<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<p>Hi <br>
</p>
<p><br>
</p>
<p>finally this thread conviced the SP vendor to honor not only
assertion signature, but also Responses signatures . <br>
</p>
<p>As I understood from this thread, it is better to Sign responses,
so, what should I do ?: <br>
</p>
<p>1) set in that SP metadata a "<i>Want<b>Response</b>Signed="true"</i>
? (if this directive exist ? , didn't found that on shibboleth
Doc, only <i>Want<b>Assertions</b>Signed)</i></p>
<p>2) as the IDP signs by default responses, maybe the best solution
is to set nothing regarding signature in SP medatada ? <br>
</p>
3) as I still have to override for that SP in<i> relying-party.xml</i>
the fact that it doesn't encrypt Assertion => <i>p:encryptAssertions="false"</i>
, should I set there <code class="code cc-1o5d2cw"
data-renderer-mark="true">signResponses="true" , <font size="4">or
again it it not necessary as the IDP does this (signResponses)
by default ? <br>
</font></code>
<p><br>
</p>
<p>Thanks . <br>
</p>
<p><br>
</p>
<p>jehan<br>
</p>
<p><br>
</p>
<div class="moz-cite-prefix">On 29/02/2024 00:16, Morgan, Andrew J
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:SJ0P222MB0122D282D4DD6A297C3CA85CD1582@SJ0P222MB0122.NAMP222.PROD.OUTLOOK.COM">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<style type="text/css" style="display:none;">P {margin-top:0;margin-bottom:0;}</style>
<div class="elementToProof"
style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Hi Jehan,</div>
<div class="elementToProof"
style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof"
style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
The default for the Shibboleth IDP is to sign the Response, not
the Assertion.</div>
<div class="elementToProof"
style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof"><span
style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">It
looks like both the SAML Response and the SAML Assertion are
being signed. This is okay, but it is not necessary to sign
both. Since you are modifying the SP config using
relying-party.xml anyway, you could set signResponses=false to
eliminate the double signing.</span></div>
<div class="elementToProof"><span
style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"><br>
</span></div>
<div class="elementToProof"><span
style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">If
the SP wants the assertion signed, they should include that
flag in their metadata (see the bottom of
<a
href="https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/3169288205/ProfileConfiguration-SAMLAssertion"
id="OWAdf3b2a2a-2e2d-a9f7-2df1-307b80021e88"
class="OWAAutoLink moz-txt-link-freetext"
moz-do-not-send="true">
https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/3169288205/ProfileConfiguration-SAMLAssertion</a>).</span></div>
<div class="elementToProof"><span
style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"><br>
</span></div>
<div class="elementToProof"><span
style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">Andy<br>
</span></div>
<div class="elementToProof"><span
style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"><br>
</span></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font style="font-size:11pt"
face="Calibri, sans-serif" color="#000000"><b>From:</b> jehan
Procaccia tem <a class="moz-txt-link-rfc2396E" href="mailto:jehan.procaccia@tem-tsp.eu"><jehan.procaccia@tem-tsp.eu></a><br>
