<div dir="ltr"><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">Hello Simon,</div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">I don't have any experience with AWS Cognito metadata, but have some recommendations based on the article <a href="https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1429930512/AmazonCognito">https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1429930512/AmazonCognito</a>.</div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">SInce you are configuring AWS Cognito as an SP, you need to use "SPSSODescriptor", not "IDPSSODescriptor". Also, "WantAuthnRequestsSigned" is for IdPs, not SPs.</div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">Regarding the "assertion consumer endpoint": replace "md:SingleSignOnService" with "md:AssertionConsumerService".</div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">The article says that both the assertion consumer endpoint (service) and the endpoint for consuming logout responses use "post" bindings ("urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"). Try removing the HTTP-Redirect endpoint definitions.</div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">And now we have to get into the weeds a bit about encryption and NameIDs. The article says the service behavior "relies on signed responses and no encryption", and it also says that they require a NameID.</div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">There are different ways of turning off encryption. You can set "idp.encryption.optional = true" in idp.properties. If you want to do it on a per-service basis, the example relying-party.xml override in the article is one way to do it. I got the impression that you aren't very familiar with relying party overrides, though.</div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">I am a big fan of using metadata-driven configuration instead. Your IdP may already be set up to support metadata-driven configuration. If not, the tweaks are simple: see <a href="https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631679/MetadataDrivenConfiguration#General-Configuration">https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631679/MetadataDrivenConfiguration#General-Configuration</a>. Once configured, there are simple stanzas to add to disable encryption for the service: see <a href="https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631679/MetadataDrivenConfiguration#%5BinlineExtension%5DDisabling-Encryption">https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631679/MetadataDrivenConfiguration#%5BinlineExtension%5DDisabling-Encryption</a>. For the general approach of including these tags in metadata files, see <a href="https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631679/MetadataDrivenConfiguration#Applying-Tags">https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631679/MetadataDrivenConfiguration#Applying-Tags</a>.</div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">I think you need to use a different NameIDFormat other than "urn:oasis:names:tc:SAML:2.0:nameid-format:unspecified". The article intentionally doesn't give much guidance as to which format to use, assuming you know about NameIDFormats and can choose which one is best for your circumstance. If you aren't familiar with NameIDFormats, I interpret the article as saying you _can_ use "urn:oasis:names:tc:SAML:2.0:nameid-format:persistent", with caveats, but you _can't_ use "urn:oasis:names:tc:SAML:2.0:nameid-format:transient". My personal experience is that when I mess up and make a mismatch between NameIDFormat and nameIDFormatPrecedence, no NameID will be sent. That could definitely end up with some odd Cognito error message during login.</div><div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">Good luck! -Les</div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><br></div><div><table style="color:rgb(136,136,136);border:none;border-collapse:collapse"><tbody><tr style="height:0pt;border-top:1pt solid rgb(204,204,204)"><td style="border-right:1pt solid rgb(204,204,204);vertical-align:middle;padding:5pt;overflow:hidden"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:0pt"><a href="http://www.carleton.edu/" target="_blank"><span style="font-size:11pt;font-family:Arial;color:rgb(17,85,204);vertical-align:baseline;white-space:pre-wrap"><span style="border:none;display:inline-block;overflow:hidden;width:70px;height:73px"><img