<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>Hello,</p>
    <p><br>
    </p>
    <p>some news about the hack I was facing (MITM allowing to
      impersonate because of signature not verified) <br>
    </p>
    <p><br>
    </p>
    <p>the  SP Vendor did corrected it's code, and now does check the
      signature of SAML reponse, they are using a library (
      <a class="moz-txt-link-freetext" href="https://www.componentspace.com/">https://www.componentspace.com/</a> for their DotNet code) .</p>
    <p>Now changing on the fly the NamedID brakes the signature and
      fails the login process :-) <br>
    </p>
    <p><br>
    </p>
    <p>howerver, I still have a question regarding the overrides for
      that SP in <i>relying-party.xml</i> of my IDP, now I had to force
      <i><font size="2">" <b>p:signAssertions="true" </b></font></i>[1]
      in order for the SSO flow to succeed<i><font size="2"><b> <br>
          </b></font></i></p>
    <p><i><font size="2"><b><br>
          </b></font></i></p>
    <p>Isn't it the default behavior for the IDP to SignAssertions ? <i><font
          size="2"><b><br>
          </b></font></i></p>
    <p><i><font size="2"><b><br>
          </b></font></i></p>
    <p><i><font size="2"><b>[1]<br>
          </b></font></i></p>
    <p><i><font size="2"><bean id="IMTOP9"
          parent="RelyingPartyByName"
          c:relyingPartyIds="#{{'<a class="moz-txt-link-freetext" href="https://vendorsp.int.Fr">https://vendorsp.int.Fr</a>'}}"><br>
                      <property name="profileConfigurations"><br>
                          <list><br>
                              <bean parent="SAML2.SSO" <b>p:signAssertions="true"</b>
          p:encryptAssertions="false" p:checkAddress="false"
p:nameIDFormatPrecedence="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
          p:postAuthenticationFlows="#{ {'attribute-release'} }" /><br>
                          </list><br>
                      </property><br>
                  </bean></font></i><br>
    </p>
    <p><br>
    </p>
    <p>Below [2] is the final response with the succeed login assertion,
      why is there 2 occurences of signatures !? I am wondering if
      forcing <i><font size="2"><b>p:signAssertions="true" </b></font></i>in
      relying-party overrides doesn't generate that 2nd signature and
      hence if I finally correctly corrected that signature initial
      failure (MITM) ? <i><font size="2"><b><br>
          </b></font></i></p>
    <p><i><font size="2"><b><br>
          </b></font></i></p>
    <p>Thanks .</p>
    <p><br>
    </p>
    <p>jehan<br>
    </p>
    <p><br>
    </p>
    <p><font size="1"><i><?xml version="1.0"
          encoding="UTF-8"?><saml2p:Response
          xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"
          Destination=<a class="moz-txt-link-rfc2396E" href="https://spvendor.int.fr/DN/Cor/Login.aspx?">"https://spvendor.int.fr/DN/Cor/Login.aspx?"</a>
          ID="_559afb4625da7388a1875db8d8abfcd5"
          InResponseTo="_41e01d0f-6da3-4c1e-8ad2-b506729f3c48"
          IssueInstant="2024-02-28T20:17:52.809Z"
          Version="2.0"><saml2:Issuer
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"><a class="moz-txt-link-freetext" href="https://idp4mt.int.fr/idp/shibboleth">https://idp4mt.int.fr/idp/shibboleth</a></saml2:Issuer><ds:Signature
xmlns:ds=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2000/09/xmldsig#">"http://www.w3.org/2000/09/xmldsig#"</a>><ds:SignedInfo><ds:CanonicalizationMethod
Algorithm=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2001/10/xml-exc-c14n#">"http://www.w3.org/2001/10/xml-exc-c14n#"</a>/><ds:SignatureMethod
Algorithm=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256">"http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"</a>/><ds:Reference
URI="#_559afb4625da7388a1875db8d8abfcd5"><ds:Transforms><ds:Transform
Algorithm=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2000/09/xmldsig#enveloped-signature">"http://www.w3.org/2000/09/xmldsig#enveloped-signature"</a>/><ds:Transform
Algorithm=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2001/10/xml-exc-c14n#">"http://www.w3.org/2001/10/xml-exc-c14n#"</a>/></ds:Transforms><ds:DigestMethod
