Error on signing outbound SAML message

Bogdan Albei bogdan.albei at callsign.com
Wed Jan 6 10:56:07 EST 2016


This is the response sent to the SP:

<saml2p:Response Destination="https://sp.testshib.org/Shibboleth.sso/SAML2/POST"
                 ID="_d6cf60550650affba554471ff5c19848"
                 InResponseTo="_7b53d45db57c6b5176e0c245fa860983"
                 IssueInstant="2016-01-06T15:53:08.544Z"
                 Version="2.0"
                 xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"
                 xmlns:xsd="http://www.w3.org/2001/XMLSchema"
                 >
    <saml2:Issuer
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">http://localhost:8080/saml/2e/shibboleth</saml2:Issuer>
    <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:SignedInfo>
            <ds:CanonicalizationMethod
Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
            <ds:SignatureMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512" />
            <ds:Reference URI="#_d6cf60550650affba554471ff5c19848">
                <ds:Transforms>
                    <ds:Transform
Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" />
                    <ds:Transform
Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#">
                        <ec:InclusiveNamespaces PrefixList="xsd"

xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#"
                                                />
                    </ds:Transform>
                </ds:Transforms>
                <ds:DigestMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#sha512" />

<ds:DigestValue>zz/MXzGmNE08H+0j1JdLEMgfa0LghkP9ftGr+zYWXoiWgVh4nr+vyXP6zONDe1BPZth4SEHiqUk+
FNR0+hvZZg==</ds:DigestValue>
            </ds:Reference>
        </ds:SignedInfo>
        <ds:SignatureValue>
G9KQ5FKHHQRRB5in3/1Qv5Zt1Al5QizCEXr3LHiLQUCrMps+RYHmCnK5SgpXLEF/tPWxKPnAOnpf
dY3h+uJDNwZTD9j8TL+Xs167p4YcVOimYus/3mkMrebIxqstEhdu8ClcNyihirHmQ6JbiaUsJBff
AUJsAOD4tIM9r9znTKYCYJOqqW/0xm+RHqVu4uvroGJK4wfeBGbMLKnRs7cq59xee2cXrzNz2zyh
8PzxlzpQj2NC9nnyHJaA7x1WNqZrZL5r/WUAqpi10jWPXEI5nM342sUWNy6Bx7JFEYO/c1zF3SnC
Dfa4BpK7DP0m1KgIk+C4LcTSfloGqQ5oNiFiOQ==
</ds:SignatureValue>
        <ds:KeyInfo>
            <ds:X509Data>

<ds:X509Certificate>MIIC7jCCAdagAwIBAgIVAMitRIDQ/S+pmNiWOrCRMawt0kz0MA0GCSqGSIb3DQEBCwUAMBQxEjAQ
BgNVBAMMCWxvY2FsaG9zdDAeFw0xNjAxMDQxMDU3NDBaFw0xOTAxMDQxMDU3NDBaMBQxEjAQBgNV
BAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKFp3sHDj1O5jVVN
TbzImTSKHsaWIvDH3OrTX9ViuSf+lXyvqcYQVUQAp70P8kqIaeAlDdpU7bqTfNuDJ9eD/TE1xgZK
7KtR5rx/MHEiTcV10XMPgiAem9K5egnDKtElYT6K02pYGMPCBAq+BMmS0IqjA1GuOox999MdV3Rs
eCisStJlzWSxa0qcKcwAyTODzQ1mTq1/B5ng7E8QZsgUbYLELWnt6TdssmIBGuxCWDI9Tn2ozo92
mJwjXVP0ghF8lfNR6+HRuLm56oEa4U1l54HNdbBixLrE6NReUd/mERzDKO/pjUI3eCD4aC0JanbS
UmzrzrKVvBYZ6hwX1CdQuUUCAwEAAaM3MDUwHQYDVR0OBBYEFLUMx35bNYzZdQeRraahy1ThLoG8
MBQGA1UdEQQNMAuCCWxvY2FsaG9zdDANBgkqhkiG9w0BAQsFAAOCAQEAIjOwlHqvxG7RVDgRe0iw
v+P4oRaJxHV2WkIfo0z/Jn+kX+w2HyXfGiJyAFnS/vwcsZR/hGvD1q5EIsqBWFLH2iQXdDXC6o/Q
0cXXlLT4bp1dHJ3yyG5h3wWJbJYO8Br4E2l4T0tvGlHk26OZs0T69ycC9xkKW1zbfCEYSFj8OL2J
Yq/KQGQeUWdKtakBjP4sikP6739imAgPkNIfsaJBu2Qd7FjPrrJf1CZD9gFieE/VO/hioWObkSsG
enMQ37aCkrXgotgkFXqGiUJodHht9Ge///xU0irD6O7zkI6896RsmNunf+iSqFIdc7/apc/ytSMz
0quyqFLk9s0stMDoEg==</ds:X509Certificate>
            </ds:X509Data>
        </ds:KeyInfo>
    </ds:Signature>
    <saml2p:Status>
        <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success" />
    </saml2p:Status>
    <saml2:Assertion ID="_027833a60d09dff2a18540868d93d4f4"
                     IssueInstant="2016-01-06T15:53:08.544Z"
                     Version="2.0"
                     xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
                     >
        <saml2:Issuer>http://localhost:8080/saml/2e/shibboleth</saml2:Issuer>
        <saml2:Subject>
            <saml2:NameID
Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"

