<html><body><div style="color:#000; background-color:#fff; font-family:arial, helvetica, sans-serif;font-size:12pt"><div><span>Removing holderofkey fixed it.</span></div><div><br></div>  <div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"> <div style="font-family: 'times new roman', 'new york', times, serif; font-size: 12pt;"> <div dir="ltr"> <font size="2" face="Arial"> <hr size="1">  <b><span style="font-weight:bold;">From:</span></b> Marc Boorshtein &lt;mboorshtein@gmail.com&gt;<br> <b><span style="font-weight: bold;">To:</span></b> Shib Users &lt;users@shibboleth.net&gt; <br> <b><span style="font-weight: bold;">Sent:</span></b> Thursday, February 7, 2013 2:04 PM<br> <b><span style="font-weight: bold;">Subject:</span></b> Re: IdP initiated SSO<br> </font> </div> <br>
Here's a working assertion:<br><br>&lt;saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  ID="fa211f99a41adcf1d07a81fce09fc0d43ce6da419"<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  IssueInstant="2013-02-07T22:02:58.160Z"<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  Version="2.0"<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  &gt;<br>&nbsp; &nbsp; &lt;saml2:Issuer<br>xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"&gt;<a href="https://localhost.localdomain:8443/auth/idp/test" target="_blank">https://localhost.localdomain:8443/auth/idp/test</a>&lt;/saml2:Issuer&gt;<br>&nbsp; &nbsp; &lt;ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#"&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &lt;ds:SignedInfo&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;ds:CanonicalizationMethod<br>Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"
 /&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;ds:SignatureMethod<br>Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1" /&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;ds:Reference URI="#fa211f99a41adcf1d07a81fce09fc0d43ce6da419"&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;ds:Transforms&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;ds:Transform<br>Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" /&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;ds:Transform<br>Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#" target="_blank">http://www.w3.org/2001/10/xml-exc-c14n#</a>"&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;ec:InclusiveNamespaces<br>xmlns:ec="<a href="http://www.w3.org/2001/10/xml-exc-c14n#" target="_blank">http://www.w3.org/2001/10/xml-exc-c14n#</a>"<br>&nbsp;
 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; PrefixList="ds saml2 saml2p xs"<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; /&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/ds:Transform&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/ds:Transforms&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;ds:DigestMethod<br>Algorithm="http://www.w3.org/2000/09/xmldsig#sha1" /&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;ds:DigestValue&gt;4EXOqwRKWTD8w5v1PwR2LlyZjws=&lt;/ds:DigestValue&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/ds:Reference&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &lt;/ds:SignedInfo&gt;<br>&nbsp; &nbsp; &nbsp;
 &nbsp; &lt;ds:SignatureValue&gt;<br>Yh2HPrAGCWWahNVfSGenq+F5l89r23uKcZFwlsxvdlbziR+1U1UoUt4pVUv/bvP7kzI88Rlgg7MB<br>kx0uhd8fYwT7VRYkvJYj0+yIyahNe61GYnYrnqKWrlm+900THA4/8O4CoH6tYcTbYvlTPewwjbMi<br>HyfRf3iKXMYJF0zTQeM=<br>&lt;/ds:SignatureValue&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &lt;ds:KeyInfo&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;
