<div dir="ltr">Hi all,<br><br> I'm integrating Shibboleth SP with Idp 3.2.1. Signing and encryption is enabled in SP shibboleth2.xml file in this way:<br><br> <ApplicationDefaults entityID="<a href="https://sp.local:8443/shibboleth-sp">https://sp.local:8443/shibboleth-sp</a>"<br> REMOTE_USER="eppn persistent-id targeted-id" signing="true" encryption="true"><br><br> SSO works fine but when I try to logout from SP (<a href="https://sp.host/Shibboleth.sso/Logout">https://sp.host/Shibboleth.sso/Logout</a>) the LogoutRequest cannot be processed by the Idp and logout fails. I tried it with SP version 2.5.6 and 2.6.0 without success.<br><br><br>This is an extract from idp-process.log <br><br> 2016-12-14 13:13:44,608 - INFO [org.springframework.beans.factory.xml.XmlBeanDefinitionReader:317]- Loading XML bean definitions from file [/opt/tomcat/webapps/idp/idp/system/flows/saml/saml2/../security-beans.xml]<br>2016-12-14 13:13:44,624 - INFO [org.springframework.web.context.support.GenericWebApplicationContext:578]- Refreshing Flow ApplicationContext [intercept/security-policy/saml2-slo]: startup date [Wed Dec 14 13:13:44 GMT 2016]; parent: WebApplicationContext for namespace 'idp-servlet'<br>2016-12-14 13:13:44,625 - INFO [org.springframework.beans.factory.support.DefaultListableBeanFactory:869]- Replacing scope 'request' from [org.springframework.web.context.request.RequestScope@4011eb3] to [org.springframework.web.context.request.RequestScope@324bcfff]<br>2016-12-14 13:13:44,695 - INFO [org.opensaml.xmlsec.keyinfo.impl.BasicProviderKeyInfoCredentialResolver:164]- KeyInfo was null, any credentials will be resolved by post-processing hooks only<br>2016-12-14 13:13:44,720 - ERROR [org.opensaml.xmlsec.encryption.support.Decrypter:603]- Error decrypting the encrypted data element<br>org.apache.xml.security.encryption.XMLEncryptionException: Illegal key size<br> at org.apache.xml.security.encryption.XMLCipher.decryptToByteArray(XMLCipher.java:1852)<br>Caused by: java.security.InvalidKeyException: Illegal key size<br> at javax.crypto.Cipher.checkCryptoPerm(Cipher.java:1039)<br>2016-12-14 13:13:44,721 - ERROR [org.opensaml.xmlsec.encryption.support.Decrypter:547]- Failed to decrypt EncryptedData using either EncryptedData KeyInfoCredentialResolver or EncryptedKeyResolver + EncryptedKey KeyInfoCredentialResolver<br>2016-12-14 13:13:44,722 - ERROR [org.opensaml.saml.saml2.encryption.Decrypter:178]- SAML Decrypter encountered an error decrypting element content<br>org.opensaml.xmlsec.encryption.support.DecryptionException: Failed to decrypt EncryptedData<br> at org.opensaml.xmlsec.encryption.support.Decrypter.decryptDataToDOM(Decrypter.java:550)<br>2016-12-14 13:13:44,722 - WARN [org.opensaml.saml.saml2.profile.impl.DecryptNameIDs:99]- Profile Action DecryptNameIDs: Failure performing decryption<br>org.opensaml.xmlsec.encryption.support.DecryptionException: Failed to decrypt EncryptedData<br> at org.opensaml.xmlsec.encryption.support.Decrypter.decryptDataToDOM(Decrypter.java:550)<br>2016-12-14 13:13:44,728 - WARN [org.opensaml.profile.action.impl.LogEvent:76]- An error event occurred while processing the request: DecryptNameIDFailed<br><br><br>This is the LogoutRequest sent by Shibboleth SP:<br><br><?xml version="1.0" encoding="UTF-8"?