<html><body><div style="color:#000; background-color:#fff; font-family:arial, helvetica, sans-serif;font-size:12pt"><div><span>Removing holderofkey fixed it.</span></div><div><br></div> <div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"> <div style="font-family: 'times new roman', 'new york', times, serif; font-size: 12pt;"> <div dir="ltr"> <font size="2" face="Arial"> <hr size="1"> <b><span style="font-weight:bold;">From:</span></b> Marc Boorshtein <mboorshtein@gmail.com><br> <b><span style="font-weight: bold;">To:</span></b> Shib Users <users@shibboleth.net> <br> <b><span style="font-weight: bold;">Sent:</span></b> Thursday, February 7, 2013 2:04 PM<br> <b><span style="font-weight: bold;">Subject:</span></b> Re: IdP initiated SSO<br> </font> </div> <br>
Here's a working assertion:<br><br><saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"<br> ID="fa211f99a41adcf1d07a81fce09fc0d43ce6da419"<br> IssueInstant="2013-02-07T22:02:58.160Z"<br> Version="2.0"<br> ><br> <saml2:Issuer<br>xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://localhost.localdomain:8443/auth/idp/test" target="_blank">https://localhost.localdomain:8443/auth/idp/test</a></saml2:Issuer><br> <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><br> <ds:SignedInfo><br> <ds:CanonicalizationMethod<br>Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"
/><br> <ds:SignatureMethod<br>Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1" /><br> <ds:Reference URI="#fa211f99a41adcf1d07a81fce09fc0d43ce6da419"><br> <ds:Transforms><br> <ds:Transform<br>Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" /><br> <ds:Transform<br>Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#" target="_blank">http://www.w3.org/2001/10/xml-exc-c14n#</a>"><br> <ec:InclusiveNamespaces<br>xmlns:ec="<a href="http://www.w3.org/2001/10/xml-exc-c14n#" target="_blank">http://www.w3.org/2001/10/xml-exc-c14n#</a>"<br>
PrefixList="ds saml2 saml2p xs"<br> /><br> </ds:Transform><br> </ds:Transforms><br> <ds:DigestMethod<br>Algorithm="http://www.w3.org/2000/09/xmldsig#sha1" /><br> <ds:DigestValue>4EXOqwRKWTD8w5v1PwR2LlyZjws=</ds:DigestValue><br> </ds:Reference><br> </ds:SignedInfo><br>
<ds:SignatureValue><br>Yh2HPrAGCWWahNVfSGenq+F5l89r23uKcZFwlsxvdlbziR+1U1UoUt4pVUv/bvP7kzI88Rlgg7MB<br>kx0uhd8fYwT7VRYkvJYj0+yIyahNe61GYnYrnqKWrlm+900THA4/8O4CoH6tYcTbYvlTPewwjbMi<br>HyfRf3iKXMYJF0zTQeM=<br></ds:SignatureValue><br> <ds:KeyInfo><br>
<ds:X509Data><br><br><ds:X509Certificate>MIICsTCCAhqgAwIBAgIGATnVOZ4iMA0GCSqGSIb3DQEBBQUAMH8xCzAJBgNVBAYTAlVTMREwDwYD<br>VQQIEwhWaXJnaW5pYTESMBAGA1UEBxMJQXJsaW5ndG9uMR8wHQYDVQQKExZUcmVtb2xvIFNlY3Vy<br>aXR5LCBJbmMuMRAwDgYDVQQLEwdUZXN0aW5nMRYwFAYDVQQDEw1pZHAtc2FtbDItc2lnMB4XDTEy<br>MDkxNzE3MTQ0NloXDTIyMDkxNTE3MTQ0NlowfzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdp<br>bmlhMRIwEAYDVQQHEwlBcmxpbmd0b24xHzAdBgNVBAoTFlRyZW1vbG8gU2VjdXJpdHksIEluYy4x<br>EDAOBgNVBAsTB1Rlc3RpbmcxFjAUBgNVBAMTDWlkcC1zYW1sMi1zaWcwgZ8wDQYJKoZIhvcNAQEB<br>BQADgY0AMIGJAoGBAJIni3hDLjLak7lguCMjDFsHUso8qk+Xde2hveIGr4VIhGi6itWjLrf4XRRp<br>A3goOTBbm9nTj3iWHskmWm5ly1+OyOzkAxM7+Ws62bL5CfSmQwvVlw/YwaEmOEVAGdzTKcfZm+ju<br>rMv8Fw6UZ765Fny1I1KA1A1x7rhYpb3J/7t7AgMBAAGjODA2MAwGA1UdEwEB/wQCMAAwDgYDVR0P<br>AQH/BAQDAgWgMBYGA1UdJQEB/wQMMAoGCCsGAQUFBwMBMA0GCSqGSIb3DQEBBQUAA4GBAB0jGXs+<br>phEFdvOtqMP9yGvc0u7JN51ebmZr6aQ9nLrk1+YlsZgMfhzf4I7z+V3d42OOSTnB25O9+PB/z3MU<br>j7ui0CazW8VKnAzw1Cq9dvkaYqQz3JvTW
4GryEC/vkeH/diPA/X1NDQJ2nBUsFxnhIH59XmJKOSh<br>36loeqE7/Xhc</ds:X509Certificate><br> </ds:X509Data><br> </ds:KeyInfo><br> </ds:Signature><br> <saml2p:Status><br> <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success" /><br> </saml2p:Status><br> <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"<br> ID="f7f54e02482c3d5297c30d16e83a32eb8f4e4e69a"<br> IssueInstant="2013-02-07T22:02:58.160Z"<br> Version="2.0"<br> ><br>