<b>Sent:</b> Wednesday, February 28, 2024 12:58 PM<br>
<b>To:</b> Shib Users <a class="moz-txt-link-rfc2396E" href="mailto:users@shibboleth.net"><users@shibboleth.net></a><br>
<b>Cc:</b> Morgan, Andrew J <a class="moz-txt-link-rfc2396E" href="mailto:morgan@oregonstate.edu"><morgan@oregonstate.edu></a><br>
<b>Subject:</b> Re: sign and/or encrypt SAML assetions, hack
MITM</font>
<div> </div>
</div>
<div>
<p><span style="color:#D73F09">[This email originated from
outside of OSU. Use caution with links and attachments.]</span></p>
<div>
<p>Hello,</p>
<p><br>
</p>
<p>some news about the hack I was facing (MITM allowing to
impersonate because of signature not verified)
<br>
</p>
<p><br>
</p>
<p>the SP Vendor did corrected it's code, and now does check
the signature of SAML reponse, they are using a library (
<a class="x_moz-txt-link-freetext moz-txt-link-freetext"
href="https://www.componentspace.com/"
originalsrc="https://www.componentspace.com/"
shash="LdGBIVSrGHSKpRXFLJOu/ofPZMipDRUDBd1nfRIorGHxtx8Wr54cWcnMPrPZI0yIt0GqXh0UXV2vZEJmFXyzwZHz6o7/HKSuU5HjAohqSnkc80I97GmcUfhhwYxQJb+86wXtSGaiqFLcnAcL0sw/FOy9uM7CvSgemlW3TLlMeDA="
moz-do-not-send="true">
https://www.componentspace.com/</a> for their DotNet code)
.</p>
<p>Now changing on the fly the NamedID brakes the signature
and fails the login process :-)
<br>
</p>
<p><br>
</p>
<p>howerver, I still have a question regarding the overrides
for that SP in <i>relying-party.xml</i> of my IDP, now I
had to force
<i><font size="2">" <b>p:signAssertions="true" </b></font></i>[1]
in order for the SSO flow to succeed<i><font size="2"><b>
<br>
</b></font></i></p>
<p><i><font size="2"><b><br>
</b></font></i></p>
<p>Isn't it the default behavior for the IDP to SignAssertions
? <i><font size="2"><b><br>
</b></font></i></p>
<p><i><font size="2"><b><br>
</b></font></i></p>
<p><i><font size="2"><b>[1]<br>
</b></font></i></p>
<p><i><font size="2"><bean id="IMTOP9"
parent="RelyingPartyByName" c:relyingPartyIds="#{{'<a
class="x_moz-txt-link-freetext"
href="https://vendorsp.int.fr/"
originalsrc="https://vendorsp.int.fr/"
shash="VxM0AtVwbrPa7jYZ/E6F9Ucr6wJJRRvvGlCKofix4S/xMuZyDqXiH4Juum1/ucVkaovvgFS3CTXSVnm+gJeWw5s3Dv1XT3bdrivoWWimBXxlFrbW4GET4fyeqH0Pv9fORDXWIls95BnO+Nn8qmi2/p/R9wvsHDo5BVomP1Nr83A="
moz-do-not-send="true">https://vendorsp.int.Fr</a>'}}"><br>
<property
name="profileConfigurations"><br>
<list><br>
<bean parent="SAML2.SSO" <b>p:signAssertions="true"</b>
p:encryptAssertions="false" p:checkAddress="false"
p:nameIDFormatPrecedence="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
p:postAuthenticationFlows="#{ {'attribute-release'} }"
/><br>
</list><br>
</property><br>
</bean></font></i><br>
</p>
<p><br>
</p>
<p>Below [2] is the final response with the succeed login
assertion, why is there 2 occurences of signatures !? I am
wondering if forcing
<i><font size="2"><b>p:signAssertions="true" </b></font></i>in
relying-party overrides doesn't generate that 2nd signature
and hence if I finally correctly corrected that signature
initial failure (MITM) ?
<i><font size="2"><b><br>
</b></font></i></p>
<p><i><font size="2"><b><br>
</b></font></i></p>
<p>Thanks .</p>
<p><br>
</p>
<p>jehan<br>
</p>
<p><br>
</p>
<p><font size="1"><i><?xml version="1.0"
encoding="UTF-8"?><saml2p:Response
xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"
Destination=<a class="x_moz-txt-link-rfc2396E"
href="https://spvendor.int.fr/DN/Cor/Login.aspx?"
originalsrc="https://spvendor.int.fr/DN/Cor/Login.aspx?"
