DocuSign SSO issues on Dev environment.

Dr_Natas Juan.Rios at csuci.edu
Wed Nov 30 16:17:10 EST 2016


Hello everybody,

One word "Docusign". I'm not able to get our idp to communicate with the SSO
with DocuSign. See exhibit_A.png
<http://shibboleth.1660669.n2.nabble.com/file/n7629901/Exhibit_A.png> 
Can someone take a look at my saml-nameid.xml to verify that it looks good. 



Haven't been able to get past this issue. The most relevant  post the issue
that I'm having is the following. 
http://shibboleth.1660669.n2.nabble.com/Docusign-td7627413.html#a7627415
Alaska University discovered that Docusign forces you to disable encryption. 



Self Note: Debugging is on for my test environment. Revert back to Info
only. 

Logs: idp-process.log
Log Notes: I changed the user name we use for the test account to
test-account at csuci.edu.

tail -f /opt/shibboleth-idp/logs/idp-process.log |grep  "Beginning to encode
attribute" -B 5 -A 10 
2016-11-30 11:55:36,955 - DEBUG
[org.springframework.beans.factory.support.DefaultListableBeanFactory:484] -
Finished creating instance of bean 'AddAttributeStatementToAssertion'
2016-11-30 11:55:36,955 - DEBUG
[org.springframework.webflow.execution.ActionExecutor:49] - Executing
net.shibboleth.idp.saml.saml2.profile.impl.AddAttributeStatementToAssertion at 1d0bbabf
2016-11-30 11:55:36,956 - DEBUG
[net.shibboleth.idp.saml.profile.impl.BaseAddAttributeStatementToAssertion:229]
- Profile Action AddAttributeStatementToAssertion: Attempting to add an
AttributeStatement to outgoing Assertion
2016-11-30 11:55:36,956 - DEBUG
[net.shibboleth.idp.saml.saml2.profile.impl.AddAttributeStatementToAssertion:174]
- Profile Action AddAttributeStatementToAssertion: Attempting to encode
attribute mail as a SAML 2 Attribute
2016-11-30 11:55:36,956 - DEBUG
[net.shibboleth.idp.saml.saml2.profile.impl.AddAttributeStatementToAssertion:188]
- Profile Action AddAttributeStatementToAssertion: Encoding attribute mail
as a SAML 2 Attribute
2016-11-30 11:55:36,957 - DEBUG
[net.shibboleth.idp.saml.attribute.encoding.AbstractSAMLAttributeEncoder:154]
- Beginning to encode attribute mail
2016-11-30 11:55:36,957 - DEBUG
[net.shibboleth.idp.saml.attribute.encoding.SAMLEncoderSupport:73] -
Encoding value test-account at csuci.com of attribute mail
2016-11-30 11:55:36,958 - DEBUG
[net.shibboleth.idp.saml.attribute.encoding.AbstractSAMLAttributeEncoder:191]
- Completed encoding 1 values for attribute mail
2016-11-30 11:55:36,958 - DEBUG
[net.shibboleth.idp.saml.saml2.profile.impl.AddAttributeStatementToAssertion:174]
- Profile Action AddAttributeStatementToAssertion: Attempting to encode
attribute transientId as a SAML 2 Attribute
2016-11-30 11:55:36,958 - DEBUG
[net.shibboleth.idp.saml.saml2.profile.impl.AddAttributeStatementToAssertion:204]
- Profile Action AddAttributeStatementToAssertion: Attribute transientId did
not have a usable SAML 2 Attribute encoder associated with it, nothing to do
2016-11-30 11:55:36,959 - DEBUG
[net.shibboleth.idp.saml.saml2.profile.impl.AddAttributeStatementToAssertion:174]
- Profile Action AddAttributeStatementToAssertion: Attempting to encode
attribute NameID as a SAML 2 Attribute
2016-11-30 11:55:36,959 - DEBUG
[net.shibboleth.idp.saml.saml2.profile.impl.AddAttributeStatementToAssertion:204]
- Profile Action AddAttributeStatementToAssertion: Attribute NameID did not
have a usable SAML 2 Attribute encoder associated with it, nothing to do
2016-11-30 11:55:36,960 - DEBUG
[net.shibboleth.idp.saml.saml2.profile.impl.AddAttributeStatementToAssertion:174]
- Profile Action AddAttributeStatementToAssertion: Attempting to encode
attribute surname as a SAML 2 Attribute
2016-11-30 11:55:36,960 - DEBUG
[net.shibboleth.idp.saml.saml2.profile.impl.AddAttributeStatementToAssertion:188]
- Profile Action AddAttributeStatementToAssertion: Encoding attribute
surname as a SAML 2 Attribute
2016-11-30 11:55:36,960 - DEBUG
[net.shibboleth.idp.saml.attribute.encoding.AbstractSAMLAttributeEncoder:154]
- Beginning to encode attribute surname
2016-11-30 11:55:36,961 - DEBUG
[net.shibboleth.idp.saml.attribute.encoding.SAMLEncoderSupport:73] -
Encoding value test-account of attribute surname
2016-11-30 11:55:36,962 - DEBUG
[net.shibboleth.idp.saml.attribute.encoding.AbstractSAMLAttributeEncoder:191]
- Completed encoding 1 values for attribute surname
2016-11-30 11:55:36,962 - DEBUG
[net.shibboleth.idp.saml.saml2.profile.impl.AddAttributeStatementToAssertion:174]
- Profile Action AddAttributeStatementToAssertion: Attempting to encode
attribute givenName as a SAML 2 Attribute
2016-11-30 11:55:36,962 - DEBUG
[net.shibboleth.idp.saml.saml2.profile.impl.AddAttributeStatementToAssertion:188]
- Profile Action AddAttributeStatementToAssertion: Encoding attribute
givenName as a SAML 2 Attribute
2016-11-30 11:55:36,963 - DEBUG
[net.shibboleth.idp.saml.attribute.encoding.AbstractSAMLAttributeEncoder:154]
- Beginning to encode attribute givenName
2016-11-30 11:55:36,963 - DEBUG
[net.shibboleth.idp.saml.attribute.encoding.SAMLEncoderSupport:73] -
Encoding value test-account of attribute givenName
2016-11-30 11:55:36,964 - DEBUG
[net.shibboleth.idp.saml.attribute.encoding.AbstractSAMLAttributeEncoder:191]
- Completed encoding 1 values for attribute givenName
2016-11-30 11:55:36,964 - DEBUG
[net.shibboleth.idp.saml.saml2.profile.impl.AddAttributeStatementToAssertion:118]
- Profile Action AddAttributeStatementToAssertion: Adding constructed
AttributeStatement to Assertion _57eee162691461ac1f6ae8b64c5974b2 
2016-11-30 11:55:36,964 - DEBUG
[org.springframework.webflow.execution.ActionExecutor:53] - Finished
executing
net.shibboleth.idp.saml.saml2.profile.impl.AddAttributeStatementToAssertion at 1d0bbabf;
result = null
2016-11-30 11:55:36,965 - DEBUG
[org.springframework.webflow.execution.AnnotatedAction:149] - Clearing
action execution attributes map[[empty]]
2016-11-30 11:55:36,965 - DEBUG
[org.springframework.webflow.execution.ActionExecutor:53] - Finished
executing [EvaluateAction at 728e5a48 expression =
AddAttributeStatementToAssertion, resultExpression = [null]]; result = null
2016-11-30 11:55:36,966 - DEBUG
[org.springframework.webflow.engine.ActionState:120] - Action execution [5]
returned a [null] event: proceeding to the next action in the list
2016-11-30 11:55:36,966 - DEBUG
[org.springframework.webflow.execution.ActionExecutor:49] - Executing
[EvaluateAction at 15826934 expression = AddNameIDToSubjects, resultExpression
= [null]]
2016-11-30 11:55:36,966 - DEBUG
[org.springframework.webflow.execution.AnnotatedAction:142] - Putting action
execution attributes map[[empty]]
2016-11-30 11:55:36,967 - DEBUG
[org.springframework.beans.factory.support.DefaultListableBeanFactory:448] -
Creating instance of bean 'AddNameIDToSubjects'

The most relevant log notes that I can see are these two.

2016-11-30 11:55:36,959 - DEBUG
[net.shibboleth.idp.saml.saml2.profile.impl.AddAttributeStatementToAssertion:174]
- Profile Action AddAttributeStatementToAssertion: Attempting to encode
attribute NameID as a SAML 2 Attribute
2016-11-30 11:55:36,959 - DEBUG
[net.shibboleth.idp.saml.saml2.profile.impl.AddAttributeStatementToAssertion:204]
- Profile Action AddAttributeStatementToAssertion: Attribute NameID did not
have a usable SAML 2 Attribute encoder associated with it, nothing to do

Some how I don't think my settings for my Attribute-Resolver.xml are up to
par. 

Note: Truncated Attribute-Resolver.xml for Docusign
427     
428     <resolver:AttributeDefinition  xsi:type="ad:Simple" id="NameID"
sourceAttributeID="employeeID">
429         <resolver:Dependency ref="myLDAP" />
430         <resolver:AttributeEncoder
xsi:type="enc:SAML1StringNameIdentifier"
nameFormat="urn:mace:shibboleth:1.0:nameIdentifier"/>
431         <resolver:AttributeEncoder xsi:type="enc:SAML2StringNameID"
nameFormat="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"/>
432     </resolver:AttributeDefinition>


More logs from "Idp-Process.log"
2016-11-30 12:45:47,454 - DEBUG [PROTOCOL_MESSAGE:70] - 
<?xml version="1.0" encoding="UTF-8"?>
<saml2p:Response
   
Destination="https://account-d.docusign.com/organizations/37269197-2dd0-49da-8668-526cfe2e4c56/saml2/login"
    ID="_bc2cea9fa2f2800a094b5fc486fd3f45"
    InResponseTo="_56cb71eb-4d64-4921-a0b1-fe7f14e3c0ae"
    IssueInstant="2016-11-30T20:45:47.099Z" Version="2.0"
xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol">
    <saml2:Issuer
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">https://209.129.116.15/idp/shibboleth</saml2:Issuer>
    <ds:Signature
                xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo>
<ds:CanonicalizationMethod
                Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
<ds:SignatureMethod
               
Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<ds:Reference
                        URI="#_bc2cea9fa2f2800a094b5fc486fd3f45">
<ds:Transforms>
<ds:Transform
                       
Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<ds:Transform
                    Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
</ds:Transforms>
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<ds:DigestValue>G1R70Jwe7APsBp+Ag8mXYwYOvZrkkaC6Nr2o1TX5qp0=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>
Truncate Cert
</ds:SignatureValue>
<ds:KeyInfo>
            <ds:X509Data>
                <ds:X509Certificate>Truncate Cert=</ds:X509Certificate>
            </ds:X509Data>
        </ds:KeyInfo>
    </ds:Signature>
    <saml2p:Status>
        <saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:Requester">
            <saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:InvalidNameIDPolicy"/>
        </saml2p:StatusCode>
        <saml2p:StatusMessage>An error occurred.</saml2p:StatusMessage>
    </saml2p:Status>
</saml2p:Response>


The main error that I can see here is the following:
<saml2p:Status>
        <saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:Requester">
            <saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:InvalidNameIDPolicy"/>
        </saml2p:StatusCode>
        <saml2p:StatusMessage>An error occurred.</saml2p:StatusMessage>
    </saml2p:Status>


Here is what my code looks for "Attribute-Filter.xml"
 419 
 420 <afp:AttributeFilterPolicy id="docusign">
 421     <afp:PolicyRequirementRule
xsi:type="basic:AttributeRequesterString"
value="https://account-d.docusign.com/organizations/37269197-2dd0-49da-8668-526cf
e2e4c56/saml2" />
 422     
 423     <afp:AttributeRule attributeID="NameID">
 424           <afp:PermitValueRule xsi:type="basic:ANY" />
 425     </afp:AttributeRule>
 426     <afp:AttributeRule attributeID="mail">
 427           <afp:PermitValueRule xsi:type="basic:ANY" />
 428     </afp:AttributeRule>
 429     <afp:AttributeRule attributeID="givenName">
 430           <afp:PermitValueRule xsi:type="basic:ANY" />
 431     </afp:AttributeRule>
 432     <afp:AttributeRule attributeID="surname">
 433           <afp:PermitValueRule xsi:type="basic:ANY" />
 434     </afp:AttributeRule>
 435 </afp:AttributeFilterPolicy>
 436 



Code for "saml-nameid.xml"

 57         <bean parent="shibboleth.SAML2AttributeSourcedGenerator"
 58            
p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
 59             p:attributeSourceIds="#{ {'NameID'} }">
 60             <property name="activationCondition">
 61                 <bean parent="shibboleth.Conditions.RelyingPartyId"
c:candidate="https://account-d.docusign.com/organizations/37269197-2dd0-49da-8668-526cf   
e2e4c56/saml2" />
 62             </property>
 63         </bean>


Code for "metadata-provides.xml"
213         <MetadataProvider id="docusign"
214             xsi:type="FileBackedHTTPMetadataProvider"
215             xmlns="urn:mace:shibboleth:2.0:metadata"
216            
metadataURL="https://account-d.docusign.com/organizations/37269197-2dd0-49da-8668-526cfe2e4c56/saml2/metadata"
217            
backingFile="/opt/shibboleth-idp/metadata/docusign-metadata.xml" />


Disabling Encryption for "relying-party.xml"

Code for "relying-party.xml"
97         <bean parent="RelyingPartyByName"
c:relyingPartyIds="https://account-d.docusign.com/organizations/37269197-2dd0-49da-8668-526cfe2e4c56/saml2">
 98             <property name="profileConfigurations">
 99                 <list>
100                     <bean parent="SAML2.SSO" p:encryptAssertions="false" 
p:nameIDFormatPrecedence="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"    
/>
101                 </list>
102             </property>
103         </bean>
 
Code for "saml-nameid.properties"
7 # Comment out to disable legacy NameID generation via Attribute Resolver
  8 idp.nameid.saml2.legacyGenerator = shibboleth.LegacySAML2NameIDGenerator
  9 idp.nameid.saml1.legacyGenerator =
shibboleth.LegacySAML1NameIdentifierGenerator

I enabled these just in case, but it still didn't work. 









-----
Thank you!
--
View this message in context: http://shibboleth.1660669.n2.nabble.com/DocuSign-SSO-issues-on-Dev-environment-tp7629901.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.


More information about the users mailing list