Hi, we are trying to replace our Shibboleth with CAS SAML2 IdP functionality. In our setup CAS is the IdP and ADFS 2.0 is the relying party.
Initiating the request seems to work even the response seems to be accepted from ADFS in the first place but the XML is not valid?! The Federation Service encountered an error while processing the WS-Trust request. Request type: http://schemas.xmlsoap.org/ws/2005/02/trust/RST/Issue Additional Data Exception details: System.Xml.XmlException: 'Element' is an invalid XmlNodeType. at System.Xml.XmlReader.ReadEndElement() at Microsoft.IdentityModel.Tokens.Saml2.Saml2SecurityTokenHandler. ReadAttribute(XmlReader reader) at Microsoft.IdentityModel.Tokens.Saml2.Saml2SecurityTokenHandler. ReadAttributeStatement(XmlReader reader) at Microsoft.IdentityModel.Tokens.Saml2.Saml2SecurityTokenHandler. ReadAssertion(XmlReader reader) at Microsoft.IdentityModel.Tokens.Saml2.Saml2SecurityTokenHandler. ReadToken(XmlReader reader) at Microsoft.IdentityModel.Tokens.SecurityTokenHandlerCollection. ReadToken(XmlReader reader) at Microsoft.IdentityModel.Tokens.SecurityTokenElement.ReadSecurityToken( XmlElement securityTokenXml, SecurityTokenHandlerCollection securityTokenHandlers) at Microsoft.IdentityModel.Tokens.SecurityTokenElement.GetSecurityToken() at Microsoft.IdentityServer.Service.Tokens. SamlMessageSecurityTokenHandler.ReadToken(XmlReader reader) at Microsoft.IdentityModel.Tokens.SecurityTokenHandlerCollection. ReadToken(XmlReader reader) at Microsoft.IdentityModel.Tokens.SecurityTokenElement.ReadSecurityToken( XmlElement securityTokenXml, SecurityTokenHandlerCollection securityTokenHandlers) at Microsoft.IdentityModel.Tokens.SecurityTokenElement.GetSecurityToken() at Microsoft.IdentityServer.Service.SecurityTokenService. MSISSecurityTokenService.GetOnBehalfOfPrincipal(RequestSecurityToken request , IClaimsPrincipal callerPrincipal) at Microsoft.IdentityServer.Service.SecurityTokenService. MSISSecurityTokenService.BeginGetScope(IClaimsPrincipal principal, RequestSecurityToken request, AsyncCallback callback, Object state) at Microsoft.IdentityModel.SecurityTokenService.SecurityTokenService. BeginIssue(IClaimsPrincipal principal, RequestSecurityToken request, AsyncCallback callback, Object state) at Microsoft.IdentityModel.Protocols.WSTrust.WSTrustServiceContract. DispatchRequestAsyncResult..ctor(DispatchContext dispatchContext, AsyncCallback asyncCallback, Object asyncState) at Microsoft.IdentityModel.Protocols.WSTrust.WSTrustServiceContract. BeginDispatchRequest(DispatchContext dispatchContext, AsyncCallback asyncCallback, Object asyncState) at Microsoft.IdentityModel.Protocols.WSTrust.WSTrustServiceContract. ProcessCoreAsyncResult..ctor(WSTrustServiceContract contract, DispatchContext dispatchContext, MessageVersion messageVersion, WSTrustResponseSerializer responseSerializer, WSTrustSerializationContext serializationContext, AsyncCallback asyncCallback, Object asyncState) at Microsoft.IdentityModel.Protocols.WSTrust.WSTrustServiceContract. BeginProcessCore(Message requestMessage, WSTrustRequestSerializer requestSerializer, WSTrustResponseSerializer responseSerializer, String requestAction, String responseAction, String trustNamespace, AsyncCallback callback, Object state) The following response is sent to ADFS: <?xml version="1.0" encoding="UTF-8"?