Algorithm=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2001/04/xmlenc#sha256">"http://www.w3.org/2001/04/xmlenc#sha256"</a>/><ds:DigestValue>eqkNtL+bgLqmt5bzxnP8SWpF+/0pWyF05WWLoe9Lpsk=</ds:DigestValue></ds:Reference></ds:SignedInfo><b><ds:SignatureValue></b>UsW9wqtigxJCkPei65OCChDnn1m1g0fn1NC+3iR8YGSzkDL+gcEYovMrD1L3Lr3Sd9o8qjacnfrNpPrL5UbS0D0bvkP5Kmq3aaFxTO5wKrRZ4CcxHjOFn5AcYn+osKeZCAjcNKFmmFKABII4I3vVgSpaQ9cAQ+8whoK+3wf2e7gFyMHphtgS1DAcnplHBNbmBkSeKAuz7ikc8JR5Pmth1pUi9fEovmCs2Fz/SL6zwJRpjK4V/wgehM90/xT8S3+aS7TEz1HWd5LhyK7xhCvZH4eKvnxv4e3qDUPkOZhhUiLjEARtJ1edvhM3kNW2K5y/T1rbx4AkI8IDjs/zMPwe/l51et9P9aNSU3naH8NJcacztTJKoq2LblmivSiYjiIuSuXhR2S3Q9quYkEjMl+GhXzsR6gnqFCMGPinewb+DdgO21psJatcxQd0fbXAsBd+D7q2E0DJFQxJ7VvmOR8k/67YQguhiM/5/ldPULrvysxV4psCGfpmj6TMpdZ4xvFB<b></ds:SignatureValue><ds:KeyInfo><ds:X509Data><ds:X509Certificate></b>MIIENzCCAp+gAwIBAgIUFuvD0n2MY1kb97i5Fpj58CXbK4cwDQYJKoZIhvcNAQELBQAwHjEcMBoG<br>
A1UEAwwTaWRwNG10LmltdGJzLXRzcC5ldTAeFw0yMTA2MDIxODA2NTJaFw00MTA2MDIxODA2NTJa<br>
MB4xHDAaBgNVBAMME2lkcDRtdC5pbXRicy10c3AuZXUwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAw</i></font></p>
    <p><font size="1">.... removed lines ....<i><br>
        </i></font></p>
    <p><font size="1"><i>CDu47TK2tz6cz5nAl0zc2lXQAYp/Ozi6P60iB8tThCfWl5xKXKGxt76V+BmdeUMGIvWDivyave40<br>
nLu+SrEG56xu1QCaeivDj6YgUJon3Il7DnTFYriiHIDmwSCp8lK71NzJsxwoE7T2pgGySV5qhgTq<b></ds:X509Certificate></ds:X509Data></ds:KeyInfo></ds:Signature></b><saml2p:Status><saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:Success"/></saml2p:Status><saml2:Assertion
          xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
          ID="_ddb8bd5505c6f6aa452e7238e5c19ef8"
          IssueInstant="2024-02-28T20:17:52.809Z"
Version="2.0"><saml2:Issuer><a class="moz-txt-link-freetext" href="https://idp4mt.int.fr/idp/shibboleth">https://idp4mt.int.fr/idp/shibboleth</a></saml2:Issuer><ds:Signature
xmlns:ds=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2000/09/xmldsig#">"http://www.w3.org/2000/09/xmldsig#"</a>><ds:SignedInfo><ds:CanonicalizationMethod
Algorithm=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2001/10/xml-exc-c14n#">"http://www.w3.org/2001/10/xml-exc-c14n#"</a>/><ds:SignatureMethod
Algorithm=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256">"http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"</a>/><ds:Reference
URI="#_ddb8bd5505c6f6aa452e7238e5c19ef8"><ds:Transforms><ds:Transform
Algorithm=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2000/09/xmldsig#enveloped-signature">"http://www.w3.org/2000/09/xmldsig#enveloped-signature"</a>/><ds:Transform
Algorithm=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2001/10/xml-exc-c14n#">"http://www.w3.org/2001/10/xml-exc-c14n#"</a>/></ds:Transforms><ds:DigestMethod
Algorithm=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2001/04/xmlenc#sha256">"http://www.w3.org/2001/04/xmlenc#sha256"</a>/><ds:DigestValue>/2LlBZ/gtYHQwsNlbCANPC7OtLS4kwzsZYw+fmoG30Y=</ds:DigestValue></ds:Reference></ds:SignedInfo><b><ds:SignatureValue></b>aZXGpM0E6PPplFqu9w0yHjS3CILLKR+tEITyokiLoZjjOucbhblytIpBlEtU1TQLlthkbmIJ3vS9EM9hHWMwRBEKb6DpfCBvTs4ie2Br+/gnggk5wkZgcTxYNLrDgLVN58XW0pSsdnXXj0wDXESKAXxycsoU6RV8Tx9eX3+AvpPgyllD2mrmfCQGiepLrHEOLW9fnx07ulWZLf3CeVIiQtMXN0jg7UpPSljIizAQCblA6Vu1WoF6XQ1k73EPJpDGqTMKtTskA563WwWFYkXWd5kU1hcT4cpsBB9/xsAYd/U22rENIiUaUJkmMCIuUFlBsf+J3Ao60w5PyesKmr7m8D/HyE0FN6njKi3uLr9O1JvYw5iQB+6+1Mck4feJZiNmj/BJMRPcQrOaui3hPsi44XTBxnzzXhR1p07Trhjd1LQyuwaKNjj18SWnq5315/jZTrXbIBs0p0AxyVTtISits3v3LJSGLfNmjQAE/zwUzHvA1aE6ZhcaL9UUrMnXWYDW<b></ds:SignatureValue><ds:KeyInfo><ds:X509Data><ds:X509Certificate></b>MIIENzCCAp+gAwIBAgIUFuvD0n2MY1kb97i5Fpj58CXbK4cwDQYJKoZIhvcNAQELBQAwHjEcMBoG<br>
A1UEAwwTaWRwNG10LmltdGJzLXRzcC5ldTAeFw0yMTA2MDIxODA2NTJaFw00MTA2MDIxODA2NTJa<br>
MB4xHDAaBgNVBAMME2lkcDRtdC5pbXRicy10c3AuZXUwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAw</i></font></p>
    <p><font size="1">.... removed lines ....</font></p>
    <p><font size="1"><i>CDu47TK2tz6cz5nAl0zc2lXQAYp/Ozi6P60iB8tThCfWl5xKXKGxt76V+BmdeUMGIvWDivyave40<br>
