<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Hello Nate,</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
thank you very much for your detailed response! <span id="🙂">🙂 According to our IDP it'd take quite long to make this change on their side, because they also rely on third-party components for it. So h</span>aving a configuration option in shibboleth for
the encoding would be great. How can I submit such a request?</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Cheers</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Corin</div>
<div>
<div id="appendonsend"></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>Von:</b> users <users-bounces@shibboleth.net> im Auftrag von Nate Klingenstein <ndk@signet.id><br>
<b>Gesendet:</b> Mittwoch, 20. Oktober 2021 12:13<br>
<b>An:</b> Shib Users <users@shibboleth.net>; users@shibboleth.net <users@shibboleth.net><br>
<b>Betreff:</b> RE: SAML forceAuthn attribute XML encoding issue</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt">
<div class="PlainText">Corin,<br>
<br>
The specification they're referencing is designed for a user-agent to SP interaction to get an AuthnRequest, so it has no direct relevance to the AuthnRequest's contents, although it should also be interpreted as an XML Boolean. The schema for an AuthnRequest
contains:<br>
<br>
<attribute name="IsPassive" type="boolean" use="optional"/><br>
<br>
<a href="https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fdocs.oasis-open.org%2Fsecurity%2Fsaml%2Fv2.0%2Fsaml-core-2.0-os.pdf&data=04%7C01%7CCorin.Langosch%40swisscom.com%7C847a6e33cda444e3208708d993b23d18%7C364e5b87c1c7420d9beec35d19b557a1%7C0%7C0%7C637703215997797862%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=xgK4DoHTgAK2vPiJqy97h1Nh%2FjeigMa9f7UVFFcjQb4%3D&reserved=0">https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fdocs.oasis-open.org%2Fsecurity%2Fsaml%2Fv2.0%2Fsaml-core-2.0-os.pdf&data=04%7C01%7CCorin.Langosch%40swisscom.com%7C847a6e33cda444e3208708d993b23d18%7C364e5b87c1c7420d9beec35d19b557a1%7C0%7C0%7C637703215997797862%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=xgK4DoHTgAK2vPiJqy97h1Nh%2FjeigMa9f7UVFFcjQb4%3D&reserved=0</a><br>
<br>
While the example text includes "true" or "false" only, "1" and "0" should be permissible as well AFAIK under the XML and SAML specifications. It is a formal Boolean, and "1" is probably used here in order to constrain the size of an AuthnRequest, which has
to be serialized into a URL with the Redirect binding. I might consider requesting a configuration option in the SP or asking the IdP to support it per the XML specification.<br>
<br>
Take care,<br>
Nate.<br>
<br>
--------<br>
Signet, Inc.<br>
The Art of Access ®<br>
<br>
<a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.signet.id%2F&data=04%7C01%7CCorin.Langosch%40swisscom.com%7C847a6e33cda444e3208708d993b23d18%7C364e5b87c1c7420d9beec35d19b557a1%7C0%7C0%7C637703215997797862%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=iwlkMtLaN1c4ZWZ66xOFBmuy%2BdoToDPtnZ4AXcVYzUQ%3D&reserved=0">https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.signet.id%2F&data=04%7C01%7CCorin.Langosch%40swisscom.com%7C847a6e33cda444e3208708d993b23d18%7C364e5b87c1c7420d9beec35d19b557a1%7C0%7C0%7C637703215997797862%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=iwlkMtLaN1c4ZWZ66xOFBmuy%2BdoToDPtnZ4AXcVYzUQ%3D&reserved=0</a><br>
<br>
-----Original message-----<br>
From: Corin.Langosch@swisscom.com<br>
Sent: Wednesday, October 20 2021, 10:00 am<br>
To: users@shibboleth.net<br>
Subject: SAML forceAuthn attribute XML encoding issue<br>
<br>
Hi guys,<br>
<br>
we are using shibboleth SP 3.1.0 and trying to get forced re-authentication to work.<br>
<br>
In our configuration we have forceAuthn set to "true" but it seems shibboleth is always sending it as "1" in the XML auth request. According to this old post from 2019 of the keycloak mailing list (<a href=""></a>https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Flists.jboss.org%2Fpipermail%2Fkeycloak-user%2F2019-August%2F019058.html&data=04%7C01%7CCorin.Langosch%40swisscom.com%7C847a6e33cda444e3208708d993b23d18%7C364e5b87c1c7420d9beec35d19b557a1%7C0%7C0%7C637703215997797862%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=EKx03uMa2YlCgYjRtLmS6v2Q3F%2F1Xh%2BhlUmwrm0%2BJZ0%3D&reserved=0
