mace-opensaml-users - Unable to extract SAML token
Subject: OpenSAML user discussion
List archive
- From:
- To:
- Subject: Unable to extract SAML token
- Date: Thu, 31 Jul 2008 07:22:51 -0400 (EDT)
I am facing an issue with extracting SAML token (signed one). I am using SAML
1.0. My problem is - how do I refer to the saml token as the URI in
ds:Reference element under the ds:Signature/ds:SignedInfo element ? It is
unable to refer/resolve to the URI attr in ds:Reference. I have tried to
follow the oasis doc
http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.0.pdf. I am
attaching the signed saml token for reference here (that was generated by
opensaml):
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/"
xmlns:cli="http://client.sts.sit.com"
xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">
<soapenv:Header>
<wsse:Security
xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd">
<saml:Assertion xmlns="urn:oasis:names:tc:SAML:1.0:assertion"
xmlns:saml="urn:oasis:names:tc:SAML:1.0:assertion"
xmlns:xsd="http://www.w3.org/2001/XMLSchema"
xmlns:samlp="urn:oasis:names:tc:SAML:1.0:protocol"
AssertionID="a17f470355aaafe584e215960eb57896" id="id-skjhskjh"
IssueInstant="2008-07-17T09:35:05.629Z" Issuer="SmartInternetTechnology"
MajorVersion="1" MinorVersion="1"><Conditions
NotBefore="2008-07-17T09:35:05.608Z"
NotOnOrAfter="2008-07-17T10:35:05.608Z"/><AuthenticationStatement
AuthenticationInstant="2008-07-17T09:35:05.608Z"
AuthenticationMethod="urn:oasis:names:tc:SAML:1.0:am:password"><Subject><NameIdentifier
Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">arun</NameIdentifier><SubjectConfirmation><ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:holder-of-key</ConfirmationMethod></SubjectConfirmation></Subject></AuthenticationStatement><AttributeStatement><Subject><NameIdentifier
Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">a
run</NameIdentifier><SubjectConfirmation><ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:holder-of-key</ConfirmationMethod></SubjectConfirmation></Subject><Attribute
AttributeName="telephoneNumber"
AttributeNamespace="telephoneNumber"><AttributeValue>a</AttributeValue></Attribute></AttributeStatement><ds:Signature
xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:CanonicalizationMethod
Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n-20010315"
xmlns:ds="http://www.w3.org/2000/09/xmldsig#"/>
<ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"
xmlns:ds="http://www.w3.org/2000/09/xmldsig#"/>
<ds:Reference URI="#STR1" xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:Transforms xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:Transform
Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"
xmlns:ds="http://www.w3.org/2000/09/xmldsig#"/>
<ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"
xmlns:ds="http://www.w3.org/2000/09/xmldsig#"/>
</ds:Transforms>
<ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"
xmlns:ds="http://www.w3.org/2000/09/xmldsig#"/>
<ds:DigestValue
xmlns:ds="http://www.w3.org/2000/09/xmldsig#">Gfvi4g54sSjmiQe7Tmvoa6g2pAE=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
