RE: Browser Post - ConsumeResponse query
"killian davies" <[email protected]> Fri, 15 Apr 2005 14:06:08 +0100
| Newsgroups | gmane.comp.sourceid.sso.user |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. ------=_NextPart_000_0031_01C541C4.467586F0 Content-Type: multipart/alternative; boundary="----=_NextPart_001_0032_01C541C4.46770D90" ------=_NextPart_001_0032_01C541C4.46770D90 Content-Type: text/plain; charset="US-ASCII" Content-Transfer-Encoding: 7bit The assertion doc is attached. As I understand, in this context ConsumeResponse is verifying the signature of the authentication response assertion that has been Post-ed. Can I ask, is signing and verifying recommended with the artifact approach? I seem to be able to get lots of detail on SAML use cases on the web but little discussion of the pros/cons of using post vs artifact. Is the advantage with artifact primarily preventing replay attacks without the requirement for time tolerances? Thanks, Killian _____ From: [email protected] [mailto:[email protected]] On Behalf Of David Waite Sent: 14 April 2005 17:52 To: SourceID Users List Subject: Re: [SourceID SSO-users] Browser Post - ConsumeResponse query On Apr 14, 2005, at 3:20 AM, killian davies wrote: Hi, I have been using the .NET implementation. I have had a problem with the following the "ConsumeResponse" method of the AutnRequestor class (using browser post). The validation of the signature in the response (authentication response) was always returning true because "response_doc["Signature", SignedXml.XmlDsigNamespaceUrl]" was always returning null - the XPath expr wasn't matching it. I changed to use the XmlNamespaceManager with all relevant namespaces added and this does now locate the Signature element. I'll look into this - thanks! Could you possibly send me an example of the document, because I do not understand the circumstance at which this is supposed to fail. The XPath expression below is incorrect, because the location of the Signature within the response document is meant to trigger different processing logic. It is currently attempting to verify the sig but I'm always getting false back (possibly because i have updated my project to use WSE2 (bad idea - not b'ward compatible with WSE1) - am not sure that this is the reason?) WSE 2 at some point forked all of the System.Security.Cryptography classes and interfaces - before it just had forked versions of the .Xml and .X509 classes. This means you either go completely with the WSE 2 version of the security classes, or you stay away completely. We are wrapping up a new release now which still uses WSE 1, but I imagine any release following will be against the .Net Framework 2.0, and will cut the dependancies on WSE and the Mentalis library. ------=_NextPart_001_0032_01C541C4.46770D90 Content-Type: text/html; charset="US-ASCII" Content-Transfer-Encoding: quoted-printable <html xmlns:v=3D"urn:schemas-microsoft-com:vml" = xmlns:o=3D"urn:schemas-microsoft-com:office:office" = xmlns:w=3D"urn:schemas-microsoft-com:office:word" = xmlns=3D"http://www.w3.org/TR/REC-html40"> <head> <meta http-equiv=3DContent-Type content=3D"text/html; = charset=3Dus-ascii"> <meta name=3DGenerator content=3D"Microsoft Word 11 (filtered medium)"> <!--[if !mso]> <style> v\:* {behavior:url(#default#VML);} o\:* {behavior:url(#default#VML);} w\:* {behavior:url(#default#VML);} .shape {behavior:url(#default#VML);} </style> <![endif]--> <style> <!-- /* Font Definitions */ @font-face {font-family:Tahoma; panose-1:2 11 6 4 3 5 4 4 2 4;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0in; margin-bottom:.0001pt; font-size:12.0pt; font-family:"Times New Roman";} a:link, span.MsoHyperlink {color:blue; text-decoration:underline;} a:visited, span.MsoHyperlinkFollowed {color:purple; text-decoration:underline;} span.EmailStyle18 {mso-style-type:personal-reply; font-family:Arial; color:navy;} @page Section1 {size:8.5in 11.0in; margin:1.0in 1.25in 1.0in 1.25in;} div.Section1 {page:Section1;} --> </style> </head> <body lang=3DEN-US link=3Dblue vlink=3Dpurple style=3D'word-wrap: = break-word; -khtml-nbsp-mode: space;-khtml-line-break: after-white-space'> <div class=3DSection1> <p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span = style=3D'font-size: 10.0pt;font-family:Arial;color:navy'>The assertion doc is attached. As I understand, in this context ConsumeResponse is verifying the signature = of the authentication response assertion that has been Post-ed. = <o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span = style=3D'font-size: 10.0pt;font-family:Arial;color:navy'><o:p> </o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span = style=3D'font-size: 10.0pt;font-family:Arial;color:navy'>Can I ask, is signing and verifying = recommended with the artifact approach? I seem to be able to get lots of detail on = SAML use cases on the web but little discussion of the pros/cons of using post vs artifact. Is the advantage with artifact primarily preventing replay = attacks without the requirement for time tolerances?