NameQualifier="http://localhost:8080/saml/2e/shibboleth"

SPNameQualifier="https://sp.testshib.org/shibboleth-sp"

>AAdzZWNyZXQxMSJJhBe+HIgXoaaB8i6tZjTQUFBLYfnoUQIi2M3BLhCDSBL/dQy5cp1+SRDYNW5rXGBsq8bG+W7SbrU9xMjcZsfPge9/ySW5En+9Kzv0PfgN0gjrcYN8LSwwydjNmnNv061pdvxQ</saml2:NameID>
            <saml2:SubjectConfirmation
Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
                <saml2:SubjectConfirmationData Address="0:0:0:0:0:0:0:1"

InResponseTo="_7b53d45db57c6b5176e0c245fa860983"

NotOnOrAfter="2016-01-06T15:58:08.628Z"

Recipient="https://sp.testshib.org/Shibboleth.sso/SAML2/POST"
                                               />
            </saml2:SubjectConfirmation>
        </saml2:Subject>
        <saml2:Conditions NotBefore="2016-01-06T15:53:08.544Z"
                          NotOnOrAfter="2016-01-06T15:58:08.544Z"
                          >
            <saml2:AudienceRestriction>

<saml2:Audience>https://sp.testshib.org/shibboleth-sp</saml2:Audience>
            </saml2:AudienceRestriction>
        </saml2:Conditions>
        <saml2:AuthnStatement AuthnInstant="2016-01-06T15:53:08.300Z"
                              SessionIndex="_f9c8b4b8492327df3e214179029d4111"
                              >
            <saml2:SubjectLocality Address="0:0:0:0:0:0:0:1" />
            <saml2:AuthnContext>

<saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef>
            </saml2:AuthnContext>
        </saml2:AuthnStatement>
        <saml2:AttributeStatement>
            <saml2:Attribute FriendlyName="lastname"
                             Name="lastname"

NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"
                             >
                <saml2:AttributeValue
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
                                      xsi:type="xsd:string"
                                      >Albei</saml2:AttributeValue>
            </saml2:Attribute>
            <saml2:Attribute FriendlyName="firstname"
                             Name="firstname"

NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"
                             >
                <saml2:AttributeValue
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
                                      xsi:type="xsd:string"
                                      >Bogdan</saml2:AttributeValue>
            </saml2:Attribute>
            <saml2:Attribute FriendlyName="callsign"
                             Name="callsign"

NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"
                             >
                <saml2:AttributeValue
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
                                      xsi:type="xsd:string"
                                      >gigi3</saml2:AttributeValue>
            </saml2:Attribute>
        </saml2:AttributeStatement>
    </saml2:Assertion>
</saml2p:Response>


And this is the metadata:


<EntitiesDescriptor Name="urn:mace:shibboleth:callsign"
    xmlns="urn:oasis:names:tc:SAML:2.0:metadata"
xmlns:ds="http://www.w3.org/2000f/09/xmldsig#"
xmlns:mdalg="urn:oasis:names:tc:SAML:metadata:algsupport"
xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui"
xmlns:shibmd="urn:mace:shibboleth:metadata:1.0"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
    <EntityDescriptor entityID="http://localhost:8080/saml/2e/shibboleth">
        <Extensions>            <mdalg:DigestMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#sha512" />
<mdalg:DigestMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384" />
 <mdalg:DigestMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" />
<mdalg:SigningMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512" />
     <mdalg:SigningMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384" />
     <mdalg:SigningMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" />
 </Extensions>
        <IDPSSODescriptor
protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol
urn:mace:shibboleth:1.0 urn:oasis:names:tc:SAML:2.0:protocol">
   <Extensions>                <shibmd:Scope
regexp="false">localhost</shibmd:Scope>                <mdui:UIInfo>
                 <mdui:DisplayName
xml:lang="en">Callsign</mdui:DisplayName>
<mdui:Description xml:lang="en">Callsign IdP</mdui:Description>
            <mdui:Logo height="88"
width="253">https://auth.callsign.com/saml/resources/base/images/callsign-logo-full-green.png</mdui:Logo>
               </mdui:UIInfo>
            </Extensions>            <KeyDescriptor>
<ds:KeyInfo>                    <ds:X509Data>
<ds:X509Certificate>
MIIC7jCCAdagAwIBAgIVAMitRIDQ/S+pmNiWOrCRMawt0kz0MA0GCSqGSIb3DQEB

CwUAMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDAeFw0xNjAxMDQxMDU3NDBaFw0xOTAx

MDQxMDU3NDBaMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEB

BQADggEPADCCAQoCggEBAKFp3sHDj1O5jVVNTbzImTSKHsaWIvDH3OrTX9ViuSf+

lXyvqcYQVUQAp70P8kqIaeAlDdpU7bqTfNuDJ9eD/TE1xgZK7KtR5rx/MHEiTcV1

0XMPgiAem9K5egnDKtElYT6K02pYGMPCBAq+BMmS0IqjA1GuOox999MdV3RseCis

StJlzWSxa0qcKcwAyTODzQ1mTq1/B5ng7E8QZsgUbYLELWnt6TdssmIBGuxCWDI9

Tn2ozo92mJwjXVP0ghF8lfNR6+HRuLm56oEa4U1l54HNdbBixLrE6NReUd/mERzD

KO/pjUI3eCD4aC0JanbSUmzrzrKVvBYZ6hwX1CdQuUUCAwEAAaM3MDUwHQYDVR0O

BBYEFLUMx35bNYzZdQeRraahy1ThLoG8MBQGA1UdEQQNMAuCCWxvY2FsaG9zdDAN

BgkqhkiG9w0BAQsFAAOCAQEAIjOwlHqvxG7RVDgRe0iwv+P4oRaJxHV2WkIfo0z/

Jn+kX+w2HyXfGiJyAFnS/vwcsZR/hGvD1q5EIsqBWFLH2iQXdDXC6o/Q0cXXlLT4

bp1dHJ3yyG5h3wWJbJYO8Br4E2l4T0tvGlHk26OZs0T69ycC9xkKW1zbfCEYSFj8

OL2JYq/KQGQeUWdKtakBjP4sikP6739imAgPkNIfsaJBu2Qd7FjPrrJf1CZD9gFi

eE/VO/hioWObkSsGenMQ37aCkrXgotgkFXqGiUJodHht9Ge///xU0irD6O7zkI68
                     96RsmNunf+iSqFIdc7/apc/ytSMz0quyqFLk9s0stMDoEg==
                      </ds:X509Certificate>
</ds:X509Data>                </ds:KeyInfo>
<EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/>
  <EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc" />
   <EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
  <EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
     <EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
      <EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-1_5"/>
</KeyDescriptor>
            <ArtifactResolutionService
Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"

Location="https://idp.testshib.org:8443/idp/profile/SAML1/SOAP/ArtifactResolution"
                                      index="1"/>
<ArtifactResolutionService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"

Location="https://idp.testshib.org:8443/idp/profile/SAML2/SOAP/ArtifactResolution"
                                      index="2"/>
            <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
           <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
            <SingleSignOnService
Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest"

Location="http://localhost:8080/saml/2e/profile/Shibboleth/SSO"/>
      <SingleSignOnService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"

Location="http://localhost:8080/saml/2e/profile/SAML2/POST/SSO"/>
      <SingleSignOnService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"

Location="http://localhost:8080/saml/2e/profile/SAML2/Redirect/SSO"/>
          <SingleSignOnService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"
             Location="http://localhost:8080/saml/2e/profile/SAML2/SOAP/ECP"/>
        </IDPSSODescriptor>

