mace-opensaml-users - RE: signature validation in OpenSAML2
Subject: OpenSAML user discussion
List archive
- From: "Scott Cantor" <>
- To: <>
- Subject: RE: signature validation in OpenSAML2
- Date: Tue, 11 Dec 2007 13:21:24 -0500
- Organization: The Ohio State University
> So, maybe everyone else already caught this from the debugging output I
> posted, and I'm just slow as a result of not being familiar with this
> stuff, but apparently (based on comparing the output with the xmlsec
> source) the digest is validating correctly, and it is only the signature
> validation that is failing.
It looked like it.
> Correct me if I'm wrong, but my understanding (based on the xml-dsig
> spec) is that the digest is calculated over the referenced element (in
> SAML, the assertion), and it is the <SignedInfo/> element, which
> contains both the reference (and the reference contains the digest),
> that is signed with the public/private key algorithm. Now, the digest is
> definitely the same on both sides (I checked), and the signature is
> inside the SAML assertion, which is what it is supposed to be a digest
> of, so according to SHA1 nothing is changing. Is there any type of
> change the RSA might be sensitive to that SHA1 isn't? Or is it possible
> that this is a configuration problem or something?
If SignedInfo changes, I'd start by making sure you were using exclusive
c14n everywhere, including for the overall signature c14n, not just as a
transform. If so, there usually aren't a lot of namespace problems inside
SignedInfo unless something is physically rewriting them in a noticable way.
SignedInfo is also digested before signing it, so you can also catch those
bytes during the final digest step.
-- Scott
- Re: signature validation in OpenSAML2, (continued)
- Re: signature validation in OpenSAML2, Kenny Pearce, 12/07/2007
- Re: signature validation in OpenSAML2, Kenny Pearce, 12/10/2007
- RE: signature validation in OpenSAML2, Scott Cantor, 12/10/2007
- Re: signature validation in OpenSAML2, Chad La Joie, 12/11/2007
- Re: signature validation in OpenSAML2, Kenny Pearce, 12/11/2007
- RE: signature validation in OpenSAML2, Scott Cantor, 12/11/2007
- Re: signature validation in OpenSAML2, Chad La Joie, 12/11/2007
- Re: signature validation in OpenSAML2, Kenny Pearce, 12/11/2007
- Re: signature validation in OpenSAML2, Chad La Joie, 12/11/2007
- Re: signature validation in OpenSAML2, Kenny Pearce, 12/11/2007
- RE: signature validation in OpenSAML2, Scott Cantor, 12/11/2007
- Message not available
- Re: signature validation in OpenSAML2, Brent Putman, 12/11/2007
- Re: signature validation in OpenSAML2, Kenny Pearce, 12/11/2007
- Re: signature validation in OpenSAML2, Brent Putman, 12/11/2007
- RE: signature validation in OpenSAML2, Scott Cantor, 12/11/2007
- Re: signature validation in OpenSAML2, Chad La Joie, 12/11/2007
- RE: signature validation in OpenSAML2, Scott Cantor, 12/11/2007
- Re: signature validation in OpenSAML2, Kenny Pearce, 12/11/2007
Archive powered by MHonArc 2.6.16.