 &lt;ds:X509Data&gt;<br><br>&lt;ds:X509Certificate&gt;MIICsTCCAhqgAwIBAgIGATnVOZ4iMA0GCSqGSIb3DQEBBQUAMH8xCzAJBgNVBAYTAlVTMREwDwYD<br>VQQIEwhWaXJnaW5pYTESMBAGA1UEBxMJQXJsaW5ndG9uMR8wHQYDVQQKExZUcmVtb2xvIFNlY3Vy<br>aXR5LCBJbmMuMRAwDgYDVQQLEwdUZXN0aW5nMRYwFAYDVQQDEw1pZHAtc2FtbDItc2lnMB4XDTEy<br>MDkxNzE3MTQ0NloXDTIyMDkxNTE3MTQ0NlowfzELMAkGA1UEBhMCVVMxETAPBgNVBAgTCFZpcmdp<br>bmlhMRIwEAYDVQQHEwlBcmxpbmd0b24xHzAdBgNVBAoTFlRyZW1vbG8gU2VjdXJpdHksIEluYy4x<br>EDAOBgNVBAsTB1Rlc3RpbmcxFjAUBgNVBAMTDWlkcC1zYW1sMi1zaWcwgZ8wDQYJKoZIhvcNAQEB<br>BQADgY0AMIGJAoGBAJIni3hDLjLak7lguCMjDFsHUso8qk+Xde2hveIGr4VIhGi6itWjLrf4XRRp<br>A3goOTBbm9nTj3iWHskmWm5ly1+OyOzkAxM7+Ws62bL5CfSmQwvVlw/YwaEmOEVAGdzTKcfZm+ju<br>rMv8Fw6UZ765Fny1I1KA1A1x7rhYpb3J/7t7AgMBAAGjODA2MAwGA1UdEwEB/wQCMAAwDgYDVR0P<br>AQH/BAQDAgWgMBYGA1UdJQEB/wQMMAoGCCsGAQUFBwMBMA0GCSqGSIb3DQEBBQUAA4GBAB0jGXs+<br>phEFdvOtqMP9yGvc0u7JN51ebmZr6aQ9nLrk1+YlsZgMfhzf4I7z+V3d42OOSTnB25O9+PB/z3MU<br>j7ui0CazW8VKnAzw1Cq9dvkaYqQz3JvTW
4GryEC/vkeH/diPA/X1NDQJ2nBUsFxnhIH59XmJKOSh<br>36loeqE7/Xhc&lt;/ds:X509Certificate&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/ds:X509Data&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &lt;/ds:KeyInfo&gt;<br>&nbsp; &nbsp; &lt;/ds:Signature&gt;<br>&nbsp; &nbsp; &lt;saml2p:Status&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &lt;saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success" /&gt;<br>&nbsp; &nbsp; &lt;/saml2p:Status&gt;<br>&nbsp; &nbsp; &lt;saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  ID="f7f54e02482c3d5297c30d16e83a32eb8f4e4e69a"<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  IssueInstant="2013-02-07T22:02:58.160Z"<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  Version="2.0"<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  &gt;<br>&nbsp; &nbsp; &nbsp; &nbsp;
 &lt;saml2:Issuer&gt;<a href="https://localhost.localdomain:8443/auth/idp/test" target="_blank">https://localhost.localdomain:8443/auth/idp/test</a>&lt;/saml2:Issuer&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &lt;saml2:Subject&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;saml2:NameID<br>Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"&gt;admin&lt;/saml2:NameID&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;saml2:SubjectConfirmation<br>Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;saml2:SubjectConfirmationData<br>NotOnOrAfter="2013-02-07T22:07:58.160Z"<br><br>Recipient="<a href="https://www.tremolosecurity-test.com/auth/SAML2Auth" target="_blank">https://www.tremolosecurity-test.com/auth/SAML2Auth</a>"<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 
 /&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/saml2:SubjectConfirmation&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &lt;/saml2:Subject&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &lt;saml2:Conditions NotBefore="2013-02-07T21:57:58.160Z"<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; NotOnOrAfter="2013-02-07T22:07:58.160Z"<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;saml2:AudienceRestriction&gt;<br><br>&lt;saml2:Audience&gt;<a href="https://www.tremolosecurity-test.com/auth/SAML2Auth" target="_blank">https://www.tremolosecurity-test.com/auth/SAML2Auth</a>&lt;/saml2:Audience&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/saml2:AudienceRestriction&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &lt;/saml2:Conditions&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &lt;saml2:AuthnStatement
 AuthnInstant="2013-02-07T22:02:58.160Z"<br><br>SessionIndex="f7f54e02482c3d5297c30d16e83a32eb8f4e4e69a"<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;saml2:AuthnContext&gt;<br><br>&lt;saml2:AuthnContextClassRef&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified&lt;/saml2:AuthnContextClassRef&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/saml2:AuthnContext&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &lt;/saml2:AuthnStatement&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &lt;saml2:AttributeStatement&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;saml2:Attribute Name="uid"&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;saml2:AttributeValue<br>xmlns:xs="http://www.w3.org/2001/XMLSchema"<br><br>xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance" target="_blank">http://www.w3.org/2001/XMLSchema-instance</a>"<br>&nbsp;
