<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Hi Jehan,</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Since the IDP's default is to sign responses, you can remove WantAssertionsSigned from the SP metadata.  You don't need to add signResponses="true" to relying-party.xml.</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I'm glad the vendor improved their product!</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thanks,</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Andy</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="appendonsend"></div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<hr style="display: inline-block; width: 98%;">
<div dir="ltr" id="divRplyFwdMsg"><span style="font-family: Calibri, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);"><b>From:</b> jehan.procaccia@tem-tsp.eu <jehan.procaccia@tem-tsp.eu><br>
<b>Sent:</b> Tuesday, March 5, 2024 11:15 AM<br>
<b>To:</b> Morgan, Andrew J <morgan@oregonstate.edu>; Shib Users <users@shibboleth.net><br>
<b>Subject:</b> Re: sign and/or encrypt SAML assetions, hack MITM</span>
<div> </div>
</div>
<p style="margin-top: 0px; margin-bottom: 0px;"><span style="color: rgb(215, 63, 9);">[This email originated from outside of OSU. Use caution with links and attachments.]</span></p>
<p style="margin-top: 0px; margin-bottom: 0px;">Hi</p>
<p style="margin-top: 0px; margin-bottom: 0px;"><br>
</p>
<p style="margin-top: 0px; margin-bottom: 0px;">finally this thread conviced the SP vendor to honor not only assertion signature, but also Responses signatures .</p>
<p style="margin-top: 0px; margin-bottom: 0px;">As I understood from this thread, it is better to Sign responses, so, what should I do ?:</p>
<p style="margin-top: 0px; margin-bottom: 0px;">1) set in that SP metadata a "<i>Want</i><b><i>Response</i></b><i>Signed="true"</i> ? (if this directive exist ? , didn't found that on shibboleth Doc, only
<i>Want</i><b><i>Assertions</i></b><i>Signed)</i></p>
<p style="margin-top: 0px; margin-bottom: 0px;">2) as the IDP signs by default responses, maybe the best solution is to set nothing regarding signature in SP medatada ?</p>
3) as I still have to override for that SP in<i> relying-party.xml</i> the fact that it doesn't encrypt Assertion => 
<i>p:encryptAssertions="false"</i> , should I set there <code>signResponses="true" ,
</code><span style="font-size: 18px;"><code>or again it it not necessary as the IDP does this (signResponses)  by default ?</code><br>
</span>
<p style="margin-top: 0px; margin-bottom: 0px;"><br>
</p>
<p style="margin-top: 0px; margin-bottom: 0px;">Thanks .</p>
<p style="margin-top: 0px; margin-bottom: 0px;"><br>
</p>
<p style="margin-top: 0px; margin-bottom: 0px;">jehan</p>
<p style="margin-top: 0px; margin-bottom: 0px;"><br>
</p>
<div>On 29/02/2024 00:16, Morgan, Andrew J wrote:</div>
<blockquote>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Hi Jehan,</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
The default for the Shibboleth IDP is to sign the Response, not the Assertion.</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div><span style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">It looks like both the SAML Response and the SAML Assertion are being signed.  This is okay, but it is not necessary to sign both.  Since you are modifying the
 SP config using relying-party.xml anyway, you could set signResponses=false to eliminate the double signing.</span></div>
<div><span style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"><br>
</span></div>