height="73" src="https://lh6.googleusercontent.com/QEL1To3Ci_dJA1huaKzfZ0Lf4MaZlAy_f-W3vQjbyzNq_yXq_ZYGv3tuT4dkaZS_bZ5X6fZR4iKzBboZhxbCF5htZFnLNKGqmrzHsVJtsjsy0pfK5w2z0Dlq-EtZcWhv0PxBpWmR" width="70" style="margin-left:0px;margin-top:0px"></span></span></a></p></td><td style="border-left:1pt solid rgb(204,204,204);vertical-align:top;padding:10.8pt;overflow:hidden"><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><font color="#dea410" face="Arial"><span style="font-size:14.6667px;white-space:pre-wrap"><b>Les LaCroix '79</b></span></font></p><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="color:rgb(11,80,145)"><span style="font-size:11pt;font-family:Arial;vertical-align:baseline;white-space:pre-wrap">Strategic Technologist</span></span></p><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="color:rgb(11,80,145)"><span style="font-size:11pt;font-family:Arial;vertical-align:baseline;white-space:pre-wrap">Information Technology Services</span></span></p><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="color:rgb(11,80,145)"><span style="font-size:11pt;font-family:Arial;vertical-align:baseline;white-space:pre-wrap">t: (507) 222-5455</span></span></p></td></tr></tbody></table></div></div></div></div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Apr 13, 2023 at 2:44 PM Simon Cunningham <<a href="mailto:simon@nu-solutions.com">simon@nu-solutions.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div class="msg-7331227385846303225">
<div dir="ltr">
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0);background-color:rgb(255,255,255)">
<span style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;background-color:rgb(255,255,255)">We are trying to configure Shibboleth as an SP with AWS Cognito. The goal is to support customers who would like
to authorize internal users as well as external users to access a web-based application that has limited SSO support (but does support Shibboleth). Most of the time the external entities will originate in an Azure AD tenant, but we would like to be able to
support other IdPs in the future.</span><br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0);background-color:rgb(255,255,255)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0);background-color:rgb(255,255,255)">
The only documentation I have found thus far is this page that Scott put together: <a href="https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1429930512/AmazonCognito" target="_blank">https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1429930512/AmazonCognito</a>.
Using that page as a guide I have been working on constructing the correct metadata. I was wondering if anyone might be able to suggest what I am doing wrong. Ultimately, I would like to help provide more details that could be used to update the above document
for anyone else who might want to employ the same setup.<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0);background-color:rgb(255,255,255)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0);background-color:rgb(255,255,255)">
<span style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;background-color:rgb(255,255,255)"><br>
</span></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0);background-color:rgb(255,255,255)">
<span style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;background-color:rgb(255,255,255)">Using the AmazonCognito page linked above as a guide for constructing the metadata file for the SP...</span><br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0);background-color:rgb(255,255,255)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0);background-color:rgb(255,255,255)">
------------</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0);background-color:rgb(255,255,255)">
<i><br>
</i></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0);background-color:rgb(255,255,255)">
<i>"For some SAML identity providers, you also need to provide the SP Audience URI / SP Entity ID, in the form:</i></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0);background-color:rgb(255,255,255)">
<div><span style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;background-color:rgb(255,255,255)"><i>urn:amazon:cognito:sp:<yourUserPoolID>"</i></span></div>
<div><br>
</div>
<div><span style="background-color:rgb(255,255,255)">In the metadata xml, I have set the entitiyID accordingly (whether this is necessary or not, I don't know):</span><br>
</div>
<div><md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="urn:amazon:cognito:sp:us-west-2_lfCRX6MMo"><br>
<br>
</div>