shash="gABoRBbvzXzbZ3J8GeeA26yBS6J5e6rSaggilVSOy/u6mSSeFp0/SUAnsQ+qQ+mcEwP46wJVg+wgHJAVPU4mk9mcL85sz71CWfhd+oz7XIylmWDtuE7sBcW1EOH4O0+m9kzHv72NiYUvdUB4Xqaml0LrecGQ62ryOwEUXvXfJoE="
moz-do-not-send="true">"https://spvendor.int.fr/DN/Cor/Login.aspx?"</a>
ID="_559afb4625da7388a1875db8d8abfcd5"
InResponseTo="_41e01d0f-6da3-4c1e-8ad2-b506729f3c48"
IssueInstant="2024-02-28T20:17:52.809Z"
Version="2.0"><saml2:Issuer
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"><a
class="x_moz-txt-link-freetext moz-txt-link-freetext"
href="https://idp4mt.int.fr/idp/shibboleth"
originalsrc="https://idp4mt.int.fr/idp/shibboleth"
shash="YVT+0fndRz6gxp8/o7AI4vmwQuDvFVVZ7al7LdzwqtdJ94xF3GYHs3ytKtU0u9UVin2aoMpyw9UTs6yHTt/8NQ0TOG+ZtBBF/X/XYi/Xh6du7dgDCWy6bxtvwcOy3BQwCE9vW6kKRvAJY5eGhGQxADCsM3R5YaJS6QUrd3lKR8M="
moz-do-not-send="true">https://idp4mt.int.fr/idp/shibboleth</a></saml2:Issuer><ds:Signature
xmlns:ds=<a class="x_moz-txt-link-rfc2396E"
href="http://www.w3.org/2000/09/xmldsig#"
originalsrc="http://www.w3.org/2000/09/xmldsig#"
shash="wi+E+R4Hid3aXOMNRDXGJVyxydVf/hIHoYPNHsKWNmF/2s+WfD9S9KE6BBJ0XIAq1nPBjX6ADMeTzcPuN3bwG78OxGjjkcQdYcMdI0kgPoI/t4tiEN+HGnbAPOGmSEjwAswC0KJv+sRsB8L+kWVHnaPpnTcL5dQZHEe/p+LL3is="
moz-do-not-send="true">"http://www.w3.org/2000/09/xmldsig#"</a>><ds:SignedInfo><ds:CanonicalizationMethod
Algorithm=<a class="x_moz-txt-link-rfc2396E"
href="http://www.w3.org/2001/10/xml-exc-c14n#"
originalsrc="http://www.w3.org/2001/10/xml-exc-c14n#"
shash="BgHywC5AAL88NvLlaSidkgCskd+DvNkd0vnWXQ2DrcKUXRLkummPbcunjxVFaoxuPLg5MTNbiQD8kvNhJsuyq7Q3AHytFAk9H9Dqz9n4KTx7RTQ1MC/IKQL0ngnfFLfC7ZjBy/c1xtS8cTImfc6X4HCCUlEmjFHeTl2BuHxVjQk="
moz-do-not-send="true">"http://www.w3.org/2001/10/xml-exc-c14n#"</a>/><ds:SignatureMethod
Algorithm=<a class="x_moz-txt-link-rfc2396E"
href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"
originalsrc="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"
shash="G+mARjC2D3HGcH4Ut2XsaeljXJpPvRc02DiPzTHCgpcrrxsjz5/BT6w6+hrtD5Ilxz9sWKQJoCPhY+iGGOW/WMJdVqUqcfXDJL7AMZtqmDVozl54YsKGxfHFVHNiGiYtD7UMo3Y0Z9MLYV7RTIeXdTjaJLf1abCyptkiaRXWUnw="
moz-do-not-send="true">"http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"</a>/><ds:Reference
URI="#_559afb4625da7388a1875db8d8abfcd5"><ds:Transforms><ds:Transform
Algorithm=<a class="x_moz-txt-link-rfc2396E"
href="http://www.w3.org/2000/09/xmldsig#enveloped-signature"
originalsrc="http://www.w3.org/2000/09/xmldsig#enveloped-signature"
