<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]-->
<title>RE: Error encountered when implementing SP SAMLRequest signing="conditional"</title>
<style><!--
/* Font Definitions */
@font-face
        {font-family:Wingdings;
        panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}
@font-face
        {font-family:"Segoe UI";
        panose-1:2 11 5 2 4 2 4 2 2 3;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;
        mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
pre
        {mso-style-priority:99;
        mso-style-link:"HTML Preformatted Char";
        margin:0cm;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
        {mso-style-priority:34;
        margin-top:0cm;
        margin-right:0cm;
        margin-bottom:0cm;
        margin-left:36.0pt;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;
        mso-fareast-language:EN-US;}
p.msonormal0, li.msonormal0, div.msonormal0
        {mso-style-name:msonormal;
        mso-margin-top-alt:auto;
        margin-right:0cm;
        mso-margin-bottom-alt:auto;
        margin-left:0cm;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
span.EmailStyle21
        {mso-style-type:personal;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
span.HTMLPreformattedChar
        {mso-style-name:"HTML Preformatted Char";
        mso-style-priority:99;
        mso-style-link:"HTML Preformatted";
        font-family:Consolas;
        mso-fareast-language:EN-US;}
span.EmailStyle25
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
        {page:WordSection1;}
/* List Definitions */
@list l0
        {mso-list-id:502359680;
        mso-list-template-ids:-134864224;}
@list l1
        {mso-list-id:1859267945;
        mso-list-template-ids:-1341909904;}
@list l2
        {mso-list-id:1892956898;
        mso-list-template-ids:1010579832;}
ol
        {margin-bottom:0cm;}
ul
        {margin-bottom:0cm;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-GB" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">Hi Nate,<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thank you for flagging this. The IDP in question is certainly configured for this already. They were the one telling us that this is in their configuration, and is used by other Providers they work with. So we know that they will not accept
 our requests until these are signed. Since then we have attempted to conditionally turn this on for them, but that was so far not successful. (since it should be a simple config change, it is a little frustrating).<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">We did some upgrade in the last year or so from shib 2.4 to 2.6.0 so I have also asked our operation / dev team to check that no older file was eventually being picked up by accident and being responsible for this issue. (Thanks Peter for
 your earlier comment about this)<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Hopefully we will get to the bottom of this.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal"><span lang="EN-US" style="color:#1F497D;mso-fareast-language:EN-GB"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#1F497D;mso-fareast-language:EN-GB">Cheers,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#1F497D;mso-fareast-language:EN-GB">Christian.</span><span style="font-size:7.5pt;font-family:"Arial",sans-serif;color:#1F497D;mso-fareast-language:EN-GB"><br>
________________________________________________________<br>
</span><b><span style="font-size:7.5pt;font-family:"Arial",sans-serif;color:#FF8040;mso-fareast-language:EN-GB">Christian Pruvost</span></b><span style="font-size:7.5pt;font-family:"Arial",sans-serif;color:#FF8040;mso-fareast-language:EN-GB">                                           </span><span style="font-size:7.5pt;font-family:"Arial",sans-serif;color:#1F497D;mso-fareast-language:EN-GB"><br>
</span><span lang="EN-US" style="font-size:10.0pt;font-family:Wingdings;color:#E36C0A;mso-fareast-language:EN-GB">*</span><span style="font-size:7.5pt;font-family:"Arial",sans-serif;color:#943634;mso-fareast-language:EN-GB">:</span><span style="font-size:7.5pt;font-family:"Arial",sans-serif;color:#1F497D;mso-fareast-language:EN-GB">
</span><span lang="EN-US" style="color:#1F497D;mso-fareast-language:EN-GB"><a href="mailto:c.pruvost@elsevier.com"><span lang="EN-GB" style="font-size:7.5pt;font-family:"Arial",sans-serif;color:blue">c.pruvost@elsevier.com</span></a></span><span style="color:#1F497D;mso-fareast-language:EN-GB"><br>
<br>
</span><span style="font-size:7.5pt;font-family:"Arial",sans-serif;color:#1F497D;mso-fareast-language:EN-GB"><o:p></o:p></span></p>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal"><b><span lang="EN-US" style="mso-fareast-language:EN-GB">From:</span></b><span lang="EN-US" style="mso-fareast-language:EN-GB"> users <users-bounces@shibboleth.net>
