RE: Browser Post - ConsumeResponse query

"killian davies" <[email protected]> Fri, 15 Apr 2005 14:06:08 +0100
Newsgroups gmane.comp.sourceid.sso.user
Message-ID <[email protected]>
This is a multi-part message in MIME format.

------=_NextPart_000_0031_01C541C4.467586F0
Content-Type: multipart/alternative;
	boundary="----=_NextPart_001_0032_01C541C4.46770D90"


------=_NextPart_001_0032_01C541C4.46770D90
Content-Type: text/plain;
	charset="US-ASCII"
Content-Transfer-Encoding: 7bit

The assertion doc is attached. As I understand, in this context
ConsumeResponse is verifying the signature of the authentication response
assertion that has been Post-ed. 

 

Can I ask, is signing and verifying recommended with the artifact approach?
I seem to be able to get lots of detail on SAML use cases on the web but
little discussion of the pros/cons of using post vs artifact. Is the
advantage with artifact primarily preventing replay attacks without the
requirement for time tolerances?

 

Thanks,

Killian

 

  _____  

From: [email protected] [mailto:[email protected]]
On Behalf Of David Waite
Sent: 14 April 2005 17:52
To: SourceID Users List
Subject: Re: [SourceID SSO-users] Browser Post - ConsumeResponse query

 

 

On Apr 14, 2005, at 3:20 AM, killian davies wrote:





Hi,

I have been using the .NET implementation.

I have had a problem with the following the "ConsumeResponse" method of the
AutnRequestor class (using browser post).

The validation of the signature in the response (authentication response)
was always returning true because "response_doc["Signature",
SignedXml.XmlDsigNamespaceUrl]" was always returning null - the XPath expr
wasn't matching it.

I changed to use the XmlNamespaceManager with all relevant namespaces added
and this does now locate the Signature element.

I'll look into this - thanks! Could you possibly send me an example of the
document, because I do not understand the circumstance at which this is
supposed to fail. The XPath expression below is incorrect, because the
location of the Signature within the response document is meant to trigger
different processing logic.



It is currently attempting to verify the sig but I'm always getting false
back (possibly because i have updated my project to use WSE2 (bad idea - not
b'ward compatible with WSE1) - am not sure that this is the reason?)

WSE 2 at some point forked all of the System.Security.Cryptography classes
and interfaces - before it just had forked versions of the .Xml and .X509
classes. This means you either go completely with the WSE 2 version of the
security classes, or you stay away completely. We are wrapping up a new
release now which still uses WSE 1, but I imagine any release following will
be against the .Net Framework 2.0, and will cut the dependancies on WSE and
the Mentalis library.


------=_NextPart_001_0032_01C541C4.46770D90
Content-Type: text/html;
	charset="US-ASCII"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii">
<meta name=3DGenerator content=3D"Microsoft Word 11 (filtered medium)">
<!--[if !mso]>
<style>
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style>
<![endif]-->
<style>
<!--
 /* Font Definitions */
 @font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman";}
a:link, span.MsoHyperlink
	{color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{color:purple;
	text-decoration:underline;}
span.EmailStyle18
	{mso-style-type:personal-reply;
	font-family:Arial;
	color:navy;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
	{page:Section1;}
-->
</style>

</head>

<body lang=3DEN-US link=3Dblue vlink=3Dpurple style=3D'word-wrap: =
break-word;
-khtml-nbsp-mode: space;-khtml-line-break: after-white-space'>

<div class=3DSection1>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>The assertion doc is attached. As I
understand, in this context ConsumeResponse is verifying the signature =
of the
authentication response assertion that has been Post-ed. =
<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>Can I ask, is signing and verifying =
recommended
with the artifact approach? I seem to be able to get lots of detail on =
SAML use
cases on the web but little discussion of the pros/cons of using post vs
artifact. Is the advantage with artifact primarily preventing replay =
attacks without
the requirement for time tolerances?<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>Thanks,<o:p></o:p></span></font></p>=


<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>Killian<o:p></o:p></span></font></p>=


<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'><o:p>&nbsp;</o:p></span></font></p>

<div>

<div class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><font =
size=3D3
face=3D"Times New Roman"><span style=3D'font-size:12.0pt'>

