I wouldn’t be surprised if you discovered a bug in the way CAS handles encryption. Short of making sure you’re using the right credentials, best bet would be to step through the sequence of operations, see how the encrypter works and cross-check the order and sanity of ops with your client.
-- Misagh From: Todd Pratt <[email protected]> Reply: [email protected] <[email protected]> Date: January 17, 2017 at 7:33:53 PM To: CAS Community <[email protected]> Subject: [cas-user] CAS 5.0 SAML2 Response Decryption Hi, I'm having an issue getting the SAML2 response to decrypt. It all works when it's just signed but once I enable encryption I can't decrypt the assertions from the client. I'm using opensaml from java and below is the method I'm using to decrypt. The credentials are built from a keystore which I exported my public key from that I have in the metadata file. I have used this code before with other IdP's. I've also included the log messages below, metadata file and service provider files. Any help would be greatly appreciated. public static Assertion decryptEncryptedAssertion(EncryptedAssertion encryptedAssertion, Credential credentials) throws DecryptionException, CertificateException, IOException { StaticKeyInfoCredentialResolver staticKeyResolver = new StaticKeyInfoCredentialResolver(credentials); InlineEncryptedKeyResolver inlineEncryptedKeyResolver = new InlineEncryptedKeyResolver(); Decrypter decrypter = new Decrypter(null, staticKeyResolver, inlineEncryptedKeyResolver); return decrypter.decrypt(encryptedAssertion); } DEBUG [org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] - <Attempting to encrypt [org.opensaml.saml.saml2.core.impl.AssertionImpl] for [http://172.24.98.169:8080/saml_test2]> 2017-01-17 10:51:06,398 DEBUG [org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] - <Encryption blacklisted algorithms: [[http://www.w3.org/2001/04/xmlenc#rsa-1_5]]> 2017-01-17 10:51:06,398 DEBUG [org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] - <Encryption key algorithms: [[http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p, http://www.w3.org/2001/04/xmlenc#kw-aes128, http://www.w3.org/2001/04/xmlenc#kw-aes192, http://www.w3.org/2001/04/xmlenc#kw-aes256, http://www.w3.org/2001/04/xmlenc#kw-tripledes]]> 2017-01-17 10:51:06,398 DEBUG [org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] - <Signature data algorithms: [[http://www.w3.org/2001/04/xmlenc#aes128-cbc, http://www.w3.org/2001/04/xmlenc#aes192-cbc, http://www.w3.org/2001/04/xmlenc#aes256-cbc, http://www.w3.org/2001/04/xmlenc#tripledes-cbc]]> 2017-01-17 10:51:06,399 DEBUG [org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] - <Encryption whitelisted algorithms: []> 2017-01-17 10:51:06,497 DEBUG [org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] - <Locating encryption key file from [/etc/cas/saml/idp-encryption.key]> 2017-01-17 10:51:06,497 DEBUG [org.apereo.cas.util.crypto.PrivateKeyFactoryBean] - <Attempting to read /etc/cas/saml/idp-encryption.key as PEM> 2017-01-17 10:51:06,536 DEBUG [org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] - <Locating encryption certificate file from [/etc/cas/saml/idp-encryption.crt]> 2017-01-17 10:51:06,537 DEBUG [org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] - <Created encryption credential> 2017-01-17 10:51:06,539 DEBUG [org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] - <Attempting to resolve the encryption key for entity id [http://172.24.98.169:8080/saml_test2]> 2017-01-17 10:51:06,539 DEBUG [org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] - <Key encryption algorithm for [http://172.24.98.169:8080/saml_test2] is [http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p]> 2017-01-17 10:51:06,540 DEBUG [org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] - <Data encryption algorithm for [http://172.24.98.169:8080/saml_test2] is [http://www.w3.org/2001/04/xmlenc#aes128-cbc]> 2017-01-17 10:51:06,545 DEBUG [org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] - <Attempting to encrypt [org.opensaml.saml.saml2.core.impl.AssertionImpl] for [http://172.24.98.169:8080/saml_test2] with key placement of [PEER]> 2017-01-17 10:51:06,599 DEBUG [org.apereo.cas.support.saml.web.idp.profile.builders.SamlProfileSamlResponseBuilder] - <Built assertion is encrypted, so the response will add it to the encrypted assertions collection> <?xml version="1.0" encoding="UTF-8"?> <EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xml="http://www.w3.org/XML/1998/namespace" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" entityID="http://172.24.98.169:8080/saml_test2"> <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> <Extensions> <shibmd:Scope regexp="false">http://172.24.98.169:8080/saml_test2</shibmd:Scope> </Extensions> <KeyDescriptor use="signing"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> ---- My Public Cert ---- </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </KeyDescriptor> <KeyDescriptor use="encryption"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> ---- My Public Cert ---- </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </KeyDescriptor> <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat> <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat> <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://cas.morleyweb.com:8443/cas/idp/profile/SAML2/POST/SLO"/> <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://cas.morleyweb.com:8443/cas/idp/profile/SAML2/POST/SSO"/> <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://cas.morleyweb.com:8443/cas/idp/profile/SAML2/Redirect/SSO"/> <AssertionConsumerService isDefault="true" index="0" Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="http://172.24.98.169:8080/saml_test2/sso"/> </SPSSODescriptor> </EntityDescriptor> { @class: org.apereo.cas.support.saml.services.SamlRegisteredService serviceId: ^http://172.24.98.169:8080/saml_test2 name: SAMLTest id: 3032504042888199 description: SAML Testing evaluationOrder: 1 logoutType: NONE attributeReleasePolicy: { @class: org.apereo.cas.services.ReturnAllAttributeReleasePolicy principalAttributesRepository: { @class: org.apereo.cas.authentication.principal.DefaultPrincipalAttributesRepository expiration: 2 timeUnit: HOURS } authorizedToReleaseCredentialPassword: false authorizedToReleaseProxyGrantingTicket: false } multifactorPolicy: { @class: org.apereo.cas.services.DefaultRegisteredServiceMultifactorPolicy failureMode: CLOSED } accessStrategy: { @class: org.apereo.cas.services.DefaultRegisteredServiceAccessStrategy enabled: true ssoEnabled: true requireAllAttributes: false caseInsensitive: false } metadataLocation: /etc/cas/saml/saml_test2.xml metadataMaxValidity: 0 signAssertions: false signResponses: true encryptAssertions: true metadataCriteriaRoles: SPSSODescriptor metadataCriteriaRemoveEmptyEntitiesDescriptors: false metadataCriteriaRemoveRolelessEntityDescriptors: false } -- - CAS gitter chatroom: https://gitter.im/apereo/cas - CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html - CAS documentation website: https://apereo.github.io/cas - CAS project website: https://github.com/apereo/cas --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/b66a03c4-e1ba-4335-a6ff-b34cfcb325ed%40apereo.org. -- - CAS gitter chatroom: https://gitter.im/apereo/cas - CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html - CAS documentation website: https://apereo.github.io/cas - CAS project website: https://github.com/apereo/cas --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/etPan.587e951b.22c66492.5e2e%40unicon.net.