        <AttributeAuthorityDescriptor
protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol
urn:oasis:names:tc:SAML:2.0:protocol">
            <KeyDescriptor>                <ds:KeyInfo>
    <ds:X509Data>                        <ds:X509Certificate>

MIIC7jCCAdagAwIBAgIVAMitRIDQ/S+pmNiWOrCRMawt0kz0MA0GCSqGSIb3DQEB

CwUAMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDAeFw0xNjAxMDQxMDU3NDBaFw0xOTAx

MDQxMDU3NDBaMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEB

BQADggEPADCCAQoCggEBAKFp3sHDj1O5jVVNTbzImTSKHsaWIvDH3OrTX9ViuSf+

lXyvqcYQVUQAp70P8kqIaeAlDdpU7bqTfNuDJ9eD/TE1xgZK7KtR5rx/MHEiTcV1

0XMPgiAem9K5egnDKtElYT6K02pYGMPCBAq+BMmS0IqjA1GuOox999MdV3RseCis

StJlzWSxa0qcKcwAyTODzQ1mTq1/B5ng7E8QZsgUbYLELWnt6TdssmIBGuxCWDI9

Tn2ozo92mJwjXVP0ghF8lfNR6+HRuLm56oEa4U1l54HNdbBixLrE6NReUd/mERzD

KO/pjUI3eCD4aC0JanbSUmzrzrKVvBYZ6hwX1CdQuUUCAwEAAaM3MDUwHQYDVR0O

BBYEFLUMx35bNYzZdQeRraahy1ThLoG8MBQGA1UdEQQNMAuCCWxvY2FsaG9zdDAN

BgkqhkiG9w0BAQsFAAOCAQEAIjOwlHqvxG7RVDgRe0iwv+P4oRaJxHV2WkIfo0z/

Jn+kX+w2HyXfGiJyAFnS/vwcsZR/hGvD1q5EIsqBWFLH2iQXdDXC6o/Q0cXXlLT4

bp1dHJ3yyG5h3wWJbJYO8Br4E2l4T0tvGlHk26OZs0T69ycC9xkKW1zbfCEYSFj8

OL2JYq/KQGQeUWdKtakBjP4sikP6739imAgPkNIfsaJBu2Qd7FjPrrJf1CZD9gFi

eE/VO/hioWObkSsGenMQ37aCkrXgotgkFXqGiUJodHht9Ge///xU0irD6O7zkI68
                     96RsmNunf+iSqFIdc7/apc/ytSMz0quyqFLk9s0stMDoEg==
                      </ds:X509Certificate>
</ds:X509Data>                </ds:KeyInfo>
<EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/>
  <EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc" />
   <EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
  <EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
     <EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
      <EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-1_5"/>
</KeyDescriptor>

            <AttributeService
Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding"

Location="https://idp.testshib.org:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
           <AttributeService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"
          Location="https://idp.testshib.org:8443/idp/profile/SAML2/SOAP/AttributeQuery"/>
            <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
           <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
        </AttributeAuthorityDescriptor>
        <Organization>            <OrganizationName
xml:lang="en">Callsign Identity Provider</OrganizationName>
<OrganizationDisplayName
xml:lang="en">Callsign</OrganizationDisplayName>
<OrganizationURL
xml:lang="en">http://www.callsign.com</OrganizationURL>
</Organization>        <!--         <ContactPerson
contactType="technical">
<GivenName>Nate</GivenName>
<SurName>Klingenstein</SurName>
<EmailAddress>ndk at internet2.edu</EmailAddress>
</ContactPerson> -->    </EntityDescriptor></EntitiesDescriptor>


On 6 January 2016 at 15:48, Cantor, Scott <cantor.2 at osu.edu> wrote:

> Fundamentally, you can't be using default algorithms. Either the
> encryption algorithm(s) were changed from the defaults, or there has to be
> SP metadata containing extension elements that are causing it to switch to
> some algorithm that's triggering a bug.
>
> We need to see the XML produced by the encryption step before it tries to
> sign the response. I don't know if that's even possible, so I would switch
> things and turn off response signing so that it logs the final output it
> sends to the SP. That might provide a hint about what it's doing that's not
> routine.
>
> I would like to see the metadata as well.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>



-- 
Bogdan Albei
Senior Platform Engineer
Callsign Inc.
[C] bogdan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160106/57b23960/attachment-0001.html>


More information about the users mailing list