shash="ezhbELD59VunAs7Co4CweMOhxy5guTvyvYWQXXlabcD5pmHawI70c7FueerrMMDha3CmE8sJ4DkEYiZQ0/LlPyb+lVO7ZpD4027FOgQVamV0GThoip0cgIe8fIwg381rtZs5pisxBjuYpRiV4wPI89F5z3o3C4mXmUEtpCl7gmo="
moz-do-not-send="true">"http://www.w3.org/2000/09/xmldsig#enveloped-signature"</a>/><ds:Transform
Algorithm=<a class="x_moz-txt-link-rfc2396E"
href="http://www.w3.org/2001/10/xml-exc-c14n#"
originalsrc="http://www.w3.org/2001/10/xml-exc-c14n#"
shash="OQe16qpDwvYpolFzBork40xZpE4XICQwNka52YbTGZJy7jo9Y23kBcM4+VewkhduM82NJeUlVURHX30bTysF/yzaE/H/tuBgkyQEHsRbR3/8Ag+HRQs3O3I/on2ADuAsPGuLi4bjLU//x+fJd4WDmAA5QWW/HL2xolyHjMB98zg="
moz-do-not-send="true">"http://www.w3.org/2001/10/xml-exc-c14n#"</a>/></ds:Transforms><ds:DigestMethod
Algorithm=<a class="x_moz-txt-link-rfc2396E"
href="http://www.w3.org/2001/04/xmlenc#sha256"
originalsrc="http://www.w3.org/2001/04/xmlenc#sha256"
shash="hdKpPaq3l5Vm7U6LOO1h/ZjcMJfR+YkXklaBlHqHL8npgiG5vdK8awgqb7ufzQkQk6oxNKDLcFH6iOlZvPi248ejtcARFf2trXXQGkJOPhSo4AoYm1dfeIKkxvqV7SVeZ1yaYItAR6FAh20Y6pi+Elg0NSzxff6r9lFVP1XkVEM="
moz-do-not-send="true">"http://www.w3.org/2001/04/xmlenc#sha256"</a>/><ds:DigestValue>eqkNtL+bgLqmt5bzxnP8SWpF+/0pWyF05WWLoe9Lpsk=</ds:DigestValue></ds:Reference></ds:SignedInfo><b><ds:SignatureValue></b>UsW9wqtigxJCkPei65OCChDnn1m1g0fn1NC+3iR8YGSzkDL+gcEYovMrD1L3Lr3Sd9o8qjacnfrNpPrL5UbS0D0bvkP5Kmq3aaFxTO5wKrRZ4CcxHjOFn5AcYn+osKeZCAjcNKFmmFKABII4I3vVgSpaQ9cAQ+8whoK+3wf2e7gFyMHphtgS1DAcnplHBNbmBkSeKAuz7ikc8JR5Pmth1pUi9fEovmCs2Fz/SL6zwJRpjK4V/wgehM90/xT8S3+aS7TEz1HWd5LhyK7xhCvZH4eKvnxv4e3qDUPkOZhhUiLjEARtJ1edvhM3kNW2K5y/T1rbx4AkI8IDjs/zMPwe/l51et9P9aNSU3naH8NJcacztTJKoq2LblmivSiYjiIuSuXhR2S3Q9quYkEjMl+GhXzsR6gnqFCMGPinewb+DdgO21psJatcxQd0fbXAsBd+D7q2E0DJFQxJ7VvmOR8k/67YQguhiM/5/ldPULrvysxV4psCGfpmj6TMpdZ4xvFB<b></ds:SignatureValue><ds:KeyInfo><ds:X509Data><ds:X509Certificate></b>MIIENzCCAp+gAwIBAgIUFuvD0n2MY1kb97i5Fpj58CXbK4cwDQYJKoZIhvcNAQELBQAwHjEcMBoG<br>
A1UEAwwTaWRwNG10LmltdGJzLXRzcC5ldTAeFw0yMTA2MDIxODA2NTJaFw00MTA2MDIxODA2NTJa<br>
MB4xHDAaBgNVBAMME2lkcDRtdC5pbXRicy10c3AuZXUwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAw</i></font></p>
<p><font size="1">.... removed lines ....<i><br>
</i></font></p>
<p><font size="1"><i>CDu47TK2tz6cz5nAl0zc2lXQAYp/Ozi6P60iB8tThCfWl5xKXKGxt76V+BmdeUMGIvWDivyave40<br>
nLu+SrEG56xu1QCaeivDj6YgUJon3Il7DnTFYriiHIDmwSCp8lK71NzJsxwoE7T2pgGySV5qhgTq<b></ds:X509Certificate></ds:X509Data></ds:KeyInfo></ds:Signature></b><saml2p:Status><saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:Success"/></saml2p:Status><saml2:Assertion
