mace-opensaml-users - RE: Digital signature not valid
Subject: OpenSAML user discussion
List archive
- From: "Ravi Balasubramanian" <>
- To: <>
- Subject: RE: Digital signature not valid
- Date: Fri, 28 Aug 2009 08:45:08 -0400
I am generating a SAML response with
digital signature and my x509certificate data. Trying to validate the digital
signature using http://www.aleksey.com/xmlsec/xmldsig-verifier.html Having two issues:
KeyStore ks =
KeyStore.getInstance(KeyStore.getDefaultType());
char[] password =
"xxxxxx".toCharArray();
FileInputStream fis = new
FileInputStream("c:/keystore/test.ks");
ks.load(fis, password);
fis.close();
char[] achKeyStorePass = password;
String keyAlias =
"mytestkey";
PrivateKey pk = (PrivateKey)
ks.getKey(keyAlias,achKeyStorePass);
X509Certificate certificate =
(X509Certificate) ks.getCertificate(keyAlias);
BasicX509Credential credential = new
BasicX509Credential();
credential.setEntityCertificate(certificate);
credential.setPrivateKey(pk);
Signature signature = (new
SignatureBuilder()).buildObject();
Namespace signNS = new
Namespace("http://www.w3.org/2009/09/xmldsig#",
"");
signature.addNamespace(signNS);
signature.setSigningCredential(credential);
signature.setSignatureAlgorithm(SignatureConstants.ALGO_ID_SIGNATURE_RSA);
signature.setCanonicalizationAlgorithm(SignatureConstants.ALGO_ID_C14N_OMIT_COMMENTS);
KeyInfo keyinfo = (new
KeyInfoBuilder()).buildObject(KeyInfo.DEFAULT_ELEMENT_NAME);
KeyInfoHelper.addCertificate(keyinfo, certificate);
SecurityHelper.prepareSignatureParams(signature,credential, null, null);
assertion.setSignature(signature); The code generates signature but when
validating, says not able to validate. |
- XACMLPolicyQuery target, Massimiliano Masi, 08/27/2009
- Re: [OpenSAML] XACMLPolicyQuery target, HÃ¥kon Sagehaug, 08/27/2009
- Message not available
- RE: Digital signature not valid, Ravi Balasubramanian, 08/28/2009
- Re: [OpenSAML] RE: Digital signature not valid, Chad La Joie, 08/28/2009
- RE: [OpenSAML] RE: Digital signature not valid, Ravi Balasubramanian, 08/28/2009
- RE: [OpenSAML] RE: Digital signature not valid, Scott Cantor, 08/28/2009
- RE: [OpenSAML] RE: Digital signature not valid, Ravi Balasubramanian, 08/28/2009
- RE: [OpenSAML] RE: Digital signature not valid, Scott Cantor, 08/28/2009
- RE: [OpenSAML] RE: Digital signature not valid, Ravi Balasubramanian, 08/28/2009
- RE: [OpenSAML] RE: Digital signature not valid, Scott Cantor, 08/28/2009
- Message not available
- Re: [OpenSAML] RE: Digital signature not valid, Deena Gurajala, 08/28/2009
- RE: [OpenSAML] RE: Digital signature not valid, Ravi Balasubramanian, 08/28/2009
- Re: [OpenSAML] RE: Digital signature not valid, Deena Gurajala, 08/28/2009
- RE: [OpenSAML] RE: Digital signature not valid, Scott Cantor, 08/28/2009
- RE: [OpenSAML] RE: Digital signature not valid, Ravi Balasubramanian, 08/28/2009
- Re: [OpenSAML] RE: Digital signature not valid, Chad La Joie, 08/28/2009
- RE: Digital signature not valid, Ravi Balasubramanian, 08/28/2009
- Message not available
- Re: [OpenSAML] XACMLPolicyQuery target, HÃ¥kon Sagehaug, 08/27/2009
Archive powered by MHonArc 2.6.16.