I wouldn’t be surprised if you discovered a bug in the way CAS handles 
encryption. Short of making sure you’re using the right credentials, best bet 
would be to step through the sequence of operations, see how the encrypter 
works and cross-check the order and sanity of ops with your client. 

-- 
Misagh

From: Todd Pratt <[email protected]>
Reply: [email protected] <[email protected]>
Date: January 17, 2017 at 7:33:53 PM
To: CAS Community <[email protected]>
Subject:  [cas-user] CAS 5.0 SAML2 Response Decryption  

Hi,

I'm having an issue getting the SAML2 response to decrypt.  It all works when 
it's just signed but once I enable encryption I can't decrypt the assertions 
from the client.  I'm using opensaml from java and below is the method I'm 
using to decrypt.  The credentials are built from a keystore which I exported 
my public key from that I have in the metadata file.  I have used this code 
before with other IdP's.  I've also included the log messages below, metadata 
file and service provider files.  Any help would be greatly appreciated.



public static Assertion decryptEncryptedAssertion(EncryptedAssertion 
encryptedAssertion, Credential credentials) throws DecryptionException, 
CertificateException, IOException {
StaticKeyInfoCredentialResolver staticKeyResolver = new 
StaticKeyInfoCredentialResolver(credentials);
        InlineEncryptedKeyResolver inlineEncryptedKeyResolver = new 
InlineEncryptedKeyResolver();
        
        Decrypter decrypter = new Decrypter(null, staticKeyResolver, 
inlineEncryptedKeyResolver);
        
        return decrypter.decrypt(encryptedAssertion);
}


DEBUG 
[org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] 
- <Attempting to encrypt [org.opensaml.saml.saml2.core.impl.AssertionImpl] for 
[http://172.24.98.169:8080/saml_test2]>
2017-01-17 10:51:06,398 DEBUG 
[org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] 
- <Encryption blacklisted algorithms: 
[[http://www.w3.org/2001/04/xmlenc#rsa-1_5]]>
2017-01-17 10:51:06,398 DEBUG 
[org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] 
- <Encryption key algorithms: 
[[http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p, 
http://www.w3.org/2001/04/xmlenc#kw-aes128, 
http://www.w3.org/2001/04/xmlenc#kw-aes192, 
http://www.w3.org/2001/04/xmlenc#kw-aes256, 
http://www.w3.org/2001/04/xmlenc#kw-tripledes]]>
2017-01-17 10:51:06,398 DEBUG 
[org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] 
- <Signature data algorithms: [[http://www.w3.org/2001/04/xmlenc#aes128-cbc, 
http://www.w3.org/2001/04/xmlenc#aes192-cbc, 
http://www.w3.org/2001/04/xmlenc#aes256-cbc, 
http://www.w3.org/2001/04/xmlenc#tripledes-cbc]]>
2017-01-17 10:51:06,399 DEBUG 
[org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] 
- <Encryption whitelisted algorithms: []>
2017-01-17 10:51:06,497 DEBUG 
[org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] 
- <Locating encryption key file from [/etc/cas/saml/idp-encryption.key]>
2017-01-17 10:51:06,497 DEBUG 
[org.apereo.cas.util.crypto.PrivateKeyFactoryBean] - <Attempting to read 
/etc/cas/saml/idp-encryption.key as PEM>
2017-01-17 10:51:06,536 DEBUG 
[org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] 
- <Locating encryption certificate file from [/etc/cas/saml/idