Maybe I've found the issue but have to investigate more.
This part seems strange and was different in CAS 5.0.3.1.
<saml2:Attribute FriendlyName="uid" Name="uid">
<saml1:AttributeValue
xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">
user@email
</saml1:AttributeValue>
</saml2:Attribute>
I guess the <saml1:AttributeValue> should be <saml2:AttributeValue>.
Even our older version of Shibboleth responded like this:
<saml2:Attribute Name="uid"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml2:AttributeValue
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:type="xs:string">user@email</saml2:AttributeValue>
</saml2:Attribute>
So I have to find out why CAS 5.1.0-RC2 is returning saml1 attribute values
within a saml2 attribute tag.
On Wednesday, March 15, 2017 at 5:06:00 PM UTC+1, Robert Ledermüller wrote:
>
> Hi,
>
> we are trying to replace our Shibboleth with CAS SAML2 IdP functionality.
> In our setup CAS is the IdP and ADFS 2.0 is the relying party.
>
> Initiating the request seems to work even the response seems to be
> accepted from ADFS in the first place but the XML is not valid?!
>
>
> The Federation Service encountered an error while processing the WS-Trust
> request.
> Request type: http://schemas.xmlsoap.org/ws/2005/02/trust/RST/Issue
>
>
> Additional Data
> Exception details:
> System.Xml.XmlException: 'Element' is an invalid XmlNodeType.
> at System.Xml.XmlReader.ReadEndElement()
> at Microsoft.IdentityModel.Tokens.Saml2.Saml2SecurityTokenHandler.
> ReadAttribute(XmlReader reader)
> at Microsoft.IdentityModel.Tokens.Saml2.Saml2SecurityTokenHandler.
> ReadAttributeStatement(XmlReader reader)
> at Microsoft.IdentityModel.Tokens.Saml2.Saml2SecurityTokenHandler.
> ReadAssertion(XmlReader reader)
> at Microsoft.IdentityModel.Tokens.Saml2.Saml2SecurityTokenHandler.
> ReadToken(XmlReader reader)
> at Microsoft.IdentityModel.Tokens.SecurityTokenHandlerCollection.
> ReadToken(XmlReader reader)
> at Microsoft.IdentityModel.Tokens.SecurityTokenElement.
> ReadSecurityToken(XmlElement securityTokenXml,
> SecurityTokenHandlerCollection securityTokenHandlers)
> at Microsoft.IdentityModel.Tokens.SecurityTokenElement.GetSecurityToken
> ()
> at Microsoft.IdentityServer.Service.Tokens.
> SamlMessageSecurityTokenHandler.ReadToken(XmlReader reader)
> at Microsoft.IdentityModel.Tokens.SecurityTokenHandlerCollection.
> ReadToken(XmlReader reader)
> at Microsoft.IdentityModel.Tokens.SecurityTokenElement.
> ReadSecurityToken(XmlElement securityTokenXml,
> SecurityTokenHandlerCollection securityTokenHandlers)
> at Microsoft.IdentityModel.Tokens.SecurityTokenElement.GetSecurityToken
> ()
> at Microsoft.IdentityServer.Service.SecurityTokenService.
> MSISSecurityTokenService.GetOnBehalfOfPrincipal(RequestSecurityToken
> request, IClaimsPrincipal callerPrincipal)
> at Microsoft.IdentityServer.Service.SecurityTokenService.
> MSISSecurityTokenService.BeginGetScope(IClaimsPrincipal principal,
> RequestSecurityToken request, AsyncCallback callback, Object state)
> at Microsoft.IdentityModel.SecurityTokenService.SecurityTokenService.
> BeginIssue(IClaimsPrincipal principal, RequestSecurityToken request,
> AsyncCallback callback, Object state)
> at Microsoft.IdentityModel.Protocols.WSTrust.WSTrustServiceContract.
> DispatchRequestAsyncResult..ctor(DispatchContext dispatchContext,
> AsyncCallback asyncCallback, Object asyncState)
> at Microsoft.IdentityModel.Protocols.WSTrust.WSTrustServiceContract.
> BeginDispatchRequest(DispatchContext dispatchContext, AsyncCallback
> asyncCallback, Object asyncState)
> at Microsoft.IdentityModel.Protocols.WSTrust.WSTrustServiceContract.
> ProcessCoreAsyncResult..ctor(WSTrustServiceContract contract,
> DispatchContext dispatchContext, MessageVersion messageVersion,
> WSTrustResponseSerializer responseSerializer, WSTrustSerializationContext
> serializationContext, AsyncCallback asyncCallback, Object asyncState)
> at Microsoft.IdentityModel.Protocols.WSTrust.WSTrustServiceContract.