<o:p></o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span = style=3D'font-size: 10.0pt;font-family:Arial;color:navy'><o:p> </o:p></span></font></p> <p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span = style=3D'font-size: 10.0pt;font-family:Arial;color:navy'>Thanks,<o:p></o:p></span></font></p>= <p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span = style=3D'font-size: 10.0pt;font-family:Arial;color:navy'>Killian<o:p></o:p></span></font></p>= <p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span = style=3D'font-size: 10.0pt;font-family:Arial;color:navy'><o:p> </o:p></span></font></p> <div> <div class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><font = size=3D3 face=3D"Times New Roman"><span style=3D'font-size:12.0pt'> <hr size=3D2 width=3D"100%" align=3Dcenter tabindex=3D-1> </span></font></div> <p class=3DMsoNormal><b><font size=3D2 face=3DTahoma><span = style=3D'font-size:10.0pt; font-family:Tahoma;font-weight:bold'>From:</span></font></b><font = size=3D2 face=3DTahoma><span style=3D'font-size:10.0pt;font-family:Tahoma'> [email protected] [mailto:[email protected]] = <b><span style=3D'font-weight:bold'>On Behalf Of </span></b>David Waite<br> <b><span style=3D'font-weight:bold'>Sent:</span></b> 14 April 2005 = 17:52<br> <b><span style=3D'font-weight:bold'>To:</span></b> SourceID Users = List<br> <b><span style=3D'font-weight:bold'>Subject:</span></b> Re: [SourceID = SSO-users] Browser Post - ConsumeResponse query</span></font><o:p></o:p></p> </div> <p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span = style=3D'font-size: 12.0pt'><o:p> </o:p></span></font></p> <p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span = style=3D'font-size: 12.0pt'><o:p> </o:p></span></font></p> <div> <div> <p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span = style=3D'font-size: 12.0pt'>On Apr 14, 2005, at 3:20 AM, killian davies = wrote:<o:p></o:p></span></font></p> </div> <p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span = style=3D'font-size: 12.0pt'><br> <br> <o:p></o:p></span></font></p> <div> <p class=3DMsoNormal = style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><font size=3D3 face=3D"Times New Roman"><span = style=3D'font-size:12.0pt'>Hi,<O:P></O:P><o:p></o:p></span></font></p> <p class=3DMsoNormal = style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><font size=3D3 face=3D"Times New Roman"><span style=3D'font-size:12.0pt'>I = have been using the .NET implementation.<O:P></O:P><o:p></o:p></span></font></p> <p class=3DMsoNormal = style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><font size=3D3 face=3D"Times New Roman"><span style=3D'font-size:12.0pt'>I = have had a problem with the following the "ConsumeResponse" method of the AutnRequestor class (using browser = post).<O:P></O:P><o:p></o:p></span></font></p> <p class=3DMsoNormal = style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><font size=3D3 face=3D"Times New Roman"><span style=3D'font-size:12.0pt'>The = validation of the signature in the response (authentication response) was always = returning true because "<font color=3Dgreen><span = style=3D'color:green'>response_doc["Signature", SignedXml.XmlDsigNamespaceUrl]" was always returning null - the = XPath expr wasn't matching = it.<O:P></O:P></span></font><o:p></o:p></span></font></p> <p class=3DMsoNormal = style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><font size=3D3 color=3Dgreen face=3D"Times New Roman"><span = style=3D'font-size:12.0pt; color:green'>I changed to use the XmlNamespaceManager with all relevant namespaces added and this does now locate the = Signature element.