Encrypted token not accepted by Shib SPs

Hannah Short hannah.short at cern.ch
Thu Oct 15 12:35:24 UTC 2020


Dear all, 

I’m running an IdP (using Satosa https://github.com/IdentityPython/SATOSA) whose encrypted assertions are being rejected by Shibboleth SPs. 

The sample encrypted SAML Response attached is parsed correctly by a Mellon SP, and validated by the tool at https://www.samltool.com/validate_response.php <https://www.samltool.com/validate_response.php>, but fails for Shibboleth SPs. I’m pasting the logs from a shibboleth SP below. 

Has anyone hit this problem? 
Many thanks in advance for your help!
Hannah


————————

2020-10-15 12:31:45 DEBUG OpenSAML.MessageDecoder.SAML2 [455] [default]: extracting issuer from SAML 2.0 protocol message
2020-10-15 12:31:45 DEBUG OpenSAML.MessageDecoder.SAML2 [455] [default]: message from (https://fim-idp-dev.cern.ch/proxysamlfrontend)
2020-10-15 12:31:45 DEBUG OpenSAML.MessageDecoder.SAML2 [455] [default]: searching metadata for message issuer...
2020-10-15 12:31:45 DEBUG OpenSAML.MessageDecoder.SAML2 [455] [default]: recovered request/response correlation value (_124d9af9245230f37b5c32e6bcbb48a5)
2020-10-15 12:31:45 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [455] [default]: evaluating message flow policy (correlation off, replay checking on, expiration 60)
2020-10-15 12:31:45 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [455] [default]: ignoring InResponseTo, correlation checking is disabled
2020-10-15 12:31:45 DEBUG XMLTooling.StorageService [455] [default]: inserted record (id-BhpDbKTNNiXIuyE2X) in context (MessageFlow) with expiration (1602765345)
2020-10-15 12:31:45 DEBUG Shibboleth.SSO.SAML2 [455] [default]: processing message against SAML 2.0 SSO profile
2020-10-15 12:31:45 DEBUG XMLTooling.KeyInfoResolver.Inline [455] [default]: resolved 0 certificate(s)
2020-10-15 12:31:45 DEBUG XMLTooling.KeyInfoResolver.Inline [455] [default]: resolved 0 certificate(s)
2020-10-15 12:31:45 ERROR Shibboleth.SSO.SAML2 [455] [default]: failed to decrypt assertion: Unable to resolve any key decryption keys.
2020-10-15 12:31:45 WARN Shibboleth.SSO.SAML2 [455] [default]: error processing incoming assertion: A valid authentication statement was not found in the incoming message.


 


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20201015/44b6015a/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: valid-response.xml
Type: application/xml
Size: 15045 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20201015/44b6015a/attachment.wsdl>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20201015/44b6015a/attachment-0001.htm>


More information about the users mailing list