> BeginProcessCore(Message requestMessage, WSTrustRequestSerializer
> requestSerializer, WSTrustResponseSerializer responseSerializer, String
> requestAction, String responseAction, String trustNamespace, AsyncCallback
> callback, Object state)
>
>
> The following response is sent to ADFS:
>
> <?xml version="1.0" encoding="UTF-8"?>
> <saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"
> Consent="urn:oasis:names:tc:SAML:2.0:consent:unspecified"
> ID="_5712367945321305809"
> InResponseTo="id-2f792815-f7e3-4c8a-9330-6b28163dbcc0"
> IssueInstant="2017-03-15T15:06:09.915Z"
> Version="2.0">
> <saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
>
> Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">https://..../idp
> </saml2:Issuer>
> <saml2p:Status>
> <saml2p:StatusCode
> Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
>
> <saml2p:StatusMessage>urn:oasis:names:tc:SAML:2.0:status:Success</saml2p:StatusMessage>
> </saml2p:Status>
> <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
> xmlns:xsd="http://www.w3.org/2001/XMLSchema"
> ID="_3048198097917129868"
> IssueInstant="2017-03-15T15:06:09.896Z" Version="2.0">
> <saml2:Issuer>https://..../idp</saml2:Issuer>
> <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
> <ds:SignedInfo>
> <ds:CanonicalizationMethod
> Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
> <ds:SignatureMethod
> Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
> <ds:Reference URI="#_3048198097917129868">
> <ds:Transforms>
> <ds:Transform
> Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
> <ds:Transform
> Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#">
> <ec:InclusiveNamespaces
> xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#"
> PrefixList="xsd"/>
> </ds:Transform>
> </ds:Transforms>
> <ds:DigestMethod
> Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
>
> <ds:DigestValue>GQbmCPA99DH9lIfdnySXDqxYQfLuJGpnsco0t8lnEuA=</ds:DigestValue>
> </ds:Reference>
> </ds:SignedInfo>
> <ds:SignatureValue>
>
> CLgTqUpNHI+ThCIaQ+iI4++puLuCijAyjXGQnOgYE5zWjQlP0PBFmvbaTlDpaOd36I1E+NEP2cjB
>
> 22EbIf0XmL7Z6hqdtQE6wIa754SMVReG9jWG2MvrhVX/aU512Tzz4/6KAQ5IrpRMJ7sfC+y6ZbD6
>
> PudR6QgLADL7daG4jnX7BykJ7FzoY1D2ktCKTgmaLnxwvBxW5leVH1adaRQHytdW1bFqRuAq7mPF
>
> kEyTEJ6MG+E1rXiKHY3dDJdYl3F2CBr+82xjMtt7E/HF0UaW0VbfnS/fcFf6oBUoQ0Ogcoc0hPOL
> EtP8FCraP2g4byjaPKpWscIJ5iZ3VMKjN8vrlQ==
> </ds:SignatureValue>
> <ds:KeyInfo>
> <ds:X509Data>
>
> <ds:X509Certificate>MIIDODCCAiCgAwIBAgIUacPILYM92afNNZNJgvi8C6VqxG0wDQYJKoZIhvcNAQELBQAwITEfMB0G
>
> A1UEAwwWZXh0cmFuZXQtcWFzLmJyb3NlLmNvbTAeFw0xNzAyMjQyMDE0MzVaFw0zNzAyMjQyMDE0
>
> MzVaMCExHzAdBgNVBAMMFmV4dHJhbmV0LXFhcy5icm9zZS5jb20wggEiMA0GCSqGSIb3DQEBAQUA
>
> A4IBDwAwggEKAoIBAQCn8f4LB3U5/ZGLJnZP8bm2zCVg0SL0aeBAfNeiC59ChEKGHw93D+9Bwl7I
>
> AjffDcuRGK+SjKVX6m55A/3sCFp4GnsKNzdzxgDxStbADC4/fC4TYSaUG83qzpjLc776/Z9s/IDz
>
> SUZ7mTvcH3eusWctI+cRLRrGO/7qfg0Z6Blxppmtc0+/ZrfaPQ9Gtzt94GSY7KCNYecGcbvZXrkQ
>
> BpKYzoiu0ViECz6xNnRYKf1U3TCrZnwdkQe3v4HSr8xEMbMv0JOneSRQsfdzrPguwOxDkEU/pIEM
>
> Dqwy/MjZxAr5885GHgwqcD4X+vk2nscGasH4+R+HqLmeTvBRawW5eES5AgMBAAGjaDBmMB0GA1Ud
>
> DgQWBBT6DDaEyWBg/e5luv8yB5aJUZT9DjBFBgNVHREEPjA8ghZleHRyYW5ldC1xYXMuYnJvc2Uu
>
> Y29thiJleHRyYW5ldC1xYXMuYnJvc2UuY29taWRwL21ldGFkYXRhMA0GCSqGSIb3DQEBCwUAA4IB
>
> AQAFoqrOBTyGch0ga6kw//H01e6OWW4dYTEswsgg2Bc5EJKju5KDufcX0TiU3OaMGE6ebeLWjMYV
>
> JI8wbrWw4F0+sL0mV4fAmdSyvljDI1gTW6ZFbMmmKqYEqm6nfpncoX10TtuF4AEEEK8jsEHF9J74
>
> hfnFwyws6y5Ph0ANGH7pobvJt5O+b3+fgOLrj1LcwEZui4rdbyYR29QlL0aXrol4MbJqwQHe8/1E
>
> sDthVUjX4Sz/BCxjJxAVRpQ862fGgLHTWFlI9maxkeNb+H9fJwgl6Yizslyczo0ZadezLlomvO90
> Tg0M0CF9x7KkWA4wv+uW/K548ydHA4MH+sqj9skH
> </ds:X509Certificate>
> </ds:X509Data>
> </ds:KeyInfo>
> </ds:Signature>
> <saml2:Subject>
> <saml2:NameID
> Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress">user@email
> </saml2:NameID>
> <saml2:SubjectConfirmation
> Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
> <saml2:SubjectConfirmationData
> InResponseTo="id-2f792815-f7e3-4c8a-9330-6b28163dbcc0"
>
> NotOnOrAfter="2017-03-15T15:07:09.885Z"/>
> </saml2:SubjectConfirmation>
> </saml2:Subject>
> <saml2:Conditions NotBefore="2017-03-15T15:06:09.899Z"
> NotOnOrAfter="2017-03-15T15:07:09.899Z">
> <saml2:AudienceRestriction>
>
> <saml2:Audience>https://..../adfs/services/trust</saml2:Audience>
> </saml2:AudienceRestriction>
> </saml2:Conditions>
> <saml2:AuthnStatement AuthnInstant="2017-03-15T15:06:09.885Z">
> <saml2:SubjectLocality
> Address="https://..../adfs/services/trust"/>
> <saml2:AuthnContext>
>
> <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified
> </saml2:AuthnContextClassRef>
> </saml2:AuthnContext>
> </saml2:AuthnStatement>
> <saml2:AttributeStatement>
> <saml2:Attribute
> FriendlyName="samlAuthenticationStatementAuthMethod"
> Name="samlAuthenticationStatementAuthMethod">
> <saml1:AttributeValue
> xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion"
>
> xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">
> urn:oasis:names:tc:SAML:1.0:am:password
> </saml1:AttributeValue>
> </saml2:Attribute>
> <saml2:Attribute FriendlyName="uid" Name="uid">
> <saml1:AttributeValue
> xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion"
>
> xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">
> user@email
> </saml1:AttributeValue>
> </saml2:Attribute>
> <saml2:Attribute FriendlyName="isFromNewLogin"
> Name="isFromNewLogin">
> <saml1:AttributeValue
> xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion"
>
> xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
> xsi:type="xsd:string">false
> </saml1:AttributeValue>
> </saml2:Attribute>
> <saml2:Attribute FriendlyName="authenticationDate"
> Name="authenticationDate">
> <saml1:AttributeValue
> xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion"
>
> xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">
> 2017-03-15T16:06:09.734+01:00[Europe/Berlin]
> </saml1:AttributeValue>
> </saml2:Attribute>
> <saml2:Attribute FriendlyName="authenticationMethod"
> Name="authenticationMethod">
> <saml1:AttributeValue
> xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion"
>
> xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">
> specialAuthenticator
> </saml1:AttributeValue>
> </saml2:Attribute>
> <saml2:Attribute FriendlyName="successfulAuthenticationHandlers"
> Name="successfulAuthenticationHandlers">
> <saml1:AttributeValue
> xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion"
>
> xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">
> specialAuthenticator
> </saml1:AttributeValue>
> </saml2:Attribute>
> <saml2:Attribute
> FriendlyName="longTermAuthenticationRequestTokenUsed"
> Name="longTermAuthenticationRequestTokenUsed">
> <saml1:AttributeValue
> xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion"
>
> xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
> xsi:type="xsd:string">false
> </saml1:AttributeValue>
> </saml2:Attribute>
> </saml2:AttributeStatement>
> </saml2:Assertion>
> </saml2p:Response>
>
>
> Any help or hints are appreciated. Even debug logging on ADFS provides me any
> useful info.
>
>
> Best
>
> -- Robert
>
>
--
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
---
You received this message because you are subscribed to the Google Groups "CAS
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion on the web visit
https://groups.google.com/a/apereo.org/d/msgid/cas-user/1c8433c2-de8b-4eb2-ab92-658060c8eba3%40apereo.org.