<div><span style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">If the SP wants the assertion signed, they should include that flag in their metadata (see the bottom of
<a href="https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/3169288205/ProfileConfiguration-SAMLAssertion" id="OWA40469fdc-305f-bcf0-ad8d-7632eeb43e35" class="x_OWAAutoLink x_moz-txt-link-freetext" data-auth="Verified" data-loopstyle="linkonly">
https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/3169288205/ProfileConfiguration-SAMLAssertion</a>).</span></div>
<div><span style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"><br>
</span></div>
<div><span style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">Andy</span></div>
<div><span style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"><br>
</span></div>
<hr style="display: inline-block; width: 98%;">
<div dir="ltr" id="x_divRplyFwdMsg"><span style="font-family: Calibri, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);"><b>From:</b> jehan Procaccia tem
<a href="mailto:jehan.procaccia@tem-tsp.eu" id="OWA84017f76-1586-65b0-f321-13b63087e14a" class="x_moz-txt-link-rfc2396E OWAAutoLink" data-loopstyle="linkonly">
<jehan.procaccia@tem-tsp.eu></a><br>
<b>Sent:</b> Wednesday, February 28, 2024 12:58 PM<br>
<b>To:</b> Shib Users <a href="mailto:users@shibboleth.net" id="OWA5007bac2-7ad9-33d7-9a37-e841ea883312" class="x_moz-txt-link-rfc2396E OWAAutoLink" data-loopstyle="linkonly">
<users@shibboleth.net></a><br>
<b>Cc:</b> Morgan, Andrew J <a href="mailto:morgan@oregonstate.edu" id="OWAc914ebf6-5fa4-db49-edaa-439afc0b22f7" class="x_moz-txt-link-rfc2396E OWAAutoLink" data-loopstyle="linkonly">
<morgan@oregonstate.edu></a><br>
<b>Subject:</b> Re: sign and/or encrypt SAML assetions, hack MITM</span>
<div> </div>
</div>
<p style="margin-top: 0px; margin-bottom: 0px;"><span style="color: rgb(215, 63, 9);">[This email originated from outside of OSU. Use caution with links and attachments.]</span></p>
<p style="margin-top: 0px; margin-bottom: 0px;">Hello,</p>
<p style="margin-top: 0px; margin-bottom: 0px;"><br>
</p>
<p style="margin-top: 0px; margin-bottom: 0px;">some news about the hack I was facing (MITM allowing to impersonate because of signature not verified)</p>
<p style="margin-top: 0px; margin-bottom: 0px;"><br>
</p>
<p style="margin-top: 0px; margin-bottom: 0px;">the  SP Vendor did corrected it's code, and now does check the signature of SAML reponse, they are using a library (
<a href="https://www.componentspace.com/" id="OWA3279b919-9468-553c-23a0-97ff7b63e38c" class="x_x_moz-txt-link-freetext x_moz-txt-link-freetext OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-auth="Verified" data-loopstyle="linkonly">
https://www.componentspace.com/</a> for their DotNet code) .</p>
<p style="margin-top: 0px; margin-bottom: 0px;">Now changing on the fly the NamedID brakes the signature and fails the login process :-)</p>
<p style="margin-top: 0px; margin-bottom: 0px;"><br>
</p>
<p style="margin-top: 0px; margin-bottom: 0px;">howerver, I still have a question regarding the overrides for that SP in
<i>relying-party.xml</i> of my IDP, now I had to force <span style="font-size: 13px;">
<i>" </i><b><i>p:signAssertions="true" </i></b></span>[1] in order for the SSO flow to succeed</p>
<p style="margin-top: 0px; margin-bottom: 0px;"><span style="font-size: 13px;"><b><i><br>
</i></b></span></p>
<p style="margin-top: 0px; margin-bottom: 0px;">Isn't it the default behavior for the IDP to SignAssertions ?</p>
<p style="margin-top: 0px; margin-bottom: 0px;"><span style="font-size: 13px;"><b><i><br>
</i></b></span></p>
