<!DOCTYPE HTML><html>
<head>
<meta name="Generator" content="Amazon WorkMail v3.0-4275">
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<title>RE: Error encountered when implementing SP SAMLRequest signing="conditional"</title>
</head>
<body>
<p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;"><span style="background-color:#ffffff; color:#222222; font-family:arial,sans-serif; font-size:small; font-style:normal; font-variant-caps:normal; font-variant-ligatures:normal; font-weight:400; text-align:start; text-decoration-color:initial; text-decoration-style:initial; text-indent:0px; text-transform:none; white-space:normal; word-spacing:0px">Christian,</span></p><div style="background-color:#ffffff; color:#222222; font-family:arial,sans-serif; font-size:small; font-style:normal; font-variant-caps:normal; font-variant-ligatures:normal; font-weight:400; text-align:start; text-decoration-color:initial; text-decoration-style:initial; text-indent:0px; text-transform:none; white-space:normal; word-spacing:0px"> </div><div style="background-color:#ffffff; color:#222222; font-family:arial,sans-serif; font-size:small; font-style:normal; font-variant-caps:normal; font-variant-ligatures:normal; font-weight:400; text-align:start; text-decoration-color:initial; text-decoration-style:initial; text-indent:0px; text-transform:none; white-space:normal; word-spacing:0px">You might consider asking the IdP to add wantAuthnRequestsSigned to their metadata directly. Their provider's metadata needs to reflect their provider's requirements, and it sounds like in this case it doesn't. This is for 2.6.0:</div><div style="background-color:#ffffff; color:#222222; font-family:arial,sans-serif; font-size:small; font-style:normal; font-variant-caps:normal; font-variant-ligatures:normal; font-weight:400; text-align:start; text-decoration-color:initial; text-decoration-style:initial; text-indent:0px; text-transform:none; white-space:normal; word-spacing:0px"> </div><div style="background-color:#ffffff; color:#222222; font-family:arial,sans-serif; font-size:small; font-style:normal; font-variant-caps:normal; font-variant-ligatures:normal; font-weight:400; text-align:start; text-decoration-color:initial; text-decoration-style:initial; text-indent:0px; text-transform:none; white-space:normal; word-spacing:0px"><span style="background-color:#ffffff; color:#172b4d; font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen,Ubuntu,"Fira Sans","Droid Sans","Helvetica Neue",sans-serif; font-size:14px; text-decoration-color:initial; text-decoration-style:initial">The caveat with SAML 2.0 authentication is that omitting the setting defaults to a softer false that really means "don't sign unless the IdP's metadata includes the </span>WantAuthnRequestsSigned<span style="background-color:#ffffff; color:#172b4d; font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen,Ubuntu,"Fira Sans","Droid Sans","Helvetica Neue",sans-serif; font-size:14px; text-decoration-color:initial; text-decoration-style:initial"><span> </span>flag and the SP can do so".</span><span> </span></div><div style="background-color:#ffffff; color:#222222; font-family:arial,sans-serif; font-size:small; font-style:normal; font-variant-caps:normal; font-variant-ligatures:normal; font-weight:400; text-align:start; text-decoration-color:initial; text-decoration-style:initial; text-indent:0px; text-transform:none; white-space:normal; word-spacing:0px"> </div><div style="background-color:#ffffff; color:#222222; font-family:arial,sans-serif; font-size:small; font-style:normal; font-variant-caps:normal; font-variant-ligatures:normal; font-weight:400; text-align:start; text-decoration-color:initial; text-decoration-style:initial; text-indent:0px; text-transform:none; white-space:normal; word-spacing:0px"><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSigningEncryption" _src="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSigningEncryption">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSigningEncryption</a></div><div style="background-color:#ffffff; color:#222222; font-family:arial,sans-serif; font-size:small; font-style:normal; font-variant-caps:normal; font-variant-ligatures:normal; font-weight:400; text-align:start; text-decoration-color:initial; text-decoration-style:initial; text-indent:0px; text-transform:none; white-space:normal; word-spacing:0px"> </div><div style="background-color:#ffffff; color:#222222; font-family:arial,sans-serif; font-size:small; font-style:normal; font-variant-caps:normal; font-variant-ligatures:normal; font-weight:400; text-align:start; text-decoration-color:initial; text-decoration-style:initial; text-indent:0px; text-transform:none; white-space:normal; word-spacing:0px">In case Peter's hunch is right, I believe the same default behavior existed in 2.5.x, but I may be recalling wrong.