><br><samlp:LogoutRequest<br> Destination="<a href="https://idp.local/idp/profile/SAML2/Redirect/SLO">https://idp.local/idp/profile/SAML2/Redirect/SLO</a>"<br> ID="_44c87f81bab5e6108be3ce67751df9ac"<br> IssueInstant="2016-12-14T13:13:44Z" Version="2.0" xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"><br> <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://sp.local:8443/shibboleth-sp">https://sp.local:8443/shibboleth-sp</a></saml:Issuer><br> <saml:EncryptedID xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><br> <xenc:EncryptedData<br> Type="<a href="http://www.w3.org/2001/04/xmlenc#Element">http://www.w3.org/2001/04/xmlenc#Element</a>"<br> xmlns:xenc="<a href="http://www.w3.org/2001/04/xmlenc#">http://www.w3.org/2001/04/xmlenc#</a>"><br> <xenc:EncryptionMethod<br> Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#aes256-cbc">http://www.w3.org/2001/04/xmlenc#aes256-cbc</a>"/><br> <ds:KeyInfo xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"><br> <xenc:EncryptedKey xmlns:xenc="<a href="http://www.w3.org/2001/04/xmlenc#">http://www.w3.org/2001/04/xmlenc#</a>"><br> <xenc:EncryptionMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p">http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p</a>"><br> <ds:DigestMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#sha1">http://www.w3.org/2000/09/xmldsig#sha1</a>" xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"/><br> </xenc:EncryptionMethod><br> <xenc:CipherData><br> <xenc:CipherValue>FsfEPW0Q5JZk3Im+4tf2NXbYIafNCdaWlEC3/2kuvOMZVLLV/RoMw1RsIl7OUYl7Or/hgTzhLB9Y<br> 37jf/qTk4gPv5R4VZ6l62yJHakQtDk3lZjMeubSn6BuPOF8wvnHuyYNCyiRcFWP8MtzAVQFBeiYw<br> RvcKM3y5x0BHpnjrh2eAbzigIftNF/U+1H4U++q6Tr4LR7lRcTi8We07Jv68uw/+Gab8zoRFiULK<br> vOnVK89A5Kb61vU0pXdYtCtAcJUbjwVv5pmfe9V1jI6qUWEx9Q28Rg5Sp7M1+LyOgE+Ml1jhNPLr<br> v3jBBDlJSCr8KWpwvgZ5HbUzlSsYTE5bE/uwhA==</xenc:CipherValue><br> </xenc:CipherData><br> </xenc:EncryptedKey><br> </ds:KeyInfo><br> <xenc:CipherData><br> <xenc:CipherValue>7IbLRF02XwgdX8LmpsEdNKU2ri6e9XVD6KG8NVMxa5T9H7u+CaMal2qXi1k00PWX0m+cvOzGj/t5<br> TL1KQYTJxvcpp0XcxJwd8m0voI3VGCdOCBhUlEjg0AufyhGYgP7X6KEllZTFv4kAHLoWA+hw2IZg<br> MR3/e1nX8v+oxwZP9ujOQ6HYCbWup1L6ziJMo5s8IbX6460hT/hoTGCP/1BzqBCySqwYOJf01qaa<br> RKj2AEE3ws7imeTfc8p8jE28FrFluUZKIsokSc1LAsSvjAiUTa8++5dCODF/PFHAR7dD/CUEOTGQ<br> 4u82oEtbk5Zs4+Ff8Xosrhl4/sZOB5wDwDiJUcbdn6tt9EE0pIoaxQ9dYomD6SHtGyOtgJtxnZRx<br> sKm/EImVuo8dr9Es1icr9ZFSmg==</xenc:CipherValue><br> </xenc:CipherData><br> </xenc:EncryptedData><br> </saml:EncryptedID><br> <samlp:SessionIndex>_299489b8cabc2f4dbdfe503ffff326eb</samlp:SessionIndex><br></samlp:LogoutRequest><br><br><br>I suppose SP or Idp has some kind of configuration issue, but I cannot find it.<br>Could you give some ideas to solve it?<br><br>Thanks,<br clear="all"><br>-- <br><div class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr">----------------------------------------------------------<br>José Luis Canales Gasco<br><br><div style="font-family:arial;font-size:12.66px"><img src="http://www.paradigmatecnologico.com/wp-content/themes/paradigma13/images/logos/logo_paradigma_2013_BIG.png" style="font-size: small;" width="96" height="24"><span style="color:rgb(153,153,153);font-family:tahoma,sans-serif;font-size:x-small"><br></span><span style="color:rgb(153,153,153);font-family:tahoma,sans-serif;font-size:x-small">Vía de las Dos Castillas, 33. Ática 4. 2ª Planta</span><span style="color:rgb(153,153,153);font-family:tahoma,sans-serif;font-size:x-small"><br></span></div><div style="font-size:12.72px"><div><font size="1" color="#999999" face="tahoma, sans-serif">28224 Pozuelo de Alarcón, Madrid<br></font></div><div><font size="1" color="#999999" face="tahoma, sans-serif">Tel.: 91 352 59 42 // @paradigmate</font></div></div></div></div></div></div></div></div>
</div>