<p style="margin-top: 0px; margin-bottom: 0px;"><span style="font-size: 13px;"><b><i>[1]</i></b></span></p>
<p style="margin-top: 0px; margin-bottom: 0px;"><span style="font-size: 13px;"><i><bean id="IMTOP9" parent="RelyingPartyByName" c:relyingPartyIds="#{{'<a href="https://vendorsp.int.fr/" id="OWA1c8fc99b-1b08-181d-c76e-8743d4f07c86" class="x_x_moz-txt-link-freetext OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-auth="Verified" data-loopstyle="linkonly">https://vendorsp.int.Fr</a>'}}"><br>
            <property name="profileConfigurations"><br>
                <list><br>
                    <bean parent="SAML2.SSO" </i><b><i>p:signAssertions="true"</i></b><i> p:encryptAssertions="false" p:checkAddress="false" p:nameIDFormatPrecedence="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified" p:postAuthenticationFlows="#{ {'attribute-release'}
 }" /><br>
                </list><br>
            </property><br>
        </bean></i></span></p>
<p style="margin-top: 0px; margin-bottom: 0px;"><br>
</p>
<p style="margin-top: 0px; margin-bottom: 0px;">Below [2] is the final response with the succeed login assertion, why is there 2 occurences of signatures !? I am wondering if forcing
<span style="font-size: 13px;"><b><i>p:signAssertions="true" </i></b></span>in relying-party overrides doesn't generate that 2nd signature and hence if I finally correctly corrected that signature initial failure (MITM) ?</p>
<p style="margin-top: 0px; margin-bottom: 0px;"><span style="font-size: 13px;"><b><i><br>
</i></b></span></p>
<p style="margin-top: 0px; margin-bottom: 0px;">Thanks .</p>
<p style="margin-top: 0px; margin-bottom: 0px;"><br>
</p>
<p style="margin-top: 0px; margin-bottom: 0px;">jehan</p>
<p style="margin-top: 0px; margin-bottom: 0px;"><br>
</p>
<p style="margin-top: 0px; margin-bottom: 0px;"><span style="font-size: 10px;"><i><?xml version="1.0" encoding="UTF-8"?><saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination=<a href="https://spvendor.int.fr/DN/Cor/Login.aspx?" id="OWA668e8c0c-f341-67de-fa41-984dc0ed1fb1" class="x_x_moz-txt-link-rfc2396E OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-auth="Verified" data-loopstyle="linkonly">"https://spvendor.int.fr/DN/Cor/Login.aspx?"</a> ID="_559afb4625da7388a1875db8d8abfcd5"
 InResponseTo="_41e01d0f-6da3-4c1e-8ad2-b506729f3c48" IssueInstant="2024-02-28T20:17:52.809Z" Version="2.0"><saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://idp4mt.int.fr/idp/shibboleth" id="OWAd4029922-b1f9-e0cc-5252-ad2562661200" class="x_x_moz-txt-link-freetext x_moz-txt-link-freetext OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-auth="Verified" data-loopstyle="linkonly">https://idp4mt.int.fr/idp/shibboleth</a></saml2:Issuer><ds:Signature
 xmlns:ds=<a href="http://www.w3.org/2000/09/xmldsig#" id="OWAe95df3ec-9139-daaa-2a74-9cde23375a9b" class="x_x_moz-txt-link-rfc2396E OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-auth="Verified" data-loopstyle="linkonly">"http://www.w3.org/2000/09/xmldsig#"</a>><ds:SignedInfo><ds:CanonicalizationMethod
 Algorithm=<a href="http://www.w3.org/2001/10/xml-exc-c14n#" id="OWA00dcd38f-8e12-00e1-b74d-84b268632d4c" class="x_x_moz-txt-link-rfc2396E OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-auth="Verified" data-loopstyle="linkonly">"http://www.w3.org/2001/10/xml-exc-c14n#"</a>/><ds:SignatureMethod
 Algorithm=<a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" id="OWA1d9c8f58-d0f9-7ead-c32a-78f469be4c3e" class="x_x_moz-txt-link-rfc2396E OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-auth="Verified" data-loopstyle="linkonly">"http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"</a>/><ds:Reference