<div><span style="font-size:12pt;margin:0px;color:rgb(0,0,0);background-color:rgb(255,255,255)">------------</span><br>
<br>
</div>
<div><i>"You also need to provide an assertion consumer endpoint to your SAML identity provider. Configure this endpoint for SAML 2.0 POST binding in your SAML identity provider:</i></div>
<div>
<div><i style="font-family:inherit;font-size:inherit;font-variant-ligatures:inherit;font-variant-caps:inherit;font-weight:inherit;background-color:rgb(255,255,255)">https://<yourDomainPrefix>.auth.<region>.<a href="http://amazoncognito.com/saml2/idpresponse" target="_blank">amazoncognito.com/saml2/idpresponse</a>"</i><br>
</div>
</div>
<div><br>
</div>
<div><span style="background-color:rgb(255,255,255)">Anytime there is a talk about the Assertion Consumer Endpoint/URL I get confused as to exactly what this is referring to. I guessed
</span><span style="background-color:rgb(255,255,255);display:inline">(probably incorrectly) </span><span style="background-color:rgb(255,255,255)">that this is the URL for the SingleSignOnService</span><span style="background-color:rgb(255,255,255)">:</span><br>
</div>
<div><br>
</div>
<div><md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://nusol-p6.auth.us-west-2.amazoncognito.com/saml2/idpresponse" target="_blank">https://nusol-p6.auth.us-west-2.amazoncognito.com/saml2/idpresponse</a>"/></div>
<div><md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="<a href="https://nusol-p6.auth.us-west-2.amazoncognito.com/saml2/idpresponse" target="_blank">https://nusol-p6.auth.us-west-2.amazoncognito.com/saml2/idpresponse</a>"/><br>
<br>
</div>
<div><span style="font-size:12pt;margin:0px;color:rgb(0,0,0);background-color:rgb(255,255,255)">------------</span><br>
<br>
</div>
<div><i>"Configure this endpoint for consuming logout responses from your IdP. This endpoint uses post binding.<br>
https://<yourDomainPrefix>.auth.<region>.<a href="http://amazoncognito.com/saml2/logout" target="_blank">amazoncognito.com/saml2/logout</a>"<br>
</i><br>
</div>
<div>This seemed straight-forward enough:</div>
<div><br>
</div>
<div>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://nusol-p6.auth.us-west-2.amazoncognito.com/saml2/logout" target="_blank">https://nusol-p6.auth.us-west-2.amazoncognito.com/saml2/logout</a>"/>
<div><md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="<a href="https://nusol-p6.auth.us-west-2.amazoncognito.com/saml2/logout" target="_blank">https://nusol-p6.auth.us-west-2.amazoncognito.com/saml2/logout</a>"/></div>
<br>
</div>
<div>
<span style="font-size:12pt;margin:0px;color:rgb(0,0,0);background-color:rgb(255,255,255)">------------</span><br>
<br>
</div>
<div>
Not sure of RelyingPartyConfiguration is needed.</div>
<div>
<br>
</div>
<div>
<br>
</div>
<div>
This is the current metadata XML:</div>
<div>
<br>
<div><?xml version="1.0" encoding="UTF-8"?></div>
<div><md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="urn:amazon:cognito:sp:us-west-2_lfCRX6MMo"></div>
<div> <md:IDPSSODescriptor WantAuthnRequestsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"></div>
<div> <md:KeyDescriptor use="signing"></div>
<div> <ds:KeyInfo xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#" target="_blank">http://www.w3.org/2000/09/xmldsig#</a>"></div>
<div> <ds:X509Data></div>
<div><span style="background-color:rgb(255,255,255)"><span> </span><span> </span><ds:X509Certificate>...<span style="color:rgb(0,0,0);background-color:rgb(255,255,255);display:inline"></ds:X509Certificate></span></span></div>
<div> </ds:X509Data></div>
<div> </ds:KeyInfo></div>
<div> </md:KeyDescriptor></div>
<div> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://nusol-p6.auth.us-west-2.amazoncognito.com/saml2/logout" target="_blank">https://nusol-p6.auth.us-west-2.amazoncognito.com/saml2/logout</a>"/></div>
<div> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="<a href="https://nusol-p6.auth.us-west-2.amazoncognito.com/saml2/logout" target="_blank">https://nusol-p6.auth.us-west-2.amazoncognito.com/saml2/logout</a>"/></div>
<div> <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</md:NameIDFormat></div>
<div> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://nusol-p6.auth.us-west-2.amazoncognito.com/saml2/idpresponse" target="_blank">https://nusol-p6.auth.us-west-2.amazoncognito.com/saml2/idpresponse</a>"/></div>
<div> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="<a href="https://nusol-p6.auth.us-west-2.amazoncognito.com/saml2/idpresponse" target="_blank">https://nusol-p6.auth.us-west-2.amazoncognito.com/saml2/idpresponse</a>"/></div>