</span></font><o:p></o:p></p> </div> <p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span = style=3D'font-size: 12.0pt'>I'll look into this - thanks! Could you possibly send me an = example of the document, because I do not understand the circumstance at which this = is supposed to fail. The XPath expression below is incorrect, because the = location of the Signature within the response document is meant to trigger = different processing logic.<br> <br> <o:p></o:p></span></font></p> <div> <p class=3DMsoNormal = style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><O:P></O:P><= font size=3D3 color=3Dgreen face=3D"Times New Roman"><span = style=3D'font-size:12.0pt; color:green'>It is currently attempting to verify the sig but I'm always = getting false back (possibly because i have updated my project to use WSE2 (bad = idea - not b'ward compatible with WSE1) – am not sure that this is the = reason?)</span></font><o:p></o:p></p> </div> <p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span = style=3D'font-size: 12.0pt'>WSE 2 at some point forked all of the = System.Security.Cryptography classes and interfaces - before it just had forked versions of the .Xml = and .X509 classes. This means you either go completely with the WSE 2 = version of the security classes, or you stay away completely. We are wrapping up a = new release now which still uses WSE 1, but I imagine any release following = will be against the .Net Framework 2.0, and will cut the dependancies on WSE and = the Mentalis library.<o:p></o:p></span></font></p> </div> </div> </body> </html> ------=_NextPart_001_0032_01C541C4.46770D90-- ------=_NextPart_000_0031_01C541C4.467586F0 Content-Type: text/xml; name="assertion.xml" Content-Transfer-Encoding: quoted-printable Content-Disposition: attachment; filename="assertion.xml" <?xml version=3D"1.0"?> <lib:AuthnResponse xmlns:samlp=3D"urn:oasis:names:tc:SAML:1.0:protocol"=20 xmlns:xsd=3D"http://www.w3.org/2001/XMLSchema"=20 xmlns:sourceid=3D"http://www.sourceid.org/schemas/sso/providers/2002/11" = xmlns:saml=3D"urn:oasis:names:tc:SAML:1.0:assertion"=20 xmlns:xsi=3D"http://www.w3.org/2001/XMLSchema-instance"=20 xmlns:ac=3D"http://projectliberty.org/schemas/authctx/2002/05"=20 ResponseID=3D"idU0KREA=3D=3D" InResponseTo=3D"idajQVjQ=3D=3D"=20 MajorVersion=3D"1" MinorVersion=3D"0" Recipient=3D"Sample SourceID.NET = Service Provider"=20 IssueInstant=3D"2005-04-13T09:07:12Z" = xmlns:lib=3D"http://projectliberty.org/schemas/core/2002/12"> <samlp:Status><samlp:StatusCode Value=3D"samlp:Success" = /></samlp:Status><saml:Assertion=20 xsi:type=3D"lib:AssertionType" MajorVersion=3D"1" MinorVersion=3D"0" = AssertionID=3D"id10+qAA=3D=3D"=20 Issuer=3D"SourceID.NET Sample IDP" IssueInstant=3D"2005-04-13T09:07:12Z" = InResponseTo=3D"idajQVjQ=3D=3D" id=3D"id10+qAA=3D=3D"><saml:Conditions = NotBefore=3D"2005-04-13T09:06:12Z"=20 NotOnOrAfter=3D"2005-04-13T09:12:12Z"><saml:AudienceRestrictionCondition>= <saml:Audience>Sample SourceID.NET Service = Provider</saml:Audience></saml:AudienceRestrictionCondition> </saml:Conditions><saml:AuthenticationStatement = xsi:type=3D"lib:AuthenticationStatementType"=20 AuthenticationMethod=3D"urn:oasis:names:tc:SAML:1.0:am:password"=20 AuthenticationInstant=3D"2005-04-13T09:07:12Z" SessionIndex=3D"1"> <saml:Subject = xsi:type=3D"lib:SubjectType"><saml:NameIdentifier>idFoVu2Q=3D=3D</saml:Na= meIdentifier> <lib:IDPProvidedNameIdentifier>idFoVu2Q=3D=3D</lib:IDPProvidedNameIdentif= ier></saml:Subject> </saml:AuthenticationStatement><Signature = xmlns=3D"http://www.w3.org/2000/09/xmldsig#"> <SignedInfo><CanonicalizationMethod = Algorithm=3D"http://www.w3.org/TR/2001/REC-xml-c14n-20010315" /> <SignatureMethod = Algorithm=3D"http://www.w3.org/2000/09/xmldsig#rsa-sha1" /><Reference = URI=3D"#id10+qAA=3D=3D"> <Transforms><Transform = Algorithm=3D"http://www.w3.org/2000/09/xmldsig#enveloped-signature" = /></Transforms> <DigestMethod Algorithm=3D"http://www.w3.org/2000/09/xmldsig#sha1" /> <DigestValue>TSJ57ugMH6lfGECP0bt0SsR8vds=3D</DigestValue></Reference></Si= gnedInfo> <SignatureValue>Lp21zXsrVjeq6KiQHjo2+ZaEgqGOMQZHCNR0ivw3TtDzVRUrdHnbquo5g= 5o7ooJMdUUPJCu1rSolg1zfIixo61As/gr+b3Y6IlRMANsM/g36vmHWfr63STeIBskiIjL6kR= QiYMkubLeplYza1Ic6x6Ouw2U8sv8pZJGHSPMnS0k=3D</SignatureValue> </Signature></saml:Assertion><lib:ProviderID>SourceID.NET Sample = IDP</lib:ProviderID></lib:AuthnResponse> ------=_NextPart_000_0031_01C541C4.467586F0 Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ sso-users mailing list [email protected] http://lists.sourceid.org/mailman/listinfo/sso-users ------=_NextPart_000_0031_01C541C4.467586F0--