 URI="#_559afb4625da7388a1875db8d8abfcd5"><ds:Transforms><ds:Transform Algorithm=<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature" id="OWA1665cb43-e1e2-9aa7-0a1f-03f993313303" class="x_x_moz-txt-link-rfc2396E OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-auth="Verified" data-loopstyle="linkonly">"http://www.w3.org/2000/09/xmldsig#enveloped-signature"</a>/><ds:Transform
 Algorithm=<a href="http://www.w3.org/2001/10/xml-exc-c14n#" id="OWAcce641d3-244a-7307-34b8-47fa02399bf8" class="x_x_moz-txt-link-rfc2396E OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-auth="Verified" data-loopstyle="linkonly">"http://www.w3.org/2001/10/xml-exc-c14n#"</a>/></ds:Transforms><ds:DigestMethod
 Algorithm=<a href="http://www.w3.org/2001/04/xmlenc#sha256" id="OWA60acef76-b8ad-7d46-3847-12c9fc6eb3af" class="x_x_moz-txt-link-rfc2396E OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-auth="Verified" data-loopstyle="linkonly">"http://www.w3.org/2001/04/xmlenc#sha256"</a>/><ds:DigestValue>eqkNtL+bgLqmt5bzxnP8SWpF+/0pWyF05WWLoe9Lpsk=</ds:DigestValue></ds:Reference></ds:SignedInfo></i><b><i><ds:SignatureValue></i></b><i>UsW9wqtigxJCkPei65OCChDnn1m1g0fn1NC+3iR8YGSzkDL+gcEYovMrD1L3Lr3Sd9o8qjacnfrNpPrL5UbS0D0bvkP5Kmq3aaFxTO5wKrRZ4CcxHjOFn5AcYn+osKeZCAjcNKFmmFKABII4I3vVgSpaQ9cAQ+8whoK+3wf2e7gFyMHphtgS1DAcnplHBNbmBkSeKAuz7ikc8JR5Pmth1pUi9fEovmCs2Fz/SL6zwJRpjK4V/wgehM90/xT8S3+aS7TEz1HWd5LhyK7xhCvZH4eKvnxv4e3qDUPkOZhhUiLjEARtJ1edvhM3kNW2K5y/T1rbx4AkI8IDjs/zMPwe/l51et9P9aNSU3naH8NJcacztTJKoq2LblmivSiYjiIuSuXhR2S3Q9quYkEjMl+GhXzsR6gnqFCMGPinewb+DdgO21psJatcxQd0fbXAsBd+D7q2E0DJFQxJ7VvmOR8k/67YQguhiM/5/ldPULrvysxV4psCGfpmj6TMpdZ4xvFB</i><b><i></ds:SignatureValue><ds:KeyInfo><ds:X509Data><ds:X509Certificate></i></b><i>MIIENzCCAp+gAwIBAgIUFuvD0n2MY1kb97i5Fpj58CXbK4cwDQYJKoZIhvcNAQELBQAwHjEcMBoG<br>
A1UEAwwTaWRwNG10LmltdGJzLXRzcC5ldTAeFw0yMTA2MDIxODA2NTJaFw00MTA2MDIxODA2NTJa<br>
MB4xHDAaBgNVBAMME2lkcDRtdC5pbXRicy10c3AuZXUwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAw</i></span></p>
<p style="margin-top: 0px; margin-bottom: 0px;"><span style="font-size: 10px;">.... removed lines ....</span></p>
<p style="margin-top: 0px; margin-bottom: 0px;"><span style="font-size: 10px;"><i>CDu47TK2tz6cz5nAl0zc2lXQAYp/Ozi6P60iB8tThCfWl5xKXKGxt76V+BmdeUMGIvWDivyave40<br>
nLu+SrEG56xu1QCaeivDj6YgUJon3Il7DnTFYriiHIDmwSCp8lK71NzJsxwoE7T2pgGySV5qhgTq</i><b><i></ds:X509Certificate></ds:X509Data></ds:KeyInfo></ds:Signature></i></b><i><saml2p:Status><saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/></saml2p:Status><saml2:Assertion
 xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_ddb8bd5505c6f6aa452e7238e5c19ef8" IssueInstant="2024-02-28T20:17:52.809Z" Version="2.0"><saml2:Issuer><a href="https://idp4mt.int.fr/idp/shibboleth" id="OWA5a60333a-188d-e32e-2680-c88ffa8bbdce" class="x_x_moz-txt-link-freetext x_moz-txt-link-freetext OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-auth="Verified" data-loopstyle="linkonly">https://idp4mt.int.fr/idp/shibboleth</a></saml2:Issuer><ds:Signature
 xmlns:ds=<a href="http://www.w3.org/2000/09/xmldsig#" id="OWA59482b9e-5ae3-20c8-2068-015c15fbd846" class="x_x_moz-txt-link-rfc2396E OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-auth="Verified" data-loopstyle="linkonly">"http://www.w3.org/2000/09/xmldsig#"</a>><ds:SignedInfo><ds:CanonicalizationMethod
 Algorithm=<a href="http://www.w3.org/2001/10/xml-exc-c14n#" id="OWAadc68170-211a-f017-e632-42239c473b1a" class="x_x_moz-txt-link-rfc2396E OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-auth="Verified" data-loopstyle="linkonly">"http://www.w3.org/2001/10/xml-exc-c14n#"</a>/><ds:SignatureMethod