</div><div style="background-color:#ffffff; color:#222222; font-family:arial,sans-serif; font-size:small; font-style:normal; font-variant-caps:normal; font-variant-ligatures:normal; font-weight:400; text-align:start; text-decoration-color:initial; text-decoration-style:initial; text-indent:0px; text-transform:none; white-space:normal; word-spacing:0px"> </div><div style="background-color:#ffffff; color:#222222; font-family:arial,sans-serif; font-size:small; font-style:normal; font-variant-caps:normal; font-variant-ligatures:normal; font-weight:400; text-align:start; text-decoration-color:initial; text-decoration-style:initial; text-indent:0px; text-transform:none; white-space:normal; word-spacing:0px">Take care,</div><div style="background-color:#ffffff; color:#222222; font-family:arial,sans-serif; font-size:small; font-style:normal; font-variant-caps:normal; font-variant-ligatures:normal; font-weight:400; text-align:start; text-decoration-color:initial; text-decoration-style:initial; text-indent:0px; text-transform:none; white-space:normal; word-spacing:0px">Nate.</div><div style="background-color:#ffffff; color:#222222; font-family:arial,sans-serif; font-size:small; font-style:normal; font-variant-caps:normal; font-variant-ligatures:normal; font-weight:400; text-align:start; text-decoration-color:initial; text-decoration-style:initial; text-indent:0px; text-transform:none; white-space:normal; word-spacing:0px"> </div><blockquote style="border-left:2px solid #b0b0b7; margin-left:5px; margin-right:0px; padding-left:5px">-----Original message-----<br /><strong>From:</strong> Pruvost, Christian (ELS-OXF)<br /><strong>Sent:</strong> Monday, October 8 2018, 4:27 am<br /><strong>To:</strong> users@shibboleth.net<br /><strong>Subject:</strong> Error encountered when implementing SP SAMLRequest signing="conditional"<br /><br /><!-- begin sanitized html --><style type="text/css"><--
@font-face
{font-family:Wingdings;
panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;
mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:#954F72;
text-decoration:underline;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
{mso-style-priority:34;
margin-top:0cm;
margin-right:0cm;
margin-bottom:0cm;
margin-left:36.0pt;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;
mso-fareast-language:EN-US;}
p.msonormal0, li.msonormal0, div.msonormal0
{mso-style-name:msonormal;
mso-margin-top-alt:auto;
margin-right:0cm;
mso-margin-bottom-alt:auto;
margin-left:0cm;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
span.EmailStyle18
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;
font-family:"Calibri",sans-serif;
mso-fareast-language:EN-US;}
@page WordSection1
{size:612.0pt 792.0pt;
margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
{page:WordSection1;}
@list l0
{mso-list-id:679312944;
mso-list-type:hybrid;
mso-list-template-ids:-237761938 134807575 134807577 134807579 134807567 134807577 134807579 134807567 134807577 134807579;}
@list l0:level1
{mso-level-number-format:alpha-lower;
mso-level-text:"%1)";
mso-level-tab-stop:none;
mso-level-number-:left;
text-indent:-18.0pt;}
@list l0:level2
{mso-level-number-format:alpha-lower;
mso-level-tab-stop:none;
mso-level-number-:left;
text-indent:-18.0pt;}
@list l0:level3
{mso-level-number-format:roman-lower;
mso-level-tab-stop:none;
mso-level-number-:right;
text-indent:-9.0pt;}
@list l0:level4
{mso-level-tab-stop:none;
mso-level-number-:left;
text-indent:-18.0pt;}
@list l0:level5
{mso-level-number-format:alpha-lower;
mso-level-tab-stop:none;
mso-level-number-:left;
text-indent:-18.0pt;}
@list l0:level6
{mso-level-number-format:roman-lower;
mso-level-tab-stop:none;
mso-level-number-:right;
text-indent:-9.0pt;}
@list l0:level7
{mso-level-tab-stop:none;
mso-level-number-:left;
text-indent:-18.0pt;}
@list l0:level8
{mso-level-number-format:alpha-lower;
mso-level-tab-stop:none;
mso-level-number-:left;
text-indent:-18.0pt;}
@list l0:level9
{mso-level-number-format:roman-lower;
mso-level-tab-stop:none;
mso-level-number-:right;
text-indent:-9.0pt;}
ol
{margin-bottom:0cm;}
ul
{margin-bottom:0cm;}
