来自saml响应的opensaml 3签名为null

时间:2016-12-12 14:03:33

标签: java azure saml unmarshalling opensaml

嗨,我收到了这个错误消息:

net.shibboleth.utilities.java.support.logic.ConstraintViolationException: Signature was null

验证Azure AD的SAML响应。

出于测试目的,我将响应文件保存为xml并找到了一个标记:

<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:SignedInfo>
            <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
            <ds:SignatureMethod
                Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" />
            <ds:Reference URI="#_97031c65-0139-4047-a416-9495df5d6ed7">
                <ds:Transforms>
                    <ds:Transform
                        Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" />
                    <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
                </ds:Transforms>
                <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" />
                <ds:DigestValue>
                    KMaFHRt8inqVYsMGKnAryKUTQUbYGPUDPxdvj6T08OQ=
                </ds:DigestValue>
            </ds:Reference>
        </ds:SignedInfo>
        <ds:SignatureValue>
           .....
        </ds:SignatureValue>
        <KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
            <X509Data>
                <X509Certificate>
                    ....
                </X509Certificate>
            </X509Data>
        </KeyInfo>
    </ds:Signature>

我解组XML响应:

InitializationService.initialize();
DocumentBuilderFactory documentBuilderFactory = DocumentBuilderFactory.newInstance();
documentBuilderFactory.setNamespaceAware(true);
DocumentBuilder docBuilder = documentBuilderFactory.newDocumentBuilder();
String content = new String(Files.readAllBytes(Paths.get("saml_response_azure.xml")));
Document document = docBuilder.parse(new ByteArrayInputStream(content.trim().getBytes()));

Element element = document.getDocumentElement();
Unmarshaller unmarshaller = XMLObjectProviderRegistrySupport.getUnmarshallerFactory().getUnmarshaller(element);
Response response = (Response) unmarshaller.unmarshall(element);

错误被删除:

Signature signature = response.getAssertions().get(0).getSignature() // returns null

SAMLSignatureProfileValidator profValidator = new SAMLSignatureProfileValidator();
profValidator.validate(signature);

1 个答案:

答案 0 :(得分:2)

好吧,我想我找到了它,看起来你没有向你的POM添加任何实现依赖。当我使用你的POM并包含这个依赖项时,我得到了签名对象。

  <dependency>
     <groupId>org.opensaml</groupId>
     <artifactId>opensaml-saml-impl</artifactId>
     <version>3.2.0</version>
 </dependency>

依赖项的模块化结构与OpenSAML的第2版有很大不同。