 Algorithm=<a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" id="OWA20329db3-eaf1-4dc4-1f43-5869f116c78b" class="x_x_moz-txt-link-rfc2396E OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-auth="Verified" data-loopstyle="linkonly">"http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"</a>/><ds:Reference
 URI="#_ddb8bd5505c6f6aa452e7238e5c19ef8"><ds:Transforms><ds:Transform Algorithm=<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature" id="OWA2c2862c6-973f-707d-85e4-1575a986de29" class="x_x_moz-txt-link-rfc2396E OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-auth="Verified" data-loopstyle="linkonly">"http://www.w3.org/2000/09/xmldsig#enveloped-signature"</a>/><ds:Transform
 Algorithm=<a href="http://www.w3.org/2001/10/xml-exc-c14n#" id="OWA52bec90a-9849-43cc-b457-162ff1372442" class="x_x_moz-txt-link-rfc2396E OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-auth="Verified" data-loopstyle="linkonly">"http://www.w3.org/2001/10/xml-exc-c14n#"</a>/></ds:Transforms><ds:DigestMethod
 Algorithm=<a href="http://www.w3.org/2001/04/xmlenc#sha256" id="OWA0b9eab49-fd8a-6e44-ec72-6e3ea1118316" class="x_x_moz-txt-link-rfc2396E OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-auth="Verified" data-loopstyle="linkonly">"http://www.w3.org/2001/04/xmlenc#sha256"</a>/><ds:DigestValue>/2LlBZ/gtYHQwsNlbCANPC7OtLS4kwzsZYw+fmoG30Y=</ds:DigestValue></ds:Reference></ds:SignedInfo></i><b><i><ds:SignatureValue></i></b><i>aZXGpM0E6PPplFqu9w0yHjS3CILLKR+tEITyokiLoZjjOucbhblytIpBlEtU1TQLlthkbmIJ3vS9EM9hHWMwRBEKb6DpfCBvTs4ie2Br+/gnggk5wkZgcTxYNLrDgLVN58XW0pSsdnXXj0wDXESKAXxycsoU6RV8Tx9eX3+AvpPgyllD2mrmfCQGiepLrHEOLW9fnx07ulWZLf3CeVIiQtMXN0jg7UpPSljIizAQCblA6Vu1WoF6XQ1k73EPJpDGqTMKtTskA563WwWFYkXWd5kU1hcT4cpsBB9/xsAYd/U22rENIiUaUJkmMCIuUFlBsf+J3Ao60w5PyesKmr7m8D/HyE0FN6njKi3uLr9O1JvYw5iQB+6+1Mck4feJZiNmj/BJMRPcQrOaui3hPsi44XTBxnzzXhR1p07Trhjd1LQyuwaKNjj18SWnq5315/jZTrXbIBs0p0AxyVTtISits3v3LJSGLfNmjQAE/zwUzHvA1aE6ZhcaL9UUrMnXWYDW</i><b><i></ds:SignatureValue><ds:KeyInfo><ds:X509Data><ds:X509Certificate></i></b><i>MIIENzCCAp+gAwIBAgIUFuvD0n2MY1kb97i5Fpj58CXbK4cwDQYJKoZIhvcNAQELBQAwHjEcMBoG<br>
A1UEAwwTaWRwNG10LmltdGJzLXRzcC5ldTAeFw0yMTA2MDIxODA2NTJaFw00MTA2MDIxODA2NTJa<br>
MB4xHDAaBgNVBAMME2lkcDRtdC5pbXRicy10c3AuZXUwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAw</i></span></p>
<p style="margin-top: 0px; margin-bottom: 0px;"><span style="font-size: 10px;">.... removed lines ....</span></p>
<p style="margin-top: 0px; margin-bottom: 0px;"><span style="font-size: 10px;"><i>CDu47TK2tz6cz5nAl0zc2lXQAYp/Ozi6P60iB8tThCfWl5xKXKGxt76V+BmdeUMGIvWDivyave40<br>
nLu+SrEG56xu1QCaeivDj6YgUJon3Il7DnTFYriiHIDmwSCp8lK71NzJsxwoE7T2pgGySV5qhgTq</i><b><i></ds:X509Certificate></ds:X509Data></ds:KeyInfo></ds:Signature></i></b><i><saml2:Subject><saml2:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified" xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">proc</saml2:NameID><saml2:SubjectConfirmation
 Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><saml2:SubjectConfirmationData Address="157.159.52.134" InResponseTo="_41e01d0f-6da3-4c1e-8ad2-b506729f3c48" NotOnOrAfter="2024-02-28T20:22:52.814Z" Recipient=<a href="https://spvendor.int.fr/DN/Cor/Login.aspx?" id="OWAf5e93df7-bb8c-7650-372d-1ab02bb059a8" class="x_x_moz-txt-link-rfc2396E OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-auth="Verified" data-loopstyle="linkonly">"https://spvendor.int.fr/DN/Cor/Login.aspx?"</a>/></saml2:SubjectConfirmation></saml2:Subject><saml2:Conditions