c/Lnfh/qovW+TeNlyzDzhr84Zd1fDGst2Y6YXSL8SFnUXp85XEu0J20JER0nbOnCLIbjfKft+R4l
42hnFJ9QZnxzDLRe640EGc3zg6WhK7T4NOqbRpNu6TcOG5B8U3D4p+iYIZxuCCMmQDlGIklv9FQp
+A7LB31Z2k6bFA0FJ7w=
</ds:SignatureValue>
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Certificate xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
MIIDhTCCAm2gAwIBAgIKTDRbXQAAAAAF1DANBgkqhkiG9w0BAQUFADA/MRYwFAYDVQQKEw1DaXNj
byBTeXN0ZW1zMSUwIwYDVQQDExxDaXNjbyBNYW51ZmFjdHVyaW5nIENBIC0gREVWMB4XDTA2MDQx
OTE5NDE0MFoXDTE2MDQxOTE5NTE0MFowGDEWMBQGA1UEAxMNMTcyLjIyLjUwLjIzODCBnzANBgkq
hkiG9w0BAQEFAAOBjQAwgYkCgYEApooVXn6aDM0YpWF08Fy0W5Bfz8S6UCFmVNM82VLkNLUOtdGd
jw1DEY5HZgGHJijg/w9wYm+f1NmR/nH/9eov1OKFJC7GQXErgwcH/5QmJjJJ4Gk2wnWS26N7iV6g
ITnH62R0Y7tU+uDTP3xGqAfArmeWKBDhFfPz5mZAG8NS0TcCAwEAAaOCASwwggEoMA4GA1UdDwEB
/wQEAwIFoDAdBgNVHQ4EFgQUtxIdQjnvqw1muNdXWmb1KRvjrIIwHwYDVR0jBBgwFoAU8R0e7bZj
lmIxjH4A3UDYCjBMZigwQwYDVR0fBDwwOjA4oDagNIYyaHR0cDovL3d3dy5jaXNjby5jb20vc2Vj
dXJpdHkvcGtpL2NybC9jbWNhLWRldi5jcmwwUAYIKwYBBQUHAQEERDBCMEAGCCsGAQUFBzAChjRo
dHRwOi8vd3d3LmNpc2NvLmNvbS9zZWN1cml0eS9wa2kvY2VydHMvY21jYS1kZXYuY2VyMD8GCSsG
AQQBgjcUAgQyHjAASQBQAFMARQBDAEkAbgB0AGUAcgBtAGUAZABpAGEAdABlAE8AZgBmAGwAaQBu
AGUwDQYJKoZIhvcNAQEFBQADggEBAC4Kq9jGxSZDxmFfojHXtJcr1Wn2e4KWtXeJU+8St9BtBbry
3EfHP+2grQE0NSHVjZbvfnejU30xbi+DuwYv0NdLQDQBPPHwcsfv7FT9CbfTcEaaCPu6fGaX69Sx
Mpca0Ciaqw7EmkFEzZFB/zPijTqMM/Tn3UN+0xu9xB8HAObSLdmMSZVvZhRLFGwMMhi0pSDPYCY7
3tmASVHR9rpl1t0JZi44zuvrLDo+VmZ6IejMN9oDc9fyQBPtIEBpdygvfp9toJJAXE5oeZG6XZYz
eu7rBP6IzB4puPkNCIMKt9kWWMIUZ+ZnC1E8752N3bZprUyIPhfjVjGq1nPjOnYplcM=
</ds:X509Certificate>
</ds:X509Data>
<ds:KeyValue xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:RSAKeyValue xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:Modulus xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
pooVXn6aDM0YpWF08Fy0W5Bfz8S6UCFmVNM82VLkNLUOtdGdjw1DEY5HZgGHJijg/w9wYm+f1NmR
/nH/9eov1OKFJC7GQXErgwcH/5QmJjJJ4Gk2wnWS26N7iV6gITnH62R0Y7tU+uDTP3xGqAfArmeW
KBDhFfPz5mZAG8NS0Tc=
</ds:Modulus>
<ds:Exponent xmlns:ds="http://www.w3.org/2000/09/xmldsig#">AQAB</ds:Exponent>
</ds:RSAKeyValue>
</ds:KeyValue>
</ds:KeyInfo>
</ds:Signature></saml:Assertion>
<wsse:SecurityTokenReference wsu:Id="STR1">
<saml:AuthorityBinding xmlns:saml="urn:oasis:names:tc:SAML:1.0:assertion">
Binding=urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding
Location=http://www.opensaml.org/SAML-Authority
AuthorityKind= samlp:AssertionIdReference
</saml:AuthorityBinding>
<wsse:KeyIdentifier wsu:Id="key11"
ValueType="http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.0#SAMLAssertionID">a17f470355aaafe584e215960eb57896</wsse:KeyIdentifier>
</wsse:SecurityTokenReference>
</wsse:Security>
</soapenv:Header>
<soapenv:Body>
</soapenv:Body>
</soapenv:Envelope>
- Unable to extract SAML token, sburnwal, 07/31/2008
- RE: [OpenSAML] Unable to extract SAML token, Scott Cantor, 07/31/2008
- Re: [OpenSAML] Unable to extract SAML token, Tom Scavo, 07/31/2008
- RE: [OpenSAML] Unable to extract SAML token, Scott Cantor, 07/31/2008
Archive powered by MHonArc 2.6.16.