<saml2:Issuer><a href="https://localhost.localdomain:8443/auth/idp/test" target="_blank">https://localhost.localdomain:8443/auth/idp/test</a></saml2:Issuer><br> <saml2:Subject><br> <saml2:NameID<br>Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">admin</saml2:NameID><br> <saml2:SubjectConfirmation<br>Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><br> <saml2:SubjectConfirmationData<br>NotOnOrAfter="2013-02-07T22:07:58.160Z"<br><br>Recipient="<a href="https://www.tremolosecurity-test.com/auth/SAML2Auth" target="_blank">https://www.tremolosecurity-test.com/auth/SAML2Auth</a>"<br>
/><br> </saml2:SubjectConfirmation><br> </saml2:Subject><br> <saml2:Conditions NotBefore="2013-02-07T21:57:58.160Z"<br> NotOnOrAfter="2013-02-07T22:07:58.160Z"<br> ><br> <saml2:AudienceRestriction><br><br><saml2:Audience><a href="https://www.tremolosecurity-test.com/auth/SAML2Auth" target="_blank">https://www.tremolosecurity-test.com/auth/SAML2Auth</a></saml2:Audience><br> </saml2:AudienceRestriction><br> </saml2:Conditions><br> <saml2:AuthnStatement
AuthnInstant="2013-02-07T22:02:58.160Z"<br><br>SessionIndex="f7f54e02482c3d5297c30d16e83a32eb8f4e4e69a"<br> ><br> <saml2:AuthnContext><br><br><saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified</saml2:AuthnContextClassRef><br> </saml2:AuthnContext><br> </saml2:AuthnStatement><br> <saml2:AttributeStatement><br> <saml2:Attribute Name="uid"><br> <saml2:AttributeValue<br>xmlns:xs="http://www.w3.org/2001/XMLSchema"<br><br>xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance" target="_blank">http://www.w3.org/2001/XMLSchema-instance</a>"<br>
xsi:type="xs:string"<br> >admin</saml2:AttributeValue><br> </saml2:Attribute><br> </saml2:AttributeStatement><br> </saml2:Assertion><br></saml2p:Response><br><br>specifically the subject confirmation:<br><br><saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><br> <saml2:SubjectConfirmationData<br>NotOnOrAfter="2013-02-07T22:07:58.160Z"<br><br>Recipient="<a href="https://www.tremolosecurity-test.com/auth/SAML2Auth" target="_blank">https://www.tremolosecurity-test.com/auth/SAML2Auth</a>"<br>
/><br> </saml2:SubjectConfirmation><br><br>I've tested this with shib, OIF, Ping, OpenAM, ADFS, ....<br><br>On Thu, Feb 7, 2013 at 4:45 PM, Brent Putman <<a ymailto="mailto:putmanb@georgetown.edu" href="mailto:putmanb@georgetown.edu">putmanb@georgetown.edu</a>> wrote:<br>> The NotOnOrAfter is an optional attribute, but I'm not sure whether<br>> legally it can be present but empty. Semantically it is pointless to do<br>> that.<br>><br>> But the real problem, as I said in the other message, is that the SAML<br>> strucgture is just flat out wrong.<br>><br>><br>><br>><br>> On 2/7/13 4:42 PM, Mike Flynn wrote:<br>>> Thanks, Marc. I asked them to correct that but was not sure if that<br>>> was the issue
based on the message.<br>>><br>>> ------------------------------------------------------------------------<br>>> *From:* Marc Boorshtein <<a ymailto="mailto:mboorshtein@gmail.com" href="mailto:mboorshtein@gmail.com">mboorshtein@gmail.com</a>><br>>> *To:* Shib Users <<a ymailto="mailto:users@shibboleth.net" href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>>> *Sent:* Thursday, February 7, 2013 1:38 PM<br>>> *Subject:* Re: IdP initiated SSO<br>>><br>>> NotOnorAfter is blank...<br>>><br>>> On Thu, Feb 7, 2013 at 4:35 PM, Mike Flynn <<a ymailto="mailto:shibbolethlynda@yahoo.com" href="mailto:shibbolethlynda@yahoo.com">shibbolethlynda@yahoo.com</a><br>>> <mailto:<a ymailto="mailto:shibbolethlynda@yahoo.com" href="mailto:shibbolethlynda@yahoo.com">shibbolethlynda@yahoo.com</a>>> wrote:<br>>> > This is what was sent:<br>>> ><br>>>
> <saml:SubjectConfirmation<br>>> > Method="urn:oasis:names:tc:SAML:2.0:cm:holder-of-key"><br>>> > <saml:SubjectConfirmation<br>>> > Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><br>>> > <saml:SubjectConfirmationData NotOnOrAfter=""<br>>> > Recipient="<a href="https://shib.lynda.com/Shibboleth.sso/SAML2/POST" target="_blank">https://shib.lynda.com/Shibboleth.sso/SAML2/POST</a>"/><br>>> > </saml:SubjectConfirmation><br>>> > </saml:SubjectConfirmation><br>>> ><br>><br>> --<br>> To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>--<br>To unsubscribe from this list send an email to <a
ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br><br><br> </div> </div> </div></body></html>