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
ID="_ddb8bd5505c6f6aa452e7238e5c19ef8"
IssueInstant="2024-02-28T20:17:52.809Z"
Version="2.0"><saml2:Issuer><a
class="x_moz-txt-link-freetext moz-txt-link-freetext"
href="https://idp4mt.int.fr/idp/shibboleth"
originalsrc="https://idp4mt.int.fr/idp/shibboleth"
shash="T/hY5J4sXaUD7XjvaBZXHwVRnotqTRhAdi4gIqexAeiYvCNaJ2nuw7WXBhihZYIWE7FA7DS/1wnQg4NoOslW+zE2t1dQe9v7AtNAiwKNTwG6WNy+fMOvi9FbtgRJTdzok35ssdGLRLqjSYNTkEQzCQ5GfaFNAnVaePIcEha+BFA="
moz-do-not-send="true">https://idp4mt.int.fr/idp/shibboleth</a></saml2:Issuer><ds:Signature
xmlns:ds=<a class="x_moz-txt-link-rfc2396E"
href="http://www.w3.org/2000/09/xmldsig#"
originalsrc="http://www.w3.org/2000/09/xmldsig#"
shash="n9kj75Zbvms9FklsxuLCJTGng03yAG53TwkE7hFYS77HeJ1q0MQFgMN+Qkn6DULusmycX9JSl1GMfga+gtO8oFw5G9RR3AzExzmefcOBPyAw+fnDxOAbSwlno5HbN/jZ+EKiqjc3SsNO6qIrRjY6fNAh9kaxIHfa/dBBtMUOHmE="
moz-do-not-send="true">"http://www.w3.org/2000/09/xmldsig#"</a>><ds:SignedInfo><ds:CanonicalizationMethod
Algorithm=<a class="x_moz-txt-link-rfc2396E"
href="http://www.w3.org/2001/10/xml-exc-c14n#"
originalsrc="http://www.w3.org/2001/10/xml-exc-c14n#"
shash="wAOmjJV0uNjahp/ZxiYROYv+/6anDRsNl7goZDjUZz+fvTqnjIqUDFT+qXFHk7AHPd2F0r0CJwcB1H+8FXU0mB5Pp6fAcf+LOzjz/521so1xzmE7qUhzK+4/PHEaAZnfWKwY5XXwLKfJcdbgyQ7CyLeVXgLCfH/ZlumFrCgu8MA="
moz-do-not-send="true">"http://www.w3.org/2001/10/xml-exc-c14n#"</a>/><ds:SignatureMethod
Algorithm=<a class="x_moz-txt-link-rfc2396E"
href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"
originalsrc="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"
shash="PFDPi/6FLwHugMvgIUutXmmqlwPavgffeTe9psuANzHR4yKA8sJQPf5qvSGBg0ZvgbIfd1tkJAKSRXZlNKohkbpcnnVcWL6+cu4nfYZMCKvBvRv2qC79art6OSJOH+enbAWv02/pChsSR4CzC3ajBJulBQ8xFjcxTA6xpPFEZbE="
moz-do-not-send="true">"http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"</a>/><ds:Reference
URI="#_ddb8bd5505c6f6aa452e7238e5c19ef8"><ds:Transforms><ds:Transform
Algorithm=<a class="x_moz-txt-link-rfc2396E"
href="http://www.w3.org/2000/09/xmldsig#enveloped-signature"
originalsrc="http://www.w3.org/2000/09/xmldsig#enveloped-signature"
shash="CkovheHRd2I+9pW0bzD3FFEatrg1AoN8DvA5w8LjfVf2ZUQfAierWU3/tqoj/8H434e5uozxJRZ0Uw2aVbcTDYr9DOc68wJlNL4Occ/6/kfrO6crTNZJmHTH2iKLx5IXvyOkSQtqWHpz8ahRgfD4oBlnZp4vOZBzvffwhWXvKL0="
moz-do-not-send="true">"http://www.w3.org/2000/09/xmldsig#enveloped-signature"</a>/><ds:Transform
Algorithm=<a class="x_moz-txt-link-rfc2396E"
href="http://www.w3.org/2001/10/xml-exc-c14n#"