--></style><div class="bodyclass"><div class="WordSection1"><p class="MsoNormal">Dear User community,</p><p class="MsoNormal"> </p><p class="MsoNormal">We are running a Service Provider with Shibboleth 2.6.0 (I know that we should be upgrading to 3.x, but that is not the topic – we are not doing this right now)</p><p class="MsoNormal"> </p><p class="MsoNormal">We have a need to turn on Conditionally for a specific IDP the generation of a signature with the SAML Request (i.e. populating ‘SigAlg=…’ and ‘Signature=…’ together with the SAMLRequest sent to the IDP.</p><p class="MsoNormal"> </p><p class="MsoNormal">Our operations team is experiencing the following issue when:</p><ol><li><strong>Changing signing=… value from signing="false” to signing="conditional"</strong></li></ol><p class="MsoNormal"><span lang="EN-US" style="font-family:"Courier New""><ApplicationDefaults attributePrefix="ELS_" connectTimeout="10" encryption="conditional" entityID="<a title="This external link opens in a new window" href="https://sdauth.sciencedirect.com/">https://sdauth.sciencedirect.com/</a>" homeURL="<a title="This external link opens in a new window" href="https://auth.elsevier.com/ShibAuth/deliverInstCredentials">https://auth.elsevier.com/ShibAuth/deliverInstCredentials</a>" id="default" policyId="default" signing="conditional" timeout="20"></span></p><p class="MsoNormal"><span lang="EN-US" style="font-family:"Courier New""> </span></p><ol><li><strong>On restart </strong>to pick up the new configuration <strong>we get this error</strong>:</li></ol><p class="MsoNormal"><span lang="EN-US" style="font-family:"Courier New"">[root@ip-10-169-71-47 cloud]# /l-n/app/scidir/bin/start_shib_shar</span></p><p class="MsoNormal"><span lang="EN-US" style="font-family:"Courier New"">Using</span></p><p class="MsoNormal"><span lang="EN-US" style="font-family:"Courier New"">usage: /l-n/app/scidir/etc/scripts/rollLog.sh <days of logs> <logdir> <log1> [log2] ... [logN]</span></p><p class="MsoNormal"><span lang="EN-US" style="font-family:"Courier New"">Executing /l-n/app/scidir/bin/shibd -c /l-n/app/scidir/etc/shib/shibboleth_cloud.xml -d /l-n/app/scidir/etc/shib</span></p><p class="MsoNormal"><span lang="EN-US" style="font-family:"Courier New"">configuration is invalid, check console for specific problems</span></p><p class="MsoNormal"> </p><ol><li><strong>Logs</strong> showing:</li></ol><p class="MsoNormal"><span lang="EN-US" style="font-family:"Courier New"">22:58:38.879(08/29) ERROR XMLTooling.ParserPool : error on line 25, column 273, message: value 'conditional' not in enumeration</span></p><p class="MsoNormal"><span lang="EN-US" style="font-family:"Courier New"">22:58:38.879(08/29) ERROR XMLTooling.ParserPool : error on line 25, column 273, message: value 'conditional' not in enumeration</span></p><p class="MsoNormal"> </p><p class="MsoNormal">This is really odd. We are able to turn on the digital signature for all or noone, but not conditionally when the IDP Requests it ?!??</p><p class="MsoNormal"><span lang="EN-US" style="color:#1f497d"> </span></p><p class="MsoNormal">Has anyone encountered this issue, or who would be able to help with this?</p><p class="MsoNormal"> </p><p class="MsoNormal">Thank you,</p><p class="MsoNormal">Christian.<br /><span style="color:#1f497d; font-family:"Arial",sans-serif; font-size:7.5pt">________________________________________________________</span><br /><strong><span style="color:#ff8040; font-family:"Arial",sans-serif; font-size:7.5pt">Christian Pruvost</span></strong><span style="color:#ff8040; font-family:"Arial",sans-serif; font-size:7.5pt"> </span><br /><span lang="EN-US" style="color:#e36c0a; font-family:Wingdings; font-size:10.0pt">*</span><span style="color:#943634; font-family:"Arial",sans-serif; font-size:7.5pt">:</span><span style="color:#1f497d; font-family:"Arial",sans-serif; font-size:7.5pt"> </span><a title="This external link opens in a new window" href="mailto:c.pruvost@elsevier.com"><span style="color:blue; font-family:"Arial",sans-serif; font-size:7.5pt">c.pruvost@elsevier.com</span></a><br /> </p><p class="MsoNormal"> </p></div><style type="text/css">P {margin:0cm:margin-bottomL.0001pt;}</style><hr /><p><span style="font-family:"Arial","sans-serif"; font-size:10pt">Elsevier Limited. Registered Office: The Boulevard, Langford Lane, Kidlington, Oxford, OX5 1GB, United Kingdom, Registration No. 1982084, Registered in England and Wales.</span></p></div><pre>--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net</pre> <!-- end sanitized html --></blockquote>
</body>
</html>