<b>On Behalf Of </b>Nate Klingenstein<br>
<b>Sent:</b> 08 October 2018 13:55<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> RE: Error encountered when implementing SP SAMLRequest signing="conditional"<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p><strong><span style="font-family:"Calibri",sans-serif;color:white;background:red">*** External email: use caution ***</span></strong><o:p></o:p></p>
<p> <o:p></o:p></p>
<div>
<p style="margin:0cm;margin-bottom:.0001pt"><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#222222;background:white">Christian,</span><span style="font-size:12.0pt;font-family:"Arial",sans-serif"><o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#222222"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#222222">You might consider asking the IdP to add wantAuthnRequestsSigned to their metadata directly.  Their provider's metadata needs to reflect
 their provider's requirements, and it sounds like in this case it doesn't.  This is for 2.6.0:<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#222222"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:10.5pt;font-family:"Segoe UI",sans-serif;color:#172B4D;background:white">The caveat with SAML 2.0 authentication is that omitting the setting defaults to a softer false that really means "don't
 sign unless the IdP's metadata includes the </span><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#222222">WantAuthnRequestsSigned</span><span style="font-size:10.5pt;font-family:"Segoe UI",sans-serif;color:#172B4D;background:white"> flag
 and the SP can do so".</span><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#222222"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#222222"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#222222"><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSigningEncryption">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSigningEncryption</a><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#222222"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#222222">In case Peter's hunch is right, I believe the same default behavior existed in 2.5.x, but I may be recalling wrong.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#222222"> <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#222222">Take care,<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#222222">Nate.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:#222222"> <o:p></o:p></span></p>
</div>
<blockquote style="border:none;border-left:solid #B0B0B7 1.5pt;padding:0cm 0cm 0cm 4.0pt;margin-left:3.75pt;margin-top:5.0pt;margin-right:0cm;margin-bottom:5.0pt">
<p class="MsoNormal">-----Original message-----<br>
<strong><span style="font-family:"Calibri",sans-serif">From:</span></strong> Pruvost, Christian (ELS-OXF)<br>
<strong><span style="font-family:"Calibri",sans-serif">Sent:</span></strong> Monday, October 8 2018, 4:27 am<br>
<strong><span style="font-family:"Calibri",sans-serif">To:</span></strong> <a href="mailto:users@shibboleth.net">
users@shibboleth.net</a><br>
<strong><span style="font-family:"Calibri",sans-serif">Subject:</span></strong> Error encountered when implementing SP SAMLRequest signing="conditional"<br>
<br>
<br>
<span style="mso-fareast-language:EN-GB"><o:p></o:p></span></p>
<div>
<p class="MsoNormal">Dear User community,<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal">We are running a Service Provider with Shibboleth 2.6.0 (I know that we should be upgrading to 3.x, but that is not the topic – we are not doing this right now)<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal">We have a need to turn on Conditionally for a specific IDP the generation of a signature with the SAML Request (i.e. populating ‘SigAlg=…’ and ‘Signature=…’ together with the SAMLRequest sent to the IDP.<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal">Our operations team is experiencing the following issue when:<o:p></o:p></p>
<ol start="1" type="1">
<li class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l2 level1 lfo1">
<strong><span style="font-family:"Calibri",sans-serif;mso-fareast-language:EN-GB">Changing signing=… value from signing="false” to signing="conditional"</span></strong><span style="mso-fareast-language:EN-GB"><o:p></o:p></span></li></ol>
<p class="MsoNormal"><span lang="EN-US" style="font-family:"Courier New""><ApplicationDefaults attributePrefix="ELS_" connectTimeout="10" encryption="conditional" entityID="<a href="https://sdauth.sciencedirect.com/" title="This external link opens in a new window">https://sdauth.sciencedirect.com/</a>"
