<div dir="ltr"><div>I've been testing IDP 3.4.0 snapshots, and I'm finding that parts of the signature and encrypted data in the response include XML-encoded carriage returns. It seems not unlike an issue addressed a few years ago <a href="https://issues.shibboleth.net/jira/browse/JSPT-50">https://issues.shibboleth.net/jira/browse/JSPT-50</a> but in a different area of the XML. I work with at least one SP will break on this if it remains in 3.4. Is there something I can do to prevent the &#xd; being generated? I'm unfamiliar with the codebase and haven't yet tracked down where they're introduced.</div><div><br></div><div>Sorry if this should go to another list. I can't tell where it's best to send questions about unreleased versions.</div><div><br></div><div>SAML response example, with some "..." abbreviations:</div><div><br></div><div><?xml version="1.0" encoding="UTF-8"?></div><div><saml2p:Response</div><div>    Destination="<a href="http://localtest:8888/simplesaml/module.php/saml/sp/saml2-acs.php/qa-idp">http://localtest:8888/simplesaml/module.php/saml/sp/saml2-acs.php/qa-idp</a>"</div><div>    ID="_b9f88857a65dfde9454786e4e6887565"</div><div>    InResponseTo="_43d571f998bbd934ee064bba29ef63469eb93e3d9d"</div><div>    IssueInstant="2018-07-04T15:40:47.907Z" Version="2.0" xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"></div><div>    <saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://signonqa.domain/idp/shibboleth">https://signonqa.domain/idp/shibboleth</a></saml2:Issuer></div><div>    <ds:Signature</div><div>                xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"></div><div><ds:SignedInfo></div><div><ds:CanonicalizationMethod</div><div>                Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/></div><div><ds:SignatureMethod</div><div>                Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256">http://www.w3.org/2001/04/xmldsig-more#rsa-sha256</a>"/></div><div><ds:Reference</div><div>                        URI="#_b9f88857a65dfde9454786e4e6887565"></div><div><ds:Transforms></div><div><ds:Transform</div><div>                        Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature">http://www.w3.org/2000/09/xmldsig#enveloped-signature</a>"/></div><div><ds:Transform</div><div>                    Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/></div><div></ds:Transforms></div><div><ds:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#sha256">http://www.w3.org/2001/04/xmlenc#sha256</a>"/></div><div><ds:DigestValue>/1TFvcwSkf1eyzTFnEJeDL1onQdXHloyiuFspKiCP7I=</ds:DigestValue></div><div></ds:Reference></div><div></ds:SignedInfo></div><div><ds:SignatureValue></div><div>OGIPYFwFcSlrcRb9DDmUdnZZME4y0sMpLUmioXt5vrCUk1vg0XVUzSXRvvePl8yyy/KaNkH8XI1l&#xd;</div><div>wZyTSYe20XwLd3+LN8h59iNC791/qEg7yT+FhiH00xxg5lOBdwrhoWPZilgB4RhcpEhRYaENeCt5&#xd;</div><div>qCJd2e5m/Uf/CMC4XK93mqvqQDhpeKqsWjAw3rKPaA6qIfZjb8vQLPpJeRnPAgh7NCXWmYIT4EMe&#xd;</div><div>PJD0WP3W/Yxjy9ParsmzEDAb1bpYuS/Z0IEiIYSN0LncQplJDredu/qAufe/unh5sMXr8Vzbm/+7&#xd;</div><div>aJdMNfId46GP777KX5BJYq8apN/3+OmONNORbA==</div><div></ds:SignatureValue></div><div><ds:KeyInfo></div><div>            <ds:X509Data></div><div>                <ds:X509Certificate>MIIDNzCCAh+gAwIBAgIUZGP9KZJycCCasgIn1by4rR44RvowDQYJKoZIhvcNAQELBQAwHjEcMBoG</div><div>A1UEAwwTc2lnbm9ucWEubW5zdGF0ZS51czAeFw0xNzEyMTgwMzI1NTBaFw0zNzEyMTgwMzI1NTBa</div><div>MB4xHDAaBgNVBAMME3NpZ25vbnFhLm1uc3RhdGUudXMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw</div><div>...