<<a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Flists.jboss.org%2Fpipermail%2Fkeycloak-user%2F2019-August%2F019058.html&data=04%7C01%7CCorin.Langosch%40swisscom.com%7C847a6e33cda444e3208708d993b23d18%7C364e5b87c1c7420d9beec35d19b557a1%7C0%7C0%7C637703215997797862%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=EKx03uMa2YlCgYjRtLmS6v2Q3F%2F1Xh%2BhlUmwrm0%2BJZ0%3D&reserved=0">https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Flists.jboss.org%2Fpipermail%2Fkeycloak-user%2F2019-August%2F019058.html&data=04%7C01%7CCorin.Langosch%40swisscom.com%7C847a6e33cda444e3208708d993b23d18%7C364e5b87c1c7420d9beec35d19b557a1%7C0%7C0%7C637703215997797862%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=EKx03uMa2YlCgYjRtLmS6v2Q3F%2F1Xh%2BhlUmwrm0%2BJZ0%3D&reserved=0</a>>)<br>
also "1" is compliant with the spec and should be accepted.<br>
<br>
However, the IDP we are integrating insists that only "true" or "false" are compliant and doesn't accept the answer given in the post mentioned above. "Whilst XML schemas may consider 1 as a valid boolean value, the SAML spec specifically states that the values<br>
should be true or false. <a href="https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fdocs.oasis-open.org%2Fsecurity%2Fsaml%2FPost2.0%2Fsstc-request-initiation-cd-01.html&data=04%7C01%7CCorin.Langosch%40swisscom.com%7C847a6e33cda444e3208708d993b23d18%7C364e5b87c1c7420d9beec35d19b557a1%7C0%7C0%7C637703215997797862%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=5lCc39GxII9f%2Fqa0iqaOApbFl6NDDvvJEUkQZxuJPBY%3D&reserved=0">https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fdocs.oasis-open.org%2Fsecurity%2Fsaml%2FPost2.0%2Fsstc-request-initiation-cd-01.html&data=04%7C01%7CCorin.Langosch%40swisscom.com%7C847a6e33cda444e3208708d993b23d18%7C364e5b87c1c7420d9beec35d19b557a1%7C0%7C0%7C637703215997797862%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=5lCc39GxII9f%2Fqa0iqaOApbFl6NDDvvJEUkQZxuJPBY%3D&reserved=0</a>
<<a href="https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fdocs.oasis-open.org%2Fsecurity%2Fsaml%2FPost2.0%2Fsstc-request-initiation-cd-01.html&data=04%7C01%7CCorin.Langosch%40swisscom.com%7C847a6e33cda444e3208708d993b23d18%7C364e5b87c1c7420d9beec35d19b557a1%7C0%7C0%7C637703215997797862%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=5lCc39GxII9f%2Fqa0iqaOApbFl6NDDvvJEUkQZxuJPBY%3D&reserved=0">https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fdocs.oasis-open.org%2Fsecurity%2Fsaml%2FPost2.0%2Fsstc-request-initiation-cd-01.html&data=04%7C01%7CCorin.Langosch%40swisscom.com%7C847a6e33cda444e3208708d993b23d18%7C364e5b87c1c7420d9beec35d19b557a1%7C0%7C0%7C637703215997797862%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=5lCc39GxII9f%2Fqa0iqaOApbFl6NDDvvJEUkQZxuJPBY%3D&reserved=0</a>>"<br>
<br>
Is our IDP right and thus this would need to be fixed in shibboleth? Or do they have to adjust their code? Thank you very much in advance.<br>
<br>
Kind regards<br>
<br>
Corin<br>
<br>
--<br>
<br>
For Consortium Member technical support, see <a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=04%7C01%7CCorin.Langosch%40swisscom.com%7C847a6e33cda444e3208708d993b23d18%7C364e5b87c1c7420d9beec35d19b557a1%7C0%7C0%7C637703215997797862%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=LG9f7uamGM3u6H6JWn85XLd%2Bk1YNpViNklPGBNRnQlQ%3D&reserved=0">
https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=04%7C01%7CCorin.Langosch%40swisscom.com%7C847a6e33cda444e3208708d993b23d18%7C364e5b87c1c7420d9beec35d19b557a1%7C0%7C0%7C637703215997797862%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=LG9f7uamGM3u6H6JWn85XLd%2Bk1YNpViNklPGBNRnQlQ%3D&reserved=0</a><br>
<br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=04%7C01%7CCorin.Langosch%40swisscom.com%7C847a6e33cda444e3208708d993b23d18%7C364e5b87c1c7420d9beec35d19b557a1%7C0%7C0%7C637703215997797862%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=LG9f7uamGM3u6H6JWn85XLd%2Bk1YNpViNklPGBNRnQlQ%3D&reserved=0">
https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=04%7C01%7CCorin.Langosch%40swisscom.com%7C847a6e33cda444e3208708d993b23d18%7C364e5b87c1c7420d9beec35d19b557a1%7C0%7C0%7C637703215997797862%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=LG9f7uamGM3u6H6JWn85XLd%2Bk1YNpViNklPGBNRnQlQ%3D&reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</div>
</body>
</html>