> <saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Consent="urn:oasis:names:tc:SAML:2.0:consent:unspecified" ID="_5712367945321305809" InResponseTo="id-2f792815-f7e3-4c8a-9330-6b28163dbcc0" IssueInstant="2017-03-15T15:06:09.915Z" Version="2.0"> <saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">https://..../idp </saml2:Issuer> <saml2p:Status> <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/> <saml2p:StatusMessage>urn:oasis:names:tc:SAML:2.0:status:Success</saml2p:StatusMessage> </saml2p:Status> <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:xsd="http://www.w3.org/2001/XMLSchema" ID="_3048198097917129868" IssueInstant="2017-03-15T15:06:09.896Z" Version="2.0"> <saml2:Issuer>https://..../idp</saml2:Issuer> <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:SignedInfo> <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/> <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/> <ds:Reference URI="#_3048198097917129868"> <ds:Transforms> <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/> <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"> <ec:InclusiveNamespaces xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="xsd"/> </ds:Transform> </ds:Transforms> <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/> <ds:DigestValue>GQbmCPA99DH9lIfdnySXDqxYQfLuJGpnsco0t8lnEuA=</ds:DigestValue> </ds:Reference> </ds:SignedInfo> <ds:SignatureValue> CLgTqUpNHI+ThCIaQ+iI4++puLuCijAyjXGQnOgYE5zWjQlP0PBFmvbaTlDpaOd36I1E+NEP2cjB 22EbIf0XmL7Z6hqdtQE6wIa754SMVReG9jWG2MvrhVX/aU512Tzz4/6KAQ5IrpRMJ7sfC+y6ZbD6 PudR6QgLADL7daG4jnX7BykJ7FzoY1D2ktCKTgmaLnxwvBxW5leVH1adaRQHytdW1bFqRuAq7mPF kEyTEJ6MG+E1rXiKHY3dDJdYl3F2CBr+82xjMtt7E/HF0UaW0VbfnS/fcFf6oBUoQ0Ogcoc0hPOL EtP8FCraP2g4byjaPKpWscIJ5iZ3VMKjN8vrlQ== </ds:SignatureValue> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate>MIIDODCCAiCgAwIBAgIUacPILYM92afNNZNJgvi8C6VqxG0wDQYJKoZIhvcNAQELBQAwITEfMB0G A1UEAwwWZXh0cmFuZXQtcWFzLmJyb3NlLmNvbTAeFw0xNzAyMjQyMDE0MzVaFw0zNzAyMjQyMDE0 MzVaMCExHzAdBgNVBAMMFmV4dHJhbmV0LXFhcy5icm9zZS5jb20wggEiMA0GCSqGSIb3DQEBAQUA A4IBDwAwggEKAoIBAQCn8f4LB3U5/ZGLJnZP8bm2zCVg0SL0aeBAfNeiC59ChEKGHw93D+9Bwl7I AjffDcuRGK+SjKVX6m55A/3sCFp4GnsKNzdzxgDxStbADC4/fC4TYSaUG83qzpjLc776/Z9s/IDz SUZ7mTvcH3eusWctI+cRLRrGO/7qfg0Z6Blxppmtc0+/ZrfaPQ9Gtzt94GSY7KCNYecGcbvZXrkQ BpKYzoiu0ViECz6xNnRYKf1U3TCrZnwdkQe3v4HSr8xEMbMv0JOneSRQsfdzrPguwOxDkEU/pIEM Dqwy/MjZxAr5885GHgwqcD4X+vk2nscGasH4+R+HqLmeTvBRawW5eES5AgMBAAGjaDBmMB0GA1Ud DgQWBBT6DDaEyWBg/e5luv8yB5aJUZT9DjBFBgNVHREEPjA8ghZleHRyYW5ldC1xYXMuYnJvc2Uu Y29thiJleHRyYW5ldC1xYXMuYnJvc2UuY29taWRwL21ldGFkYXRhMA0GCSqGSIb3DQEBCwUAA4IB AQAFoqrOBTyGch0ga6kw//H01e6OWW4dYTEswsgg2Bc5EJKju5KDufcX0TiU3OaMGE6ebeLWjMYV JI8wbrWw4F0+sL0mV4fAmdSyvljDI1gTW6ZFbMmmKqYEqm6nfpncoX10TtuF4AEEEK8jsEHF9J74 hfnFwyws6y5Ph0ANGH7pobvJt5O+b3+fgOLrj1LcwEZui4rdbyYR29QlL0aXrol4MbJqwQHe8/1E sDthVUjX4Sz/BCxjJxAVRpQ862fGgLHTWFlI9maxkeNb+H9fJwgl6Yizslyczo0ZadezLlomvO90 Tg0M0CF9x7KkWA4wv+uW/K548ydHA4MH+sqj9skH </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </ds:Signature> <saml2:Subject> <saml2:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress">user@email </saml2:NameID> <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"> <saml2:SubjectConfirmationData InResponseTo="id-2f792815-f7e3-4c8a-9330-6b28163dbcc0" NotOnOrAfter="2017-03-15T15:07:09.885Z"/> </saml2:SubjectConfirmation> </saml2:Subject> <saml2:Conditions NotBefore="2017-03-15T15:06:09.899Z" NotOnOrAfter="2017-03-15T15:07:09.899Z"> <saml2:AudienceRestriction> <saml2:Audience>https://..../adfs/services/trust</saml2:Audience> </saml2:AudienceRestriction> </saml2:Conditions> <saml2:AuthnStatement AuthnInstant="2017-03-15T15:06:09.885Z"> <saml2:SubjectLocality Address="https://..../adfs/services/trust"/> <saml2:AuthnContext> <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified </saml2:AuthnContextClassRef> </saml2:AuthnContext> </saml2:AuthnStatement> <saml2:AttributeStatement> <saml2:Attribute FriendlyName="samlAuthenticationStatementAuthMethod" Name="samlAuthenticationStatementAuthMethod"> <saml1:AttributeValue xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string"> urn:oasis:names:tc:SAML:1.0:am:password </saml1:AttributeValue> </saml2:Attribute> <saml2:Attribute FriendlyName="uid" Name="uid"> <saml1:AttributeValue xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string"> user@email </saml1:AttributeValue> </saml2:Attribute> <saml2:Attribute FriendlyName="isFromNewLogin" Name="isFromNewLogin"> <saml1:AttributeValue xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">false </saml1:AttributeValue> </saml2:Attribute> <saml2:Attribute FriendlyName="authenticationDate" Name="authenticationDate"> <saml1:AttributeValue xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string"> 2017-03-15T16:06:09.734+01:00[Europe/Berlin] </saml1:AttributeValue> </saml2:Attribute> <saml2:Attribute FriendlyName="authenticationMethod" Name="authenticationMethod"> <saml1:AttributeValue xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string"> specialAuthenticator </saml1:AttributeValue> </saml2:Attribute> <saml2:Attribute FriendlyName="successfulAuthenticationHandlers" Name="successfulAuthenticationHandlers"> <saml1:AttributeValue xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string"> specialAuthenticator </saml1:AttributeValue> </saml2:Attribute> <saml2:Attribute FriendlyName="longTermAuthenticationRequestTokenUsed" Name="longTermAuthenticationRequestTokenUsed"> <saml1:AttributeValue xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">false </saml1:AttributeValue> </saml2:Attribute> </saml2:AttributeStatement> </saml2:Assertion> </saml2p:Response> Any help or hints are appreciated. Even debug logging on ADFS provides me any useful info. Best -- Robert -- - CAS gitter chatroom: https://gitter.im/apereo/cas - CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html - CAS documentation website: https://apereo.github.io/cas - CAS project website: https://github.com/apereo/cas --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/66ae8ede-ec43-4778-ba4f-b0bd7667c411%40apereo.org.