originalsrc="http://www.w3.org/2001/10/xml-exc-c14n#"
shash="zQLW0sIXBk+MvUY9zijrJBRF0A0qyLpyA58n0Wy/5s1V3ZU3QywU+KCmL2+W7KIHmMI2JpqFQuH1x+wOoNoopoFcsxztdoulIKc/jS5QMo7/x281wznRNfxnx3BUbIWnCjlqG6zdl/K2PKZZE4zBr6KKEqF9DTAGqDVu4n0PGLw="
moz-do-not-send="true">"http://www.w3.org/2001/10/xml-exc-c14n#"</a>/></ds:Transforms><ds:DigestMethod
Algorithm=<a class="x_moz-txt-link-rfc2396E"
href="http://www.w3.org/2001/04/xmlenc#sha256"
originalsrc="http://www.w3.org/2001/04/xmlenc#sha256"
shash="NHPqTZ2SjXjMOm9uyuHaseJdSK/1XNLXFTWwNiFPBAoBTPEV+EFuURjbMm31nkKh6utVfBdpcB8OfQRIDgDQWWeHoTQHU4BulrSgSFnvNJcI+43EnWRx3q6VNL8ERwtmUFs/+HT1ROgNB6AtHIu/1IZQltlacOUt0W9dYbgEV3c="
moz-do-not-send="true">"http://www.w3.org/2001/04/xmlenc#sha256"</a>/><ds:DigestValue>/2LlBZ/gtYHQwsNlbCANPC7OtLS4kwzsZYw+fmoG30Y=</ds:DigestValue></ds:Reference></ds:SignedInfo><b><ds:SignatureValue></b>aZXGpM0E6PPplFqu9w0yHjS3CILLKR+tEITyokiLoZjjOucbhblytIpBlEtU1TQLlthkbmIJ3vS9EM9hHWMwRBEKb6DpfCBvTs4ie2Br+/gnggk5wkZgcTxYNLrDgLVN58XW0pSsdnXXj0wDXESKAXxycsoU6RV8Tx9eX3+AvpPgyllD2mrmfCQGiepLrHEOLW9fnx07ulWZLf3CeVIiQtMXN0jg7UpPSljIizAQCblA6Vu1WoF6XQ1k73EPJpDGqTMKtTskA563WwWFYkXWd5kU1hcT4cpsBB9/xsAYd/U22rENIiUaUJkmMCIuUFlBsf+J3Ao60w5PyesKmr7m8D/HyE0FN6njKi3uLr9O1JvYw5iQB+6+1Mck4feJZiNmj/BJMRPcQrOaui3hPsi44XTBxnzzXhR1p07Trhjd1LQyuwaKNjj18SWnq5315/jZTrXbIBs0p0AxyVTtISits3v3LJSGLfNmjQAE/zwUzHvA1aE6ZhcaL9UUrMnXWYDW<b></ds:SignatureValue><ds:KeyInfo><ds:X509Data><ds:X509Certificate></b>MIIENzCCAp+gAwIBAgIUFuvD0n2MY1kb97i5Fpj58CXbK4cwDQYJKoZIhvcNAQELBQAwHjEcMBoG<br>
A1UEAwwTaWRwNG10LmltdGJzLXRzcC5ldTAeFw0yMTA2MDIxODA2NTJaFw00MTA2MDIxODA2NTJa<br>
MB4xHDAaBgNVBAMME2lkcDRtdC5pbXRicy10c3AuZXUwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAw</i></font></p>
<p><font size="1">.... removed lines ....</font></p>
<p><font size="1"><i>CDu47TK2tz6cz5nAl0zc2lXQAYp/Ozi6P60iB8tThCfWl5xKXKGxt76V+BmdeUMGIvWDivyave40<br>
nLu+SrEG56xu1QCaeivDj6YgUJon3Il7DnTFYriiHIDmwSCp8lK71NzJsxwoE7T2pgGySV5qhgTq<b></ds:X509Certificate></ds:X509Data></ds:KeyInfo></ds:Signature></b><saml2:Subject><saml2:NameID
Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">proc</saml2:NameID><saml2:SubjectConfirmation
Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><saml2:SubjectConfirmationData
Address="157.159.52.134"
InResponseTo="_41e01d0f-6da3-4c1e-8ad2-b506729f3c48"
NotOnOrAfter="2024-02-28T20:22:52.814Z" Recipient=<a
class="x_moz-txt-link-rfc2396E"
href="https://spvendor.int.fr/DN/Cor/Login.aspx?"
originalsrc="https://spvendor.int.fr/DN/Cor/Login.aspx?"