<hr size=3D2 width=3D"100%" align=3Dcenter tabindex=3D-1>

</span></font></div>

<p class=3DMsoNormal><b><font size=3D2 face=3DTahoma><span =
style=3D'font-size:10.0pt;
font-family:Tahoma;font-weight:bold'>From:</span></font></b><font =
size=3D2
face=3DTahoma><span style=3D'font-size:10.0pt;font-family:Tahoma'>
[email protected] [mailto:[email protected]] =
<b><span
style=3D'font-weight:bold'>On Behalf Of </span></b>David Waite<br>
<b><span style=3D'font-weight:bold'>Sent:</span></b> 14 April 2005 =
17:52<br>
<b><span style=3D'font-weight:bold'>To:</span></b> SourceID Users =
List<br>
<b><span style=3D'font-weight:bold'>Subject:</span></b> Re: [SourceID =
SSO-users]
Browser Post - ConsumeResponse query</span></font><o:p></o:p></p>

</div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><o:p>&nbsp;</o:p></span></font></p>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>On Apr 14, 2005, at 3:20 AM, killian davies =
wrote:<o:p></o:p></span></font></p>

</div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><br>
<br>
<o:p></o:p></span></font></p>

<div>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><font
size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:12.0pt'>Hi,<O:P></O:P><o:p></o:p></span></font></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><font
size=3D3 face=3D"Times New Roman"><span style=3D'font-size:12.0pt'>I =
have been using
the .NET implementation.<O:P></O:P><o:p></o:p></span></font></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><font
size=3D3 face=3D"Times New Roman"><span style=3D'font-size:12.0pt'>I =
have had a
problem with the following the &quot;ConsumeResponse&quot; method of the
AutnRequestor class (using browser =
post).<O:P></O:P><o:p></o:p></span></font></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><font
size=3D3 face=3D"Times New Roman"><span style=3D'font-size:12.0pt'>The =
validation of
the signature in the response (authentication response) was always =
returning
true because &quot;<font color=3Dgreen><span =
style=3D'color:green'>response_doc[&quot;Signature&quot;,
SignedXml.XmlDsigNamespaceUrl]&quot; was always returning null - the =
XPath expr
wasn't matching =
it.<O:P></O:P></span></font><o:p></o:p></span></font></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><font
size=3D3 color=3Dgreen face=3D"Times New Roman"><span =
style=3D'font-size:12.0pt;
color:green'>I changed to use the XmlNamespaceManager&nbsp;with&nbsp;all
relevant&nbsp;namespaces added and this does now&nbsp;locate&nbsp;the =
Signature
element.</span></font><o:p></o:p></p>

</div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>I'll look into this - thanks! Could you possibly send me an =
example of
the document, because I do not understand the circumstance at which this =
is
supposed to fail. The XPath expression below is incorrect, because the =
location
of the Signature within the response document is meant to trigger =
different
processing logic.<br>
<br>
<o:p></o:p></span></font></p>

<div>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><O:P></O:P><=
font
size=3D3 color=3Dgreen face=3D"Times New Roman"><span =
style=3D'font-size:12.0pt;
color:green'>It is currently attempting to verify the sig but I'm always =
getting
false back (possibly because i have updated my project to use WSE2 (bad =
idea -
not b'ward compatible with WSE1) &#8211; am not sure that this is the =
reason?)</span></font><o:p></o:p></p>

</div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>WSE 2 at some point forked all of the =
System.Security.Cryptography
classes and interfaces - before it just had forked versions of the .Xml =
and
.X509 classes. This means you either go completely with the WSE 2 =
version of
the security classes, or you stay away completely. We are wrapping up a =
new
release now which still uses WSE 1, but I imagine any release following =
will be
against the .Net Framework 2.0, and will cut the dependancies on WSE and =
the
Mentalis library.<o:p></o:p></span></font></p>

</div>

</div>

</body>

</html>

------=_NextPart_001_0032_01C541C4.46770D90--

------=_NextPart_000_0031_01C541C4.467586F0
Content-Type: text/xml;
	name="assertion.xml"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: attachment;
	filename="assertion.xml"