<div> </md:IDPSSODescriptor></div>
<div></md:EntityDescriptor></div>
<div>
<br>
</div>
</div>
<div>
Testing access to the application redirects to the SingleSignOnService Location URL and generates a useless error which I would dig into if I could find any logs on the AWS side. I strongly suspect my metadata is wrong. I have searched around in re:Post for
some help on the AWS side, but there are very few results related to Shibboleth (4 results total).</div>
<div>
<br>
</div>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0);background-color:rgb(255,255,255)">
<span style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;background-color:rgb(255,255,255)">As an aside,
<span style="color:rgb(0,0,0);background-color:rgb(255,255,255);display:inline">
we are using Rocky Linux 9. </span>I had been making decent headway with configuring a Shibboleth SP against AWS IAM Identity Center, but AWS support recommended we use Cognito given the use case outlined above (IAM IC can only federate with a single external
IdP).</span><br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0);background-color:rgb(255,255,255)">
<br>
</div>
<div>
<div id="m_-7331227385846303225Signature">
<div>
<div></div>
<div></div>
<div></div>
<div id="m_-7331227385846303225divtagdefaultwrapper" style="font-size:12pt;font-family:Calibri,Arial,Helvetica,sans-serif;color:rgb(0,0,0);background-color:rgb(255,255,255)">
<div name="divtagdefaultwrapper">
<p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:15px;font-family:Calibri,sans-serif;color:rgb(33,33,33);background-color:rgb(255,255,255)">
<b><span style="font-size:12pt;color:rgb(31,73,125)">Regards,</span></b></p>
<p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:15px;font-family:Calibri,sans-serif;color:rgb(33,33,33);background-color:rgb(255,255,255)">
<b><span style="font-size:12pt;color:rgb(31,73,125)"><br>
</span></b></p>
<p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:15px;font-family:Calibri,sans-serif;color:rgb(33,33,33);background-color:rgb(255,255,255)">
<b><span style="font-size:12pt;color:rgb(31,73,125)"></span></b></p>
<p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:15px;font-family:Calibri,sans-serif;color:rgb(33,33,33);background-color:rgb(255,255,255)">
<b><span style="font-size:12pt;color:rgb(31,73,125)">Simon Cunningham</span></b></p>
<p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:15px;font-family:Calibri,sans-serif;color:rgb(33,33,33);background-color:rgb(255,255,255)">
<b><span style="font-size:12pt;color:rgb(31,73,125)">Software Engineer - Nu Solutions Consulting</span></b></p>
<p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:15px;font-family:Calibri,sans-serif;color:rgb(33,33,33);background-color:rgb(255,255,255)">
<span style="color:rgb(31,73,125)">Mobile: </span><span id="m_-7331227385846303225gc-number-83" title="Call with Google Voice" style="text-decoration:underline;color:rgb(0,51,187)">+1.907.529.0775</span><br>
</p>
<p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:15px;font-family:Calibri,sans-serif;color:rgb(33,33,33);background-color:rgb(255,255,255)">
<span title="Call with Google Voice" style="text-decoration:underline;color:rgb(0,51,187)">Office: + 1.907.290.2848</span></p>
<p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:15px;font-family:Calibri,sans-serif;color:rgb(33,33,33);background-color:rgb(255,255,255)">
<span title="Call with Google Voice" style="text-decoration:underline;color:rgb(0,51,187)"><br>
</span></p>
<p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:15px;font-family:Calibri,sans-serif;color:rgb(33,33,33);background-color:rgb(255,255,255)">
<span title="Call with Google Voice" style="text-decoration:underline;color:rgb(0,51,187)"><img style="max-width: 100%;" src="cid:18789ed80cb6a1cf3b51"><br>
</span></p>
<p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:15px;font-family:Calibri,sans-serif;color:rgb(33,33,33);background-color:rgb(255,255,255)">
<span title="Call with Google Voice" style="text-decoration:underline;color:rgb(0,51,187)"></span></p>
<div class="MsoNormal" style="margin:0px 0in 0.000133333px;font-size:15px;font-family:Calibri,sans-serif;color:rgb(33,33,33);background-color:rgb(255,255,255)">
<span title="Call with Google Voice" style="text-decoration:underline;color:rgb(0,51,187)"><br>
</span></div>
</div>
</div>
</div>
</div>
</div>
</div>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</div></blockquote></div>