 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; xsi:type="xs:string"<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &gt;admin&lt;/saml2:AttributeValue&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/saml2:Attribute&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &lt;/saml2:AttributeStatement&gt;<br>&nbsp; &nbsp; &lt;/saml2:Assertion&gt;<br>&lt;/saml2p:Response&gt;<br><br>specifically the subject confirmation:<br><br>&lt;saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;saml2:SubjectConfirmationData<br>NotOnOrAfter="2013-02-07T22:07:58.160Z"<br><br>Recipient="<a href="https://www.tremolosecurity-test.com/auth/SAML2Auth" target="_blank">https://www.tremolosecurity-test.com/auth/SAML2Auth</a>"<br>&nbsp; &nbsp;
 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  /&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/saml2:SubjectConfirmation&gt;<br><br>I've tested this with shib, OIF, Ping, OpenAM, ADFS, ....<br><br>On Thu, Feb 7, 2013 at 4:45 PM, Brent Putman &lt;<a ymailto="mailto:putmanb@georgetown.edu" href="mailto:putmanb@georgetown.edu">putmanb@georgetown.edu</a>&gt; wrote:<br>&gt; The NotOnOrAfter is an optional attribute, but I'm not sure whether<br>&gt; legally it can be present but empty.&nbsp; Semantically it is pointless to do<br>&gt; that.<br>&gt;<br>&gt; But the real problem, as I said in the other message, is that the SAML<br>&gt; strucgture is just flat out wrong.<br>&gt;<br>&gt;<br>&gt;<br>&gt;<br>&gt; On 2/7/13 4:42 PM, Mike Flynn wrote:<br>&gt;&gt; Thanks, Marc.&nbsp; I asked them to correct that but was not sure if that<br>&gt;&gt; was the issue
 based on the message.<br>&gt;&gt;<br>&gt;&gt; ------------------------------------------------------------------------<br>&gt;&gt; *From:* Marc Boorshtein &lt;<a ymailto="mailto:mboorshtein@gmail.com" href="mailto:mboorshtein@gmail.com">mboorshtein@gmail.com</a>&gt;<br>&gt;&gt; *To:* Shib Users &lt;<a ymailto="mailto:users@shibboleth.net" href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br>&gt;&gt; *Sent:* Thursday, February 7, 2013 1:38 PM<br>&gt;&gt; *Subject:* Re: IdP initiated SSO<br>&gt;&gt;<br>&gt;&gt; NotOnorAfter is blank...<br>&gt;&gt;<br>&gt;&gt; On Thu, Feb 7, 2013 at 4:35 PM, Mike Flynn &lt;<a ymailto="mailto:shibbolethlynda@yahoo.com" href="mailto:shibbolethlynda@yahoo.com">shibbolethlynda@yahoo.com</a><br>&gt;&gt; &lt;mailto:<a ymailto="mailto:shibbolethlynda@yahoo.com" href="mailto:shibbolethlynda@yahoo.com">shibbolethlynda@yahoo.com</a>&gt;&gt; wrote:<br>&gt;&gt; &gt; This is what was sent:<br>&gt;&gt; &gt;<br>&gt;&gt;
 &gt; &lt;saml:SubjectConfirmation<br>&gt;&gt; &gt; Method="urn:oasis:names:tc:SAML:2.0:cm:holder-of-key"&gt;<br>&gt;&gt; &gt;&nbsp; &nbsp; &nbsp; &lt;saml:SubjectConfirmation<br>&gt;&gt; &gt; Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"&gt;<br>&gt;&gt; &gt;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;saml:SubjectConfirmationData NotOnOrAfter=""<br>&gt;&gt; &gt; Recipient="<a href="https://shib.lynda.com/Shibboleth.sso/SAML2/POST" target="_blank">https://shib.lynda.com/Shibboleth.sso/SAML2/POST</a>"/&gt;<br>&gt;&gt; &gt;&nbsp; &nbsp; &nbsp; &lt;/saml:SubjectConfirmation&gt;<br>&gt;&gt; &gt; &lt;/saml:SubjectConfirmation&gt;<br>&gt;&gt; &gt;<br>&gt;<br>&gt; --<br>&gt; To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>--<br>To unsubscribe from this list send an email to <a
 ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br><br><br> </div> </div>  </div></body></html>