<?xml version=3D"1.0"?>
<lib:AuthnResponse xmlns:samlp=3D"urn:oasis:names:tc:SAML:1.0:protocol"=20
xmlns:xsd=3D"http://www.w3.org/2001/XMLSchema"=20
xmlns:sourceid=3D"http://www.sourceid.org/schemas/sso/providers/2002/11" =

xmlns:saml=3D"urn:oasis:names:tc:SAML:1.0:assertion"=20
xmlns:xsi=3D"http://www.w3.org/2001/XMLSchema-instance"=20
xmlns:ac=3D"http://projectliberty.org/schemas/authctx/2002/05"=20
ResponseID=3D"idU0KREA=3D=3D" InResponseTo=3D"idajQVjQ=3D=3D"=20
MajorVersion=3D"1" MinorVersion=3D"0" Recipient=3D"Sample SourceID.NET =
Service Provider"=20
IssueInstant=3D"2005-04-13T09:07:12Z" =
xmlns:lib=3D"http://projectliberty.org/schemas/core/2002/12">
<samlp:Status><samlp:StatusCode Value=3D"samlp:Success" =
/></samlp:Status><saml:Assertion=20
xsi:type=3D"lib:AssertionType" MajorVersion=3D"1" MinorVersion=3D"0" =
AssertionID=3D"id10+qAA=3D=3D"=20
Issuer=3D"SourceID.NET Sample IDP" IssueInstant=3D"2005-04-13T09:07:12Z" =

InResponseTo=3D"idajQVjQ=3D=3D" id=3D"id10+qAA=3D=3D"><saml:Conditions =
NotBefore=3D"2005-04-13T09:06:12Z"=20
NotOnOrAfter=3D"2005-04-13T09:12:12Z"><saml:AudienceRestrictionCondition>=

<saml:Audience>Sample SourceID.NET Service =
Provider</saml:Audience></saml:AudienceRestrictionCondition>
</saml:Conditions><saml:AuthenticationStatement =
xsi:type=3D"lib:AuthenticationStatementType"=20
AuthenticationMethod=3D"urn:oasis:names:tc:SAML:1.0:am:password"=20
AuthenticationInstant=3D"2005-04-13T09:07:12Z" SessionIndex=3D"1">
<saml:Subject =
xsi:type=3D"lib:SubjectType"><saml:NameIdentifier>idFoVu2Q=3D=3D</saml:Na=
meIdentifier>
<lib:IDPProvidedNameIdentifier>idFoVu2Q=3D=3D</lib:IDPProvidedNameIdentif=
ier></saml:Subject>
</saml:AuthenticationStatement><Signature =
xmlns=3D"http://www.w3.org/2000/09/xmldsig#">
<SignedInfo><CanonicalizationMethod =
Algorithm=3D"http://www.w3.org/TR/2001/REC-xml-c14n-20010315" />
<SignatureMethod =
Algorithm=3D"http://www.w3.org/2000/09/xmldsig#rsa-sha1" /><Reference =
URI=3D"#id10+qAA=3D=3D">
<Transforms><Transform =
Algorithm=3D"http://www.w3.org/2000/09/xmldsig#enveloped-signature" =
/></Transforms>
<DigestMethod Algorithm=3D"http://www.w3.org/2000/09/xmldsig#sha1" />
<DigestValue>TSJ57ugMH6lfGECP0bt0SsR8vds=3D</DigestValue></Reference></Si=
gnedInfo>
<SignatureValue>Lp21zXsrVjeq6KiQHjo2+ZaEgqGOMQZHCNR0ivw3TtDzVRUrdHnbquo5g=
5o7ooJMdUUPJCu1rSolg1zfIixo61As/gr+b3Y6IlRMANsM/g36vmHWfr63STeIBskiIjL6kR=
QiYMkubLeplYza1Ic6x6Ouw2U8sv8pZJGHSPMnS0k=3D</SignatureValue>
</Signature></saml:Assertion><lib:ProviderID>SourceID.NET Sample =
IDP</lib:ProviderID></lib:AuthnResponse>
------=_NextPart_000_0031_01C541C4.467586F0
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
sso-users mailing list
[email protected]
http://lists.sourceid.org/mailman/listinfo/sso-users

------=_NextPart_000_0031_01C541C4.467586F0--