shash="TQbT5kZYOoU7Oee2nb2Gk3lfTC8EVJ/NLfsfXg8Y+Zat6noKuyeRswNz1X2xj9Rh0nakCQ92o5DuCq64U2HzTq5G1hBcJBmHvAgSQyH+wCEXpUFhdOLLy0Mz89HP4uXXV6yf2h/A93aRoRoTp6rUFvEa8MG/Hm0wJmOOc3a0il4="
moz-do-not-send="true">"https://spvendor.int.fr/DN/Cor/Login.aspx?"</a>/></saml2:SubjectConfirmation></saml2:Subject><saml2:Conditions
NotBefore="2024-02-28T20:17:52.809Z"
NotOnOrAfter="2024-02-28T20:22:52.809Z"><saml2:AudienceRestriction><saml2:Audience><a
class="x_moz-txt-link-freetext moz-txt-link-freetext"
href="https://spvendor.int.fr/"
originalsrc="https://spvendor.int.fr/"
shash="U3HT7cKNa+kard23KLwFsALh8PfF7nMrGR3ekPCv/AQmGujBOT0MG83ZKLDEcgytrky0O2AJS9J7BBuNEn6vlUS96iROy7x2FVNfUo7JQ/CXeS8JZRTlCZP9lXDpY1jfT1ChzE7iOGMuAdBp+eUPHWDN3ba7o5IvFQHuuDb9bQs="
moz-do-not-send="true">https://spvendor.int.fr</a></saml2:Audience></saml2:AudienceRestriction></saml2:Conditions><saml2:AuthnStatement
AuthnInstant="2024-02-28T20:17:52.801Z"
SessionIndex="_039112ee44587b2570bbabf55b4626fd"><saml2:SubjectLocality
Address="157.159.52.134"/><saml2:AuthnContext><saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef></saml2:AuthnContext></saml2:AuthnStatement><saml2:AttributeStatement><saml2:Attribute
FriendlyName="mail"
Name="urn:oid:0.9.2342.19200300.100.1.3"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue><a
class="x_moz-txt-link-abbreviated moz-txt-link-freetext"
href="mailto:je.proca@int.fr" moz-do-not-send="true">je.proca@int.fr</a></saml2:AttributeValue></saml2:Attribute><saml2:Attribute
FriendlyName="uid"
Name="urn:oid:0.9.2342.19200300.100.1.1"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>proc</saml2:AttributeValue></saml2:Attribute><saml2:Attribute
FriendlyName="givenName" Name="urn:oid:2.5.4.42"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Je</saml2:AttributeValue></saml2:Attribute><saml2:Attribute
FriendlyName="eduPersonPrimaryAffiliation"
Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.5"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>staff</saml2:AttributeValue></saml2:Attribute><saml2:Attribute
FriendlyName="displayName"
Name="urn:oid:2.16.840.1.113730.3.1.241"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Je
PROCA</saml2:AttributeValue></saml2:Attribute><saml2:Attribute
FriendlyName="sn" Name="urn:oid:2.5.4.4"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>PROCA</saml2:AttributeValue></saml2:Attribute><saml2:Attribute
FriendlyName="eduPersonPrincipalName"
Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue><a
class="x_moz-txt-link-abbreviated moz-txt-link-freetext"
href="mailto:proc@tets.eu" moz-do-not-send="true">proc@tets.eu</a></saml2:AttributeValue></saml2:Attribute></saml2:AttributeStatement></saml2:Assertion></saml2p:Response></i></font><br>
<br>
</p>
<p><br>
</p>
<p><br>
</p>
<div class="x_moz-cite-prefix">On 21/02/2024 21:34, Morgan,
Andrew J via users wrote:<br>
</div>
<blockquote type="cite">
<style type="text/css" style="display:none">p
{margin-top:0;
margin-bottom:0}</style>
<div class="x_elementToProof"
style="font-family:Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
The vendor should use well-known SAML SP software. Don't
trust anyone to write their own SAML SP. Unfortunately, I
have no idea what SP software to recommend for them except
the Shibboleth SP.</div>
<div class="x_elementToProof"
style="font-family:Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div class="x_elementToProof"
style="font-family:Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Andy<br>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="x_divRplyFwdMsg" dir="ltr"><font
style="font-size:11pt" face="Calibri, sans-serif"
color="#000000"><b>From:</b> users
<a class="x_moz-txt-link-rfc2396E"
href="mailto:users-bounces@shibboleth.net"
moz-do-not-send="true"><users-bounces@shibboleth.net></a>
on behalf of
<a
class="x_moz-txt-link-abbreviated moz-txt-link-freetext"
href="mailto:jehan.procaccia@tem-tsp.eu"
moz-do-not-send="true">jehan.procaccia@tem-tsp.eu</a>
<a class="x_moz-txt-link-rfc2396E"