 NotBefore="2024-02-28T20:17:52.809Z" NotOnOrAfter="2024-02-28T20:22:52.809Z"><saml2:AudienceRestriction><saml2:Audience><a href="https://spvendor.int.fr/" id="OWA20390873-4b0a-15d5-c0eb-e1b4d69ad2bc" class="x_x_moz-txt-link-freetext x_moz-txt-link-freetext OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-auth="Verified" data-loopstyle="linkonly">https://spvendor.int.fr</a></saml2:Audience></saml2:AudienceRestriction></saml2:Conditions><saml2:AuthnStatement
 AuthnInstant="2024-02-28T20:17:52.801Z" SessionIndex="_039112ee44587b2570bbabf55b4626fd"><saml2:SubjectLocality Address="157.159.52.134"/><saml2:AuthnContext><saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef></saml2:AuthnContext></saml2:AuthnStatement><saml2:AttributeStatement><saml2:Attribute
 FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue><a href="mailto:je.proca@int.fr" id="OWA6cafec39-8b7d-096f-3b44-b3e0047ba016" class="x_x_moz-txt-link-abbreviated x_moz-txt-link-freetext OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-loopstyle="linkonly">je.proca@int.fr</a></saml2:AttributeValue></saml2:Attribute><saml2:Attribute
 FriendlyName="uid" Name="urn:oid:0.9.2342.19200300.100.1.1" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>proc</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="givenName" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Je</saml2:AttributeValue></saml2:Attribute><saml2:Attribute
 FriendlyName="eduPersonPrimaryAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.5" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>staff</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="displayName"
 Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Je PROCA</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="sn" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>PROCA</saml2:AttributeValue></saml2:Attribute><saml2:Attribute
 FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue><a href="mailto:proc@tets.eu" id="OWAea4e937f-5fbe-1856-c615-f41257553942" class="x_x_moz-txt-link-abbreviated x_moz-txt-link-freetext OWAAutoLink" style="margin-top: 0px; margin-bottom: 0px;" data-loopstyle="linkonly">proc@tets.eu</a></saml2:AttributeValue></saml2:Attribute></saml2:AttributeStatement></saml2:Assertion></saml2p:Response></i></span><br>
<br>
</p>
<p style="margin-top: 0px; margin-bottom: 0px;"><br>
</p>
<p style="margin-top: 0px; margin-bottom: 0px;"><br>
</p>
<div>On 21/02/2024 21:34, Morgan, Andrew J via users wrote:</div>
<blockquote>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
The vendor should use well-known SAML SP software.  Don't trust anyone to write their own SAML SP.  Unfortunately, I have no idea what SP software to recommend for them except the Shibboleth SP.</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Andy</div>
<hr style="display: inline-block; width: 98%;">
<div dir="ltr" id="x_x_divRplyFwdMsg"><span style="font-family: Calibri, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);"><b>From:</b> users
<a href="mailto:users-bounces@shibboleth.net" id="OWAb9dc0a03-3016-b597-fb51-253f33a7582a" class="x_x_moz-txt-link-rfc2396E OWAAutoLink" data-loopstyle="linkonly">
<users-bounces@shibboleth.net></a> on behalf of <a href="mailto:jehan.procaccia@tem-tsp.eu" id="OWAca332e48-7d99-1013-d3af-9de7b4ce5dbe" class="x_x_moz-txt-link-abbreviated x_moz-txt-link-freetext OWAAutoLink" data-loopstyle="linkonly">
jehan.procaccia@tem-tsp.eu</a> <a href="mailto:jehan.procaccia@tem-tsp.eu" id="OWAcfa9ac80-e512-123b-eceb-85dbbba600c2" class="x_x_moz-txt-link-rfc2396E OWAAutoLink" data-loopstyle="linkonly">
<jehan.procaccia@tem-tsp.eu></a><br>
