saml2aws -- IDPV4
Nathan Dors
dors at uw.edu
Fri Mar 19 21:06:09 UTC 2021
Hi Hari, can you say more about the csrf issue?
Does the issue arise due to new constraints introduced by IdPv4?
We have customers here who use saml2aws, but (uh oh) I'm not aware if we've
accounted for this potential issue in our planning around our IdPv4 upgrade.
I understand ECP and AWSCLI-login provide a comparable solution, but it'd
be useful to know more about the csrf with IdPv4.
-Nathan
On Wed, Feb 17, 2021 at 6:53 AM Mailvaganam, Hari <hari.mailvaganam at ubc.ca>
wrote:
> FYI – confirmed – csrf.
>
>
>
> *From: *users <users-bounces at shibboleth.net> on behalf of "Mailvaganam,
> Hari" <hari.mailvaganam at ubc.ca>
> *Reply-To: *Shib Users <users at shibboleth.net>
> *Date: *Tuesday, February 16, 2021 at 8:14 PM
> *To: *Shib Users <users at shibboleth.net>
> *Subject: *saml2aws -- IDPV4
>
>
>
> [*CAUTION:* Non-UBC Email]
>
> Hi:
>
>
>
> Has anyone had opportunity w.r.t saml2aws working with IDPV4.0.1?
>
>
>
>
> https://github.com/Versent/saml2aws/blob/master/pkg/provider/shibboleth/README.md
> - from link tested with IDP v3.3, however can’t quite make out why not
> working with v4.0.1 (shot in the dark – csrf?)
>
>
>
> Rreceiving message below ‘missing Assertion element. Issue only with
> saml2aws – the AWS console via SAML fine. No other changes made.
>
>
>
>
>
> missing Assertion element
>
> error parsing aws roles
>
> github.com/versent/saml2aws/v2/cmd/saml2aws/commands.selectAwsRole
>
>
> /Users/markw/Code/notgopath/saml2aws/cmd/saml2aws/commands/login.go:190
>
> github.com/versent/saml2aws/v2/cmd/saml2aws/commands.Login
>
>
> /Users/markw/Code/notgopath/saml2aws/cmd/saml2aws/commands/login.go:90
>
> main.main
>
>
> /Users/markw/Code/notgopath/saml2aws/cmd/saml2aws/main.go:163
>
> runtime.main
>
> /usr/local/Cellar/go/1.15.1/libexec/src/runtime/proc.go:204
>
> runtime.goexit
>
>
> /usr/local/Cellar/go/1.15.1/libexec/src/runtime/asm_amd64.s:1374
>
> Failed to assume role, please check whether you are permitted to assume
> the given role for the AWS service
>
> github.com/versent/saml2aws/v2/cmd/saml2aws/commands.Login
>
>
> /Users/markw/Code/notgopath/saml2aws/cmd/saml2aws/commands/login.go:92
>
> main.main
>
>
> /Users/markw/Code/notgopath/saml2aws/cmd/saml2aws/main.go:163
>
> runtime.main
>
> /usr/local/Cellar/go/1.15.1/libexec/src/runtime/proc.go:204
>
> runtime.goexit
>
>
> /usr/local/Cellar/go/1.15.1/libexec/src/runtime/asm_amd64.s:1374
>
>
>
> Best regards,
>
>
>
> *Hari Mailvaganam*
> Access Application Architect, Identity & Access Management (IAM)
>
> Cybersecurity | CISO Office
>
> The University of British Columbia | Musqueam Traditional Territory
> 420 - 6356 Agricultural Road | Vancouver BC | V6T1Z2 Canada
> Phone 604 827 5117
>
> Privacy Matters @ UBC
>
>
>
> Upcoming Scheduled Out of Office:
>
> -22nd March, 2021 – 26th March, 2021
>
> -09th August, 2021 – 20th August, 2021
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210319/e8875709/attachment.htm>
More information about the users
mailing list