</div><div>TYRZQNwMYgL3R03DhRiFze7fgwmltF/Xnl8MSH03Ddl96YosK8c7k3IHmaMaWKxrpeoKMvVqiTWk</div><div>Mq2Y9ahrTuDTNmVunaZcYamkHV8JjZdna3tOrvItlm1OAD+ClZAatve++gwShQ1GsBTD5coTnqOb</div><div>sKW3Ss2FNS5N7dryjpNUkzerrFb9e9jpHNGn42Wl62s0+NHGX3rQ0EcK9thsb4Ok4Na/EP+UpozZ</div><div>0xmDmsHxwI4nE9iFdf3x0iKnTwp0S8/AC+AlnEw=</ds:X509Certificate></div><div>            </ds:X509Data></div><div>        </ds:KeyInfo></div><div>    </ds:Signature></div><div>    <saml2p:Status></div><div>        <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/></div><div>    </saml2p:Status></div><div>    <saml2:EncryptedAssertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"></div><div>        <xenc:EncryptedData Id="_61631a441c457e33be9fa75f449f24bb"</div><div>            Type="<a href="http://www.w3.org/2001/04/xmlenc#Element">http://www.w3.org/2001/04/xmlenc#Element</a>" xmlns:xenc="<a href="http://www.w3.org/2001/04/xmlenc#">http://www.w3.org/2001/04/xmlenc#</a>"></div><div>            <xenc:EncryptionMethod</div><div>                Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#aes128-cbc">http://www.w3.org/2001/04/xmlenc#aes128-cbc</a>" xmlns:xenc="<a href="http://www.w3.org/2001/04/xmlenc#">http://www.w3.org/2001/04/xmlenc#</a>"/></div><div>            <ds:KeyInfo xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"></div><div>                <xenc:EncryptedKey</div><div>                    Id="_25197ef48d4df756d4928d53a2a5fb30"</div><div>                    Recipient="<a href="http://localtest:8888/simplesaml/module.php/saml/sp/metadata.php/qa-idp">http://localtest:8888/simplesaml/module.php/saml/sp/metadata.php/qa-idp</a>" xmlns:xenc="<a href="http://www.w3.org/2001/04/xmlenc#">http://www.w3.org/2001/04/xmlenc#</a>"></div><div>                    <xenc:EncryptionMethod</div><div>                        Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p">http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p</a>" xmlns:xenc="<a href="http://www.w3.org/2001/04/xmlenc#">http://www.w3.org/2001/04/xmlenc#</a>"></div><div>                        <ds:DigestMethod</div><div>                            Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#sha1">http://www.w3.org/2000/09/xmldsig#sha1</a>" xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"/></div><div>                    </xenc:EncryptionMethod></div><div>                    <ds:KeyInfo></div><div>                        <ds:X509Data></div><div>                            <ds:X509Certificate>MIID8DCCAtigAwIBAgIJAIahUxslYqbbMA0GCSqGSIb3DQEBBQUAMFgxCzAJBgNVBAYTAlVTMRIw</div><div>EAYDVQQIEwlNaW5uZXNvdGExEzARBgNVBAcTClNhaW50IFBhdWwxDzANBgNVBAoTBkpvYmxvZzEP</div><div>...</div><div>6zB2dsPglueHbD1kvhqvSKCUtgcCJIauYLaIEzY3Y/0e+mw6IBpXFMiayQ==</ds:X509Certificate></div><div>                        </ds:X509Data></div><div>                    </ds:KeyInfo></div><div>                    <xenc:CipherData xmlns:xenc="<a href="http://www.w3.org/2001/04/xmlenc#">http://www.w3.org/2001/04/xmlenc#</a>"></div><div>                        <xenc:CipherValue>Lwv1flvfJNXx0rR2OmqHHeTb7tLhGMkS7oqESruJtiVSzBHWcw5ME/OM8YqZLCpfu89KmgtzYQ47&#xd;</div><div>eltlAvPImhDLhHuTs3920RdNkOIT/gLF3Wp3KWcP30qNgpmDUW2P3dZGV+cKoZsp6mCl1mT7zzq9&#xd;</div><div>8YvU5Ljlie1CPlVKDufFD7gOr1QXuWiPwNxw6QTFBuisZmKZYi+dxMLDi0zerL3SJ/J+6FnMtIvk&#xd;</div><div>D6K1DZztVr9PtoLecQ8ZbJ1vgbpxg7rqUX0A7YPGRps/PRTehOBDUDmMyaHLJoA5onCqAAUoCKlv&#xd;</div><div>hHckJPt9dm/RXvQRjjjcdv6un5wlLNYdQWMpFA==</xenc:CipherValue></div><div>                    </xenc:CipherData></div><div>                </xenc:EncryptedKey></div><div>            </ds:KeyInfo></div><div>            <xenc:CipherData xmlns:xenc="<a href="http://www.w3.org/2001/04/xmlenc#">http://www.w3.org/2001/04/xmlenc#</a>"></div><div>                <xenc:CipherValue>Hbblx/phsxSe9uWeIkNSIAH0QJBubGp/Rv5Afd3lyKUCm1wOpfapixtmorWse9Sz1bXTiU+gkWBh&#xd;</div><div>rGwiX+oF3K44MLmj3DTxKjGZEz9sQIdEwTuiRxa8823iefW4xKsYwLv2d5txnijqVF6u+7FY1KJz&#xd;</div><div>4IJKW5uGYH1PbQAYfo7sEu99JBXTSkAuZpVQuix/xmdekIe+TfNv/crKYPjbcd3egDp/IHbu8sbn&#xd;</div><div>Bn+R0OUaL+KVOsAMsAEipaR+OnSfRIJoRraMyp/XmC8W3L53tGIay10+Z46KAFoZdE6OlCb+mMyp&#xd;</div><div>CGIZh4SFicOLaCZdQ7uvjr2RRNwvn4lUTcagdrgwMRqxFDSeqW3miOHIQVYK/yyELhHE+RhBCAOe&#xd;</div><div>...</div><div>eFUKR8nIaJwnEC8x+V2ax43v2tKUlXiAV1KeNUTLwA6kNycokgcx9nCeu8WYSxUzDepHBn/wWJxy&#xd;</div><div>E7PfkQhQln9MT1ZdcsQnXND2xHckNtJqEUBDrVF5naYljPg1pmL5d6uJa/UHGC85Z0l3ixUx8Fip&#xd;</div><div>AFqqqbM=</xenc:CipherValue></div><div>            </xenc:CipherData></div><div>        </xenc:EncryptedData></div><div>    </saml2:EncryptedAssertion></div><div></saml2p:Response></div></div>