<b>Sent:</b> Wednesday, February 21, 2024 12:07 PM<br>
<b>To:</b> <a href="mailto:users@shibboleth.net" id="OWAbf6710bd-eb6e-dde4-0ec8-5e95ac2ed8cc" class="x_x_moz-txt-link-abbreviated x_moz-txt-link-freetext OWAAutoLink" data-loopstyle="linkonly">
users@shibboleth.net</a> <a href="mailto:users@shibboleth.net" id="OWAb6b9392b-a1e8-5f34-ba99-fb429fd12f5d" class="x_x_moz-txt-link-rfc2396E OWAAutoLink" data-loopstyle="linkonly">
<users@shibboleth.net></a><br>
<b>Subject:</b> Re: sign and/or encrypt SAML assetions, hack MITM</span>
<div> </div>
</div>
<div><span style="font-size: 11pt;">[This email originated from outside of OSU. Use caution with links and attachments.]<br>
<br>
On 21/02/2024 16:57, Peter Schober via users wrote:<br>
> Morgan, Andrew J via users <a href="mailto:users@shibboleth.net" id="OWA3c85245f-acc6-7936-7c99-69803f9195ff" class="x_x_moz-txt-link-rfc2396E OWAAutoLink" data-loopstyle="linkonly">
<users@shibboleth.net></a> [2024-02-21 16:20 CET]:<br>
>> If you are able to modify the assertion without the SP rejecting it,<br>
>> then that SP is not validating the signature.  Personally, I would<br>
>> not use SAML with an SP that does not validate the signature.  As<br>
>> you have found, anyone can modify the assertion to impersonate<br>
>> another user - critical security bug.  Have you reported this issue<br>
>> to the vendor's security contact?<br>
Yes Morgan, we have reported the flow to the vendor, and are activelly<br>
working on a correction . That's why I search for best-practice Doc  on<br>
how to instruct them to do the right thinks, any pointer to that will be<br>
greatly appreciated .<br>
> Testing for this on a larger scale isn't trivial (and might include<br>
> legal aspects) but an activity within GÉANT has recently started to<br>
> look into this:<br>
> <a href="https://wiki.geant.org/display/GWP5/Scalable+testing+for+insecure+SAML+signature+validation" id="OWA0d54b187-0411-6c64-a7ec-d0847c6614d6" class="OWAAutoLink" data-auth="Verified" data-loopstyle="linkonly">
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.geant.org%2Fdisplay%2FGWP5%2FScalable%2Btesting%2Bfor%2Binsecure%2BSAML%2Bsignature%2Bvalidation&data=05%7C02%7Cmorgan%40oregonstate.edu%7C03cb1f9bcf8a4ae3eb8008dc3318b10a%7Cce6d05e13c5e4d6287a84c4a2713c113%7C0%7C0%7C638441428344213736%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=mKjesR%2By6vFQOt9Y3WxP6hyg%2B4Y8jPwRj%2BdHyWInpT4%3D&reserved=0</a><br>
><br>
Thanks again Peter for that link, it describe my problem, even more , it<br>
focuses on properly validate the signature.<br>
<br>
in my case it is worst, there is no signature check at all, I'll care<br>
about the authenticity of the signature in the second step .<br>
<br>
regards , jehan .<br>
<br>
><br>
> -peter<br>
--<br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" id="OWAd3b3b807-d244-79c4-3004-7be0d9ad5912" class="OWAAutoLink" data-auth="Verified" data-loopstyle="linkonly">
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C02%7Cmorgan%40oregonstate.edu%7C03cb1f9bcf8a4ae3eb8008dc3318b10a%7Cce6d05e13c5e4d6287a84c4a2713c113%7C0%7C0%7C638441428344221440%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=55ew17NywXC2egkjJynEDz%2BMlj027NXNPeJwrzJgZc0%3D&reserved=0</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" id="OWAa9995e74-91a0-9b33-df4f-3c5a0e398fe7" class="x_x_moz-txt-link-abbreviated x_moz-txt-link-freetext OWAAutoLink" data-loopstyle="linkonly">
users-unsubscribe@shibboleth.net</a></span></div>
<br>
<fieldset class="x_x_moz-mime-attachment-header"></fieldset></blockquote>
</blockquote>
</body>
</html>