<div dir="ltr">Hi all, thanks for the quick replies.<div><br></div><div>I realize I must sound quite confused - I'm not a system owner either on the IdP nor the application side, I've just been tasked to come up with some way to break a stalemate where:</div><div><ol><li>the application must use the IdP for authentication</li><li>the application does not support signing requests nor decrypting SAML responses, vendor appears to have no intention to add functionality after multiple queries</li><li>the application currently has an unsupported version-specific hack in place that is facilitating IdP auth - there is no way to repurpose this to newer app versions</li><li>the application's current version is missing critical features which the business requires, however upgrade is impossible due to points 2./3.</li></ol><div>As there is already Apache running in front of the app, I was working on quite the hack as a proof-of-concept that would use Apache to look for authn request redirects, and send them to a helper application to add a signature before eventually getting to the IdP. Apache would also watch for incoming assertions and have the helper app decrypt them and send them on to the application, allowing session creation. Very ugly to do from scratch.</div></div><div><br></div><div>Perhaps mod_shib can already handle this use case, I just couldn't tell from this morning's reading session. I definitely appreciate the need for signing and encryption and wish the application was just doing the right thing, however as things stand the old version of the application is a security risk just due to lack of updates, and things are unlikely to change unless I can find a supportable way forward.</div><div><br></div><div>Cheers,</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Jan 24, 2019 at 12:12 PM Curry, Warren <<a href="mailto:whcurry@ufl.edu">whcurry@ufl.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">





<div lang="EN-US">
<div class="gmail-m_-4094228496049827707WordSection1">
<p class="MsoNormal"><span style="font-size:11pt;font-family:Arial,sans-serif;color:rgb(0,112,192)">Some  non technical aspects added to this.
<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Arial,sans-serif;color:rgb(0,112,192)"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Arial,sans-serif;color:rgb(0,112,192)">Encryption and signing are /should not be optional.    IT is the right thing to do in all cases. 
<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Arial,sans-serif;color:rgb(0,112,192)"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Arial,sans-serif;color:rgb(0,112,192)">Vendors or campus developers should be “strongly encouraged”  to the point of extreme exception .  Support the encryption and signing you are trying to avoid.    
<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Arial,sans-serif;color:rgb(0,112,192)"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Arial,sans-serif;color:rgb(0,112,192)">We have a very few exceptions.   But it is difficult for any SP in our base to be approved to not encrypt the assertion , etc. 
<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Arial,sans-serif;color:rgb(0,112,192)"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Arial,sans-serif;color:rgb(0,112,192)">This is not technical but  rather standard, practice and risk based practice that we live by.   I know many others who are essentially very similar.       Vendors
 will and have aligned when pushed on or other vendors exist.  Institutionally developed applications are simply expected to accommodate the standard practice of requiring SP to encrypt /sign etc..  .    <u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Arial,sans-serif;color:rgb(0,112,192)"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Arial,sans-serif;color:rgb(0,112,192)">Of 2000+ SPs running at our institution, we can count on my fingers SPs with exceptions and some of those are startup exceptions while adjustments/fixes are made
 to the service provider to align with the institutional practice and standard of encryption… .  <u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Arial,sans-serif;color:rgb(0,112,192)"><u></u> <u></u></span></p>
<div>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(0,112,192)">-whc<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(0,112,192)"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(0,112,192)">Warren Curry<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(0,112,192)">Identity Architect
<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(0,112,192)">UF Information Technology – Indentity Services<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(0,112,192)">720 SW 2<sup>nd</sup> Street – Ayers Bldg<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(0,112,192)">352-273-1383<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(0,112,192)"><a href="http://identity.it.ufl.edu/" target="_blank"><span style="color:rgb(5,99,193)">http://identity.it.ufl.edu/</span></a>
<u></u><u></u></span></p>
</div>
<p class="MsoNormal"><span style="font-size:11pt;font-family:Arial,sans-serif;color:rgb(0,112,192)"><u></u> <u></u></span></p>
<div>
<div style="border-right:none;border-bottom:none;border-left:none;border-top:1pt solid rgb(225,225,225);padding:3pt 0in 0in">
<p class="MsoNormal"><b><span style="font-size:11pt;font-family:Calibri,sans-serif">From:</span></b><span style="font-size:11pt;font-family:Calibri,sans-serif"> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>>
<b>On Behalf Of </b>Domingues, Michael D<br>
<b>Sent:</b> Thursday, January 24, 2019 11:53 AM<br>
<b>To:</b> <a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a><br>
<b>Subject:</b> Re: Encryption-less SP to auth against encryption-mandating IdP?<u></u><u></u></span></p>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div id="gmail-m_-4094228496049827707divtagdefaultwrapper">
<p><span style="font-size:11pt;font-family:Calibri,sans-serif;color:black">Hi Daniel,<u></u><u></u></span></p>