 homeURL="<a href="https://auth.elsevier.com/ShibAuth/deliverInstCredentials" title="This external link opens in a new window">https://auth.elsevier.com/ShibAuth/deliverInstCredentials</a>" id="default" policyId="default" signing="conditional" timeout="20"></span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-US" style="font-family:"Courier New""> </span><o:p></o:p></p>
<ol start="1" type="1">
<li class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l0 level1 lfo2">
<strong><span style="font-family:"Calibri",sans-serif;mso-fareast-language:EN-GB">On restart
</span></strong><span style="mso-fareast-language:EN-GB">to pick up the new configuration
<strong><span style="font-family:"Calibri",sans-serif">we get this error</span></strong>:<o:p></o:p></span></li></ol>
<p class="MsoNormal"><span lang="EN-US" style="font-family:"Courier New"">[root@ip-10-169-71-47 cloud]# /l-n/app/scidir/bin/start_shib_shar</span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-US" style="font-family:"Courier New"">Using</span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-US" style="font-family:"Courier New"">usage: /l-n/app/scidir/etc/scripts/rollLog.sh <days of logs> <logdir> <log1> [log2] ... [logN]</span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-US" style="font-family:"Courier New"">Executing /l-n/app/scidir/bin/shibd -c /l-n/app/scidir/etc/shib/shibboleth_cloud.xml -d /l-n/app/scidir/etc/shib</span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-US" style="font-family:"Courier New"">configuration is invalid, check console for specific problems</span><o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<ol start="1" type="1">
<li class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l1 level1 lfo3">
<strong><span style="font-family:"Calibri",sans-serif;mso-fareast-language:EN-GB">Logs</span></strong><span style="mso-fareast-language:EN-GB"> showing:<o:p></o:p></span></li></ol>
<p class="MsoNormal"><span lang="EN-US" style="font-family:"Courier New"">22:58:38.879(08/29) ERROR XMLTooling.ParserPool : error on line 25, column 273, message: value 'conditional' not in enumeration</span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-US" style="font-family:"Courier New"">22:58:38.879(08/29) ERROR XMLTooling.ParserPool : error on line 25, column 273, message: value 'conditional' not in enumeration</span><o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal">This is really odd. We are able to turn on the digital signature for all or noone, but not conditionally when the IDP Requests it ?!??<o:p></o:p></p>
<p class="MsoNormal"><span lang="EN-US" style="color:#1F497D"> </span><o:p></o:p></p>
<p class="MsoNormal">Has anyone encountered this issue, or who would be able to help with this?<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal">Thank you,<o:p></o:p></p>
<p class="MsoNormal">Christian.<br>
<span style="font-size:7.5pt;font-family:"Arial",sans-serif;color:#1F497D">________________________________________________________</span><br>
<strong><span style="font-size:7.5pt;font-family:"Arial",sans-serif;color:#FF8040">Christian Pruvost</span></strong><span style="font-size:7.5pt;font-family:"Arial",sans-serif;color:#FF8040">                                            
</span><br>
<span lang="EN-US" style="font-size:10.0pt;font-family:Wingdings;color:#E36C0A">*</span><span style="font-size:7.5pt;font-family:"Arial",sans-serif;color:#943634">:</span><span style="font-size:7.5pt;font-family:"Arial",sans-serif;color:#1F497D">
</span><a href="mailto:c.pruvost@elsevier.com" title="This external link opens in a new window"><span style="font-size:7.5pt;font-family:"Arial",sans-serif;color:blue">c.pruvost@elsevier.com</span></a><br>
 <o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<div class="MsoNormal" align="center" style="text-align:center"><span style="mso-fareast-language:EN-GB">
<hr size="2" width="100%" align="center">
</span></div>
<p><span style="font-size:10.0pt;font-family:"Arial",sans-serif">Elsevier Limited. Registered Office: The Boulevard, Langford Lane, Kidlington, Oxford, OX5 1GB, United Kingdom, Registration No. 1982084, Registered in England and Wales.</span><o:p></o:p></p>
</div>
<pre>-- <o:p></o:p></pre>
<pre><o:p> </o:p></pre>
<pre>For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">https://wiki.shibboleth.net/confluence/x/coFAAg</a><o:p></o:p></pre>
<pre><o:p> </o:p></pre>
<pre>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><o:p></o:p></pre>
</blockquote>
</div>
</div>
<style>P {margin:0cm:margin-bottomL.0001pt;}</style><br>
<hr>
<p><span style="font-size:10pt;font-family:"Arial","sans-serif"">Elsevier Limited. Registered Office: The Boulevard, Langford Lane, Kidlington, Oxford, OX5 1GB, United Kingdom, Registration No. 1982084, Registered in England and Wales.</span>
<br clear="none">
</p>
</body>
</html>