href="mailto:jehan.procaccia@tem-tsp.eu"
moz-do-not-send="true"><jehan.procaccia@tem-tsp.eu></a><br>
<b>Sent:</b> Wednesday, February 21, 2024 12:07 PM<br>
<b>To:</b> <a
class="x_moz-txt-link-abbreviated moz-txt-link-freetext"
href="mailto:users@shibboleth.net"
moz-do-not-send="true">
users@shibboleth.net</a> <a
class="x_moz-txt-link-rfc2396E"
href="mailto:users@shibboleth.net"
moz-do-not-send="true">
<users@shibboleth.net></a><br>
<b>Subject:</b> Re: sign and/or encrypt SAML assetions,
hack MITM</font>
<div> </div>
</div>
<div class="x_BodyFragment"><font size="2"><span
style="font-size:11pt">
<div class="x_PlainText">[This email originated from
outside of OSU. Use caution with links and
attachments.]<br>
<br>
On 21/02/2024 16:57, Peter Schober via users wrote:<br>
> Morgan, Andrew J via users <a
class="x_moz-txt-link-rfc2396E"
href="mailto:users@shibboleth.net"
moz-do-not-send="true">
<users@shibboleth.net></a> [2024-02-21 16:20
CET]:<br>
>> If you are able to modify the assertion
without the SP rejecting it,<br>
>> then that SP is not validating the
signature. Personally, I would<br>
>> not use SAML with an SP that does not
validate the signature. As<br>
>> you have found, anyone can modify the
assertion to impersonate<br>
>> another user - critical security bug. Have
you reported this issue<br>
>> to the vendor's security contact?<br>
Yes Morgan, we have reported the flow to the vendor,
and are activelly<br>
working on a correction . That's why I search for
best-practice Doc on<br>
how to instruct them to do the right thinks, any
pointer to that will be<br>
greatly appreciated .<br>
> Testing for this on a larger scale isn't
trivial (and might include<br>
> legal aspects) but an activity within GÉANT has
recently started to<br>
> look into this:<br>
> <a
href="https://wiki.geant.org/display/GWP5/Scalable+testing+for+insecure+SAML+signature+validation"
originalsrc="https://wiki.geant.org/display/GWP5/Scalable+testing+for+insecure+SAML+signature+validation"
shash="F196sejBnMBiG2wTpAul4NStLZa90vZRbbWyfcrmwOkzDEU5AypjZ+Uqiz5JltZl8iTZxjjobsMtAu7AQYca9yRxKnQOG5kTEefuv+kF4SUyctvUt27zhA0qRpv2rRsyWxP2/q6cLgZ0aa5U8midst2m4MQMCxjoOzK2lpmtWlI="
moz-do-not-send="true">
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.geant.org%2Fdisplay%2FGWP5%2FScalable%2Btesting%2Bfor%2Binsecure%2BSAML%2Bsignature%2Bvalidation&data=05%7C02%7Cmorgan%40oregonstate.edu%7C03cb1f9bcf8a4ae3eb8008dc3318b10a%7Cce6d05e13c5e4d6287a84c4a2713c113%7C0%7C0%7C638441428344213736%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=mKjesR%2By6vFQOt9Y3WxP6hyg%2B4Y8jPwRj%2BdHyWInpT4%3D&reserved=0</a><br>
><br>
Thanks again Peter for that link, it describe my
problem, even more , it<br>
focuses on properly validate the signature.<br>
<br>
in my case it is worst, there is no signature check
at all, I'll care<br>
about the authenticity of the signature in the
second step .<br>
<br>
regards , jehan .<br>
<br>
><br>
> -peter<br>
--<br>
For Consortium Member technical support, see <a
href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw"
originalsrc="https://shibboleth.atlassian.net/wiki/x/ZYEpPw"
shash="iWj8f3hwIo+Y62Z1IHe76y1LpjcLY1jhjeOPYeq+8IKkcEu8cf6AvrZ37tj8AFITGals0bRUqAfTeuTNYPYX1GBruV923pYfD6GrTKcjrF2j7Kv0KFzALoeiNusdGLP4R7qXnWPEATSZoT360m9MHjGNuCJ1QiHMbnzFKZVOgjw="
moz-do-not-send="true">
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C02%7Cmorgan%40oregonstate.edu%7C03cb1f9bcf8a4ae3eb8008dc3318b10a%7Cce6d05e13c5e4d6287a84c4a2713c113%7C0%7C0%7C638441428344221440%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=55ew17NywXC2egkjJynEDz%2BMlj027NXNPeJwrzJgZc0%3D&reserved=0</a><br>
To unsubscribe from this list send an email to <a
class="x_moz-txt-link-abbreviated moz-txt-link-freetext"
href="mailto:users-unsubscribe@shibboleth.net"
moz-do-not-send="true">
users-unsubscribe@shibboleth.net</a><br>
</div>
</span></font></div>
<br>
<fieldset class="x_moz-mime-attachment-header"></fieldset>
</blockquote>
</div>
</div>
</blockquote>
</body>
</html>