPkNIfsaJBu2Qd7FjPrrJf1CZD9gFi
eE/VO/hioWObkSsGenMQ37aCkrXgotgkFXqGiUJodHht9Ge///xU0irD6O7zkI68
96RsmNunf+iSqFIdc7/apc/ytSMz0quyqFLk9s0stMDoEg==
</ds:X509Certificate>
</ds:X509Data> </ds:KeyInfo>
<EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/>
<EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc" />
<EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
<EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
<EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
<EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-1_5"/>
</KeyDescriptor>
<AttributeService
Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"
Location="https://idp.testshib.org:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
<AttributeService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"
Location="https://idp.testshib.org:8443/idp/profile/SAML2/SOAP/AttributeQuery"/>
<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
</AttributeAuthorityDescriptor>
<Organization> <OrganizationName
xml:lang="en">Callsign Identity Provider</OrganizationName>
<OrganizationDisplayName
xml:lang="en">Callsign</OrganizationDisplayName>
<OrganizationURL
xml:lang="en">http://www.callsign.com</OrganizationURL>
</Organization> <!-- <ContactPerson
contactType="technical">
<GivenName>Nate</GivenName>
<SurName>Klingenstein</SurName>
<EmailAddress>ndk at internet2.edu</EmailAddress>
</ContactPerson> --> </EntityDescriptor></EntitiesDescriptor>
On 6 January 2016 at 15:48, Cantor, Scott <cantor.2 at osu.edu> wrote:
> Fundamentally, you can't be using default algorithms. Either the
> encryption algorithm(s) were changed from the defaults, or there has to be
> SP metadata containing extension elements that are causing it to switch to
> some algorithm that's triggering a bug.
>
> We need to see the XML produced by the encryption step before it tries to
> sign the response. I don't know if that's even possible, so I would switch
> things and turn off response signing so that it logs the final output it
> sends to the SP. That might provide a hint about what it's doing that's not
> routine.
>
> I would like to see the metadata as well.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
--
Bogdan Albei
Senior Platform Engineer
Callsign Inc.
[C] bogdan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160106/57b23960/attachment-0001.html>
More information about the users
mailing list