nLu+SrEG56xu1QCaeivDj6YgUJon3Il7DnTFYriiHIDmwSCp8lK71NzJsxwoE7T2pgGySV5qhgTq<b></ds:X509Certificate></ds:X509Data></ds:KeyInfo></ds:Signature></b><saml2:Subject><saml2:NameID
          Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">proc</saml2:NameID><saml2:SubjectConfirmation
Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><saml2:SubjectConfirmationData
          Address="157.159.52.134"
          InResponseTo="_41e01d0f-6da3-4c1e-8ad2-b506729f3c48"
          NotOnOrAfter="2024-02-28T20:22:52.814Z"
Recipient=<a class="moz-txt-link-rfc2396E" href="https://spvendor.int.fr/DN/Cor/Login.aspx?">"https://spvendor.int.fr/DN/Cor/Login.aspx?"</a>/></saml2:SubjectConfirmation></saml2:Subject><saml2:Conditions
          NotBefore="2024-02-28T20:17:52.809Z"
NotOnOrAfter="2024-02-28T20:22:52.809Z"><saml2:AudienceRestriction><saml2:Audience><a class="moz-txt-link-freetext" href="https://spvendor.int.fr">https://spvendor.int.fr</a></saml2:Audience></saml2:AudienceRestriction></saml2:Conditions><saml2:AuthnStatement
          AuthnInstant="2024-02-28T20:17:52.801Z"
SessionIndex="_039112ee44587b2570bbabf55b4626fd"><saml2:SubjectLocality
Address="157.159.52.134"/><saml2:AuthnContext><saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef></saml2:AuthnContext></saml2:AuthnStatement><saml2:AttributeStatement><saml2:Attribute
          FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue><a class="moz-txt-link-abbreviated" href="mailto:je.proca@int.fr">je.proca@int.fr</a></saml2:AttributeValue></saml2:Attribute><saml2:Attribute
          FriendlyName="uid" Name="urn:oid:0.9.2342.19200300.100.1.1"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>proc</saml2:AttributeValue></saml2:Attribute><saml2:Attribute
          FriendlyName="givenName" Name="urn:oid:2.5.4.42"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Je</saml2:AttributeValue></saml2:Attribute><saml2:Attribute
          FriendlyName="eduPersonPrimaryAffiliation"
          Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.5"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>staff</saml2:AttributeValue></saml2:Attribute><saml2:Attribute
          FriendlyName="displayName"
          Name="urn:oid:2.16.840.1.113730.3.1.241"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Je
PROCA</saml2:AttributeValue></saml2:Attribute><saml2:Attribute
          FriendlyName="sn" Name="urn:oid:2.5.4.4"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>PROCA</saml2:AttributeValue></saml2:Attribute><saml2:Attribute
          FriendlyName="eduPersonPrincipalName"
          Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue><a class="moz-txt-link-abbreviated" href="mailto:proc@tets.eu">proc@tets.eu</a></saml2:AttributeValue></saml2:Attribute></saml2:AttributeStatement></saml2:Assertion></saml2p:Response></i></font><br>
      <br>
    </p>
    <p><br>
    </p>
    <p><br>
    </p>
    <div class="moz-cite-prefix">On 21/02/2024 21:34, Morgan, Andrew J
      via users wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:SJ0P222MB0122D912A6DE62EE4EBFEC5ED1572@SJ0P222MB0122.NAMP222.PROD.OUTLOOK.COM">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <style type="text/css" style="display:none;">P {margin-top:0;margin-bottom:0;}</style>
      <div class="elementToProof"
style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
        The vendor should use well-known SAML SP software.  Don't trust
        anyone to write their own SAML SP.  Unfortunately, I have no
        idea what SP software to recommend for them except the
        Shibboleth SP.</div>
      <div class="elementToProof"
style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
        <br>
      </div>
      <div class="elementToProof"
style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
        Andy<br>
      </div>
      <hr style="display:inline-block;width:98%" tabindex="-1">
      <div id="divRplyFwdMsg" dir="ltr"><font style="font-size:11pt"
          face="Calibri, sans-serif" color="#000000"><b>From:</b> users
          <a class="moz-txt-link-rfc2396E" href="mailto:users-bounces@shibboleth.net"><users-bounces@shibboleth.net></a> on behalf of
