Skip to content

Support RetrievalMethod to obtain encrypted key - #1

Merged
RumataEstor merged 3 commits into
mainfrom
feature/retrieval-method
Feb 25, 2020
Merged

Support RetrievalMethod to obtain encrypted key#1
RumataEstor merged 3 commits into
mainfrom
feature/retrieval-method

Conversation

@RumataEstor

@RumataEstor RumataEstor commented Feb 24, 2020

Copy link
Copy Markdown

The certificate details are:

Certificate:
    Data:
        Version: 1 (0x0)
        Serial Number: 10553191170509467144 (0x92747774d5016e08)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: CN=localhost
        Validity
            Not Before: Feb 25 00:49:21 2020 GMT
            Not After : Feb 22 00:49:21 2030 GMT
        Subject: CN=localhost

The decrypted assertions are:

<saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_a4f4f23063a4c34602f297728a62a984" IssueInstant="2020-02-25T01:09:03.329Z" Version="2.0">
  <saml2:Issuer>https://samltest.id/saml/idp</saml2:Issuer>
  <saml2:Subject>
    <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" NameQualifier="https://samltest.id/saml/idp" SPNameQualifier="urn:f5156378-6d88-44b0-a38a-31219f1af162">AAdzZWNyZXQxaFz414z3p79wk6Nh+/vVzF3UVtV0+jg8VHNM/ilHtGCfO9sAuwkeqvV2U9ViOR0Y6uksdH2ZABXaIkqYw2Y66uTKdUwqy7H5WD+jIWSG26Nc26s/64rXzTsQgKZk1lIY5ErrLKmWoTMzbQpT</saml2:NameID>
    <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
      <saml2:SubjectConfirmationData Address="172.31.46.7" NotOnOrAfter="2020-02-25T01:14:03.333Z" Recipient="http://localhost:4000/saml/login"></saml2:SubjectConfirmationData>
    </saml2:SubjectConfirmation>
  </saml2:Subject>
  <saml2:Conditions NotBefore="2020-02-25T01:09:03.329Z" NotOnOrAfter="2020-02-25T01:14:03.329Z">
    <saml2:AudienceRestriction>
      <saml2:Audience>urn:f5156378-6d88-44b0-a38a-31219f1af162</saml2:Audience>
    </saml2:AudienceRestriction>
  </saml2:Conditions>
  <saml2:AuthnStatement AuthnInstant="2020-02-25T01:09:03.325Z" SessionIndex="_ebe64b9f3e457d8f7d0571d1d5932568">
    <saml2:SubjectLocality Address="172.31.46.7"></saml2:SubjectLocality>
    <saml2:AuthnContext>
      <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef>
    </saml2:AuthnContext>
  </saml2:AuthnStatement>
  <saml2:AttributeStatement>
    <saml2:Attribute Name="urn:oasis:names:tc:SAML:attribute:subject-id" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
      <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">msmith@samltest.id</saml2:AttributeValue>
    </saml2:Attribute>
    <saml2:Attribute FriendlyName="uid" Name="urn:oid:0.9.2342.19200300.100.1.1" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
      <saml2:AttributeValue>morty</saml2:AttributeValue>
    </saml2:Attribute>
    <saml2:Attribute FriendlyName="telephoneNumber" Name="urn:oid:2.5.4.20" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
      <saml2:AttributeValue>+1-555-555-5505</saml2:AttributeValue>
    </saml2:Attribute>
    <saml2:Attribute FriendlyName="role" Name="https://samltest.id/attributes/role" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
      <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">janitor@samltest.id</saml2:AttributeValue>
    </saml2:Attribute>
    <saml2:Attribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
      <saml2:AttributeValue>msmith@samltest.id</saml2:AttributeValue>
    </saml2:Attribute>
    <saml2:Attribute FriendlyName="sn" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
      <saml2:AttributeValue>Smith</saml2:AttributeValue>
    </saml2:Attribute>
    <saml2:Attribute FriendlyName="displayName" Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
      <saml2:AttributeValue>Morty Smith</saml2:AttributeValue>
    </saml2:Attribute>
    <saml2:Attribute FriendlyName="givenName" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
      <saml2:AttributeValue>Mortimer</saml2:AttributeValue>
    </saml2:Attribute>
  </saml2:AttributeStatement>
</saml2:Assertion>

<saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="id78198271041823771367985085" IssueInstant="2020-02-25T00:55:25.729Z" Version="2.0">
  <saml2:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">http://www.okta.com/exkppcsjrwG5A5tLx0h7</saml2:Issuer>
  <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
    <ds:SignedInfo>
      <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"></ds:CanonicalizationMethod>
      <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"></ds:SignatureMethod>
      <ds:Reference URI="#id78198271041823771367985085">
        <ds:Transforms>
          <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"></ds:Transform>
          <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"></ds:Transform>
        </ds:Transforms>
        <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"></ds:DigestMethod>
        <ds:DigestValue>pP0CyvNSkAtnqkfGC1V3HpcWbb6vW/NUo1srwKcii+8=</ds:DigestValue>
      </ds:Reference>
    </ds:SignedInfo>
    <ds:SignatureValue>Q7Mese/JHG7ITP9V8LWsn8rXlrQhl2Qo5y8h1dNAybxgFk6NVXGbdxD/tAMwwS2iJUPzT72SMEMuiPvy0syx8AyY9PgRKJY/TzXV1nkxphQkD+uplIuPErHXu3lBFlIB8gXevD+jVG+0/S9e+Adro55SwCiLYh4BILAH17Dn8Nb8tSwmFl1ZaRwd4D7jG1mIMfXmFxXtu92+YBZKwCRBWUwuZ3ovfdPZsz9RkUn1zP6yhPeQDB3ivsnXemGNNAuXl5N7KSbHhHYywkhwAG9lsGsw1dYMns3vJH/TZup0I5nS/olCnvVH2imEh8Wiwy1zpIRbZr/ap8FiOMP2SlnamQ==</ds:SignatureValue>
    <ds:KeyInfo>
      <ds:X509Data>
        <ds:X509Certificate>MIIDpDCCAoygAwIBAgIGAWLw8/ngMA0GCSqGSIb3DQEBCwUAMIGSMQswCQYDVQQGEwJVUzETMBEG
A1UECAwKQ2FsaWZvcm5pYTEWMBQGA1UEBwwNU2FuIEZyYW5jaXNjbzENMAsGA1UECgwET2t0YTEU
MBIGA1UECwwLU1NPUHJvdmlkZXIxEzARBgNVBAMMCmRldi03MDU1NzExHDAaBgkqhkiG9w0BCQEW
DWluZm9Ab2t0YS5jb20wHhcNMTgwNDIzMDUyMTIzWhcNMjgwNDIzMDUyMjIzWjCBkjELMAkGA1UE
BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFjAUBgNVBAcMDVNhbiBGcmFuY2lzY28xDTALBgNV
BAoMBE9rdGExFDASBgNVBAsMC1NTT1Byb3ZpZGVyMRMwEQYDVQQDDApkZXYtNzA1NTcxMRwwGgYJ
KoZIhvcNAQkBFg1pbmZvQG9rdGEuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA
h6c6SRjeGM6pEP9KDLsF0KrVcneap95AoH0XcxILlNAzH45Ywp16ric5s/wBc6Chyirlg2l+uYbB
EOrIkir4Pf41b5bZlOAqFxKmTZXCxGCy+fknb9Sb+5EqTo7b5SgdT4Je9GLBBtYJfldU05vi4dnY
2mOACvtzyiDFsh9yS+cM8lCRb9ItRFvdhmN1r/hSTXSup0JelT21E1do4ECj24GyUj75u4Cm+UNE
6Y3dKNjfNCgSMqLoh7pW2fUgtAiAL3sPoINnrY9vCrKzFbRa6RBq8ObjsfY6mWpe2o2HO2lB2G36
sHjRREUd+E1ANSyyz1Vl4rUu44ywtLpxDw3QgwIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQAYs4oM
tKDlzddAcdMSBoCMwopoV8i4Qh8pqodh6F1UAHTGDfi4Rd/swFXFsxogegDgVyQrQLVUpqST84Vf
7Qkdh3Y+LgDH7NTJU3byE/3y0H8WaZ9Q8nMczZ3RdwvuKU2cseK5FWpmxMqpsmA33kCAHaRJFTpz
mGlhUXC67xBqchq5ZZL+BeZPYi4C9fm++ToagZRXYYXQ7t64oM4GIVqeng34MWgc9jkMC8IVOSBj
CVoZcwurI00LA/8bgHszBRIEQOqnuiAetD9GzCndAKwxi7wIys3r5eOeldzue88pw8NP+nrMPGk1
b5WOybfed/kbNVTb2rTW9o2vsLkalSY7</ds:X509Certificate>
      </ds:X509Data>
    </ds:KeyInfo>
  </ds:Signature>
  <saml2:Subject>
    <saml2:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">user-name</saml2:NameID>
    <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
      <saml2:SubjectConfirmationData NotOnOrAfter="2020-02-25T01:00:25.729Z" Recipient="http://localhost:4000/saml/login"></saml2:SubjectConfirmationData>
    </saml2:SubjectConfirmation>
  </saml2:Subject>
  <saml2:Conditions NotBefore="2020-02-25T00:50:25.729Z" NotOnOrAfter="2020-02-25T01:00:25.729Z">
    <saml2:AudienceRestriction>
      <saml2:Audience>urn:f5156378-6d88-44b0-a38a-31219f1af162</saml2:Audience>
    </saml2:AudienceRestriction>
  </saml2:Conditions>
  <saml2:AuthnStatement AuthnInstant="2020-02-25T00:55:16.351Z" SessionIndex="id1582592125729.1579170994">
    <saml2:AuthnContext>
      <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef>
    </saml2:AuthnContext>
  </saml2:AuthnStatement>
</saml2:Assertion>

@RumataEstor RumataEstor changed the title Feature/retrieval method Support RetrievalMethod to obtain encrypted key Feb 24, 2020
@RumataEstor
RumataEstor force-pushed the feature/retrieval-method branch from 4028fec to b4faf38 Compare February 25, 2020 01:28
@RumataEstor

RumataEstor commented Feb 25, 2020

Copy link
Copy Markdown
Author

Running a travis build on the personal repository https://travis-ci.org/RumataEstor/esaml revealed the first test fix was unnecessary probably caused by the local environment, and also that current cowlib cannot be compiled using OTP18.

@RumataEstor
RumataEstor requested a review from jdfolino February 25, 2020 02:09

@andre-dubber andre-dubber left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

My understanding of the Erlang is limited, but from what I understand all looks good

@RumataEstor
RumataEstor merged commit 7e1f948 into main Feb 25, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants