signature not found
Jeff McCullough
jeffmc at berkeley.edu
Fri Jan 13 19:03:31 EST 2017
Hi Tom,
It happens to be Kronos. Can you possibly show me the details of your override?
Thank you,
Jeff
Sent from my iPhone
> On Jan 13, 2017, at 3:05 PM, Tom Poage <tfpoage at ucdavis.edu> wrote:
>
> Barring an obvious certificate problem, last time I saw something like this (Kronos) we ended up having to switch response signature to assertion signature (relying party override).
>
> Tom.
>
>> On Jan 13, 2017, at 2:35 PM, Jeff Mccullough <jeffmc at berkeley.edu> wrote:
>>
>> Hi,
>>
>> I’m using IDP 3.2.1. There is one SP that reports that the signature the IDP is sending in the SAML response is invalid.
>>
>> The error message is: Signature can not be found in SAML Response!
>>
>> The cert in the response is correct. I checked the response with the validation tool at <https://www.samltool.com/validate_response.php>, and get the error:
>>
>> THE SAML RESPONSE IS INVALID.
>>
>> Reference validation failed
>>
>> What else should I examine or change in my configuration?
>>
>> Thanks,
>> Jeff
>>
>>
>>
>> The response is included
>> ———————————
>>
>> <saml2p:Response
>> Destination="https://sp-here/wfc/logonESS_SSO"
>> ID="_05ba5ba9448be7de75cdebc878bbd97d"
>> IssueInstant="2017-01-04T21:26:03.850Z" Version="2.0"
>> xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" xmlns:xsd="http://www.w3.org/2001/XMLSchema">
>> <saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion”>idp-here</saml2:Issuer>
>> <ds:Signature
>> xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
>> <ds:SignedInfo>
>> <ds:CanonicalizationMethod
>> Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
>> <ds:SignatureMethod
>> Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
>> <ds:Reference
>> URI="#_05ba5ba9448be7de75cdebc878bbd97d">
>> <ds:Transforms>
>> <ds:Transform
>> Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
>> <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#">
>> <ec:InclusiveNamespaces PrefixList="xsd" xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#"/>
>> </ds:Transform>
>> </ds:Transforms>
>> <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
>> <ds:DigestValue>JxUltIs20c/mhD6UZcpN2U4Df+BtQuNUqZl4p5cA5dA=</ds:DigestValue>
>> </ds:Reference>
>> </ds:SignedInfo>
>> <ds:SignatureValue>
>> WP8Iaf0xOFzj0Gk+QO+rrAeYPrjn1DFjzagl8rS15ykDUCUA4C0H5D1DVcj9BL43Z+KT+2WPZW5Y
>> scp0EZDg+rXpU/6h3qL6alvbUljCnOojDa2NtX5diShQHb8ClPhD0vDi5VBA8KeZ5JzgPqKSWL64
>> FJYeDhQLBWXDi4qSyCC4NdvZ6WvSUV7CtXOAXe791Uzp+hQ/pM9FKlfm01WIH9Cd/6TPwcjrtkXU
>> QhXoTMvPQVPMBnHVw1hLLVh2lxUcrHe5D3OvEVwY3tfoSBuz5QxXxxKTI7XJFCQ5VreM7BjLGD/f
>> 6P3VakU4RrrbJTpwx6u3hS7v4IEOu+qI6HGu+Q==
>> </ds:SignatureValue>
>> <ds:KeyInfo>
>> <ds:X509Data>
>> <ds:X509Certificate>
>> [……..]
>> </ds:X509Certificate>
>> </ds:X509Data>
>> </ds:KeyInfo>
>> </ds:Signature>
>> <saml2p:Status>
>> <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
>> </saml2p:Status>
>> <saml2:Assertion ID="_02727147fca88cb6b03bc1fe34ef25f4"
>> IssueInstant="2017-01-04T21:26:03.850Z" Version="2.0" xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">
>> <saml2:Issuer>idp-here</saml2:Issuer>
>> <saml2:Subject>
>> <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
>> <saml2:SubjectConfirmationData Address="10.136.1.241"
>> NotOnOrAfter="2017-01-04T21:31:03.862Z" Recipient=“sp-here"/>
>> </saml2:SubjectConfirmation>
>> </saml2:Subject>
>> <saml2:Conditions NotBefore="2017-01-04T21:26:03.850Z" NotOnOrAfter="2017-01-04T21:31:03.850Z">
>> <saml2:AudienceRestriction>
>> <saml2:Audience>entity-id-here</saml2:Audience>
>> </saml2:AudienceRestriction>
>> </saml2:Conditions>
>> <saml2:AuthnStatement AuthnInstant="2017-01-04T21:26:03.621Z" SessionIndex="_79ac04e21ca4c9ae04aca42e3629dc94">
>> <saml2:SubjectLocality Address="10.136.1.241"/>
>> <saml2:AuthnContext>
>> <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef>
>> </saml2:AuthnContext>
>> </saml2:AuthnStatement>
>> <saml2:AttributeStatement>
>> <saml2:Attribute
>> FriendlyName=“attribute-name"
>> Name="urn:oid:1.3.6.1.4.1.4995.2.200.10.1.5.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
>> <saml2:AttributeValue
>> xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string”>some-value</saml2:AttributeValue>
>> </saml2:Attribute>
>> </saml2:AttributeStatement>
>> </saml2:Assertion>
>> </saml2p:Response>
>> --
>> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list