          <a class="moz-txt-link-abbreviated" href="mailto:jehan.procaccia@tem-tsp.eu">jehan.procaccia@tem-tsp.eu</a> <a class="moz-txt-link-rfc2396E" href="mailto:jehan.procaccia@tem-tsp.eu"><jehan.procaccia@tem-tsp.eu></a><br>
          <b>Sent:</b> Wednesday, February 21, 2024 12:07 PM<br>
          <b>To:</b> <a class="moz-txt-link-abbreviated" href="mailto:users@shibboleth.net">users@shibboleth.net</a> <a class="moz-txt-link-rfc2396E" href="mailto:users@shibboleth.net"><users@shibboleth.net></a><br>
          <b>Subject:</b> Re: sign and/or encrypt SAML assetions, hack
          MITM</font>
        <div> </div>
      </div>
      <div class="BodyFragment"><font size="2"><span
            style="font-size:11pt;">
            <div class="PlainText">[This email originated from outside
              of OSU. Use caution with links and attachments.]<br>
              <br>
              On 21/02/2024 16:57, Peter Schober via users wrote:<br>
              > Morgan, Andrew J via users
              <a class="moz-txt-link-rfc2396E" href="mailto:users@shibboleth.net"><users@shibboleth.net></a> [2024-02-21 16:20 CET]:<br>
              >> If you are able to modify the assertion without
              the SP rejecting it,<br>
              >> then that SP is not validating the signature. 
              Personally, I would<br>
              >> not use SAML with an SP that does not validate
              the signature.  As<br>
              >> you have found, anyone can modify the assertion
              to impersonate<br>
              >> another user - critical security bug.  Have you
              reported this issue<br>
              >> to the vendor's security contact?<br>
              Yes Morgan, we have reported the flow to the vendor, and
              are activelly<br>
              working on a correction . That's why I search for
              best-practice Doc  on<br>
              how to instruct them to do the right thinks, any pointer
              to that will be<br>
              greatly appreciated .<br>
              > Testing for this on a larger scale isn't trivial (and
              might include<br>
              > legal aspects) but an activity within GÉANT has
              recently started to<br>
              > look into this:<br>
              > <a
href="https://wiki.geant.org/display/GWP5/Scalable+testing+for+insecure+SAML+signature+validation"
                moz-do-not-send="true">
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.geant.org%2Fdisplay%2FGWP5%2FScalable%2Btesting%2Bfor%2Binsecure%2BSAML%2Bsignature%2Bvalidation&data=05%7C02%7Cmorgan%40oregonstate.edu%7C03cb1f9bcf8a4ae3eb8008dc3318b10a%7Cce6d05e13c5e4d6287a84c4a2713c113%7C0%7C0%7C638441428344213736%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=mKjesR%2By6vFQOt9Y3WxP6hyg%2B4Y8jPwRj%2BdHyWInpT4%3D&reserved=0</a><br>
              ><br>
              Thanks again Peter for that link, it describe my problem,
              even more , it<br>
              focuses on properly validate the signature.<br>
              <br>
              in my case it is worst, there is no signature check at
              all, I'll care<br>
              about the authenticity of the signature in the second step
              .<br>
              <br>
              regards , jehan .<br>
              <br>
              ><br>
              > -peter<br>
              --<br>
              For Consortium Member technical support, see <a
                href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw"
                moz-do-not-send="true">
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C02%7Cmorgan%40oregonstate.edu%7C03cb1f9bcf8a4ae3eb8008dc3318b10a%7Cce6d05e13c5e4d6287a84c4a2713c113%7C0%7C0%7C638441428344221440%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=55ew17NywXC2egkjJynEDz%2BMlj027NXNPeJwrzJgZc0%3D&reserved=0</a><br>
              To unsubscribe from this list send an email to
              <a class="moz-txt-link-abbreviated" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
            </div>
          </span></font></div>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
    </blockquote>
  </body>
</html>