<p><span style="font-size:11pt;font-family:Calibri,sans-serif;color:black"><u></u> <u></u></span></p>
<p><span style="font-size:11pt;font-family:Calibri,sans-serif;color:black">What portions of the proposed system are under your control? Are you responsible for the web application that wants to receive user data (the service provider), the system that authenticate
 your users (the identity provider), or both?<u></u><u></u></span></p>
<p><span style="font-size:11pt;font-family:Calibri,sans-serif;color:black"><u></u> <u></u></span></p>
<p><span style="font-size:11pt;font-family:Calibri,sans-serif;color:black">Fundamentally, Shibboleth isn't just one product --- it's a suite of products developed to fulfill the two (primary) roles in a SAML login flow. One piece of software, the Shibboleth
 Service Provider (SP) works as an authentication middleware in conjunction with your web server, through something like mod_shib. mod_shib isn't the SP, it just bridges the SP software to your web application. The Shibboleth SP handles the generation of AuthN
 requests, comes with metadata (that you'll need to customize), and parses the SAML assertions that get sent to it, exposing identity data to your web application via server variables (or headers).<u></u><u></u></span></p>
<p><span style="font-size:11pt;font-family:Calibri,sans-serif;color:black"><u></u> <u></u></span></p>
<p><span style="font-size:11pt;font-family:Calibri,sans-serif;color:black">The other primary piece of software Shibboleth Identity Provider. It handles responding to AuthN requests, authenticating your users, then resolving identity data from underlying
 data connectors (LDAP, SQL, your person registry, etc) and sending SAML assertions to the SPs that sent the AuthN request in the first place.<u></u><u></u></span></p>
<p><span style="font-size:11pt;font-family:Calibri,sans-serif;color:black"><u></u> <u></u></span></p>
<p><span style="font-size:11pt;font-family:Calibri,sans-serif;color:black">Typically, you're only concerned with one of these things --- you're an application developer (or server admin) looking to get the Service Provider installed, or an identity team,
 looking to maintain the Identity Provider infrastructure for your institution.<u></u><u></u></span></p>
<p><span style="font-size:11pt;font-family:Calibri,sans-serif;color:black"><u></u> <u></u></span></p>
<p><span style="font-size:11pt;font-family:Calibri,sans-serif;color:black">If you control the SP, you absolutely can support encryption, metadata generation, etc. If you control the IdP, you can configure it on a per-SP basis (see the documentation for
 relying-party.xml [1]) to change its requirements depending on what an SP supports. In this scenario, if you control the IdP but not the SP, you could configure the IdP to permit non-signed AuthN requests, and send unencrypted assertions to the SP in question.<u></u><u></u></span></p>
<p><span style="font-size:11pt;font-family:Calibri,sans-serif;color:black"><u></u> <u></u></span></p>
<p><span style="font-size:11pt;font-family:Calibri,sans-serif;color:black">I hope this helps,<u></u><u></u></span></p>
<p><span style="font-size:11pt;font-family:Calibri,sans-serif;color:black"><u></u> <u></u></span></p>
<p><span style="font-size:11pt;font-family:Calibri,sans-serif;color:black">Michael<u></u><u></u></span></p>
<p><span style="font-size:11pt;font-family:Calibri,sans-serif;color:black"><u></u> <u></u></span></p>
<p><span style="font-size:11pt;font-family:Calibri,sans-serif;color:black">[1]
<a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_display_IDP30_RelyingPartyConfiguration&d=DwMFAg&c=pZJPUDQ3SB9JplYbifm4nt2lEVG5pWx2KikqINpWlZM&r=UBkKx63rTinSBj-2DQ-E7g&m=RDSS14TKNDX7wgCXGQtKRRZINvo0NxkDusbs5Lb-3pY&s=PI2_MXR_TqSIVvQT7KT2Fq2Wsljd_-hcUKyNTnZMFSw&e=" id="gmail-m_-4094228496049827707LPlnk49102" target="_blank">
https://wiki.shibboleth.net/confluence/display/IDP30/RelyingPartyConfiguration</a><u></u><u></u></span></p>
</div>
<div class="MsoNormal" align="center" style="text-align:center">
<hr size="2" width="98%" align="center">
</div>
<div id="gmail-m_-4094228496049827707divRplyFwdMsg">
<p class="MsoNormal"><b><span style="font-size:11pt;font-family:Calibri,sans-serif;color:black">From:</span></b><span style="font-size:11pt;font-family:Calibri,sans-serif;color:black"> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>>
 on behalf of Daniel Smith <<a href="mailto:danielesmith@gmail.com" target="_blank">danielesmith@gmail.com</a>><br>
<b>Sent:</b> Thursday, January 24, 2019 10:40:42 AM<br>
<b>To:</b> <a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a><br>
<b>Subject:</b> Encryption-less SP to auth against encryption-mandating IdP?</span>
<u></u><u></u></p>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
</div>
<div>
<div>
<p class="MsoNormal">I'm new to Shibboleth as of today, and the documentation is a little overwhelming. I was wondering if the following scenario is possible:
<u></u><u></u></p>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">1. SP requires SAML 2.0 assertion for user groups to assign roles, but does not support assertion decryption, nor metadata generation, nor authn request signing<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">2. IdP mandates assertion encryption and authn request signing<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">3. Shibboleth hopefully sits in the middle, sending signed authn requests to IdP and decrypted SAML assertions to SP<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Ideally I'd like to use mod_shib as the SP already has Apache running. Is there a walkthrough for this kind of scenario or do I just have to keep reading? Or, is this kind of encryption-one-way-but-not-the-other not supported?<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Thanks,<u></u><u></u></p>
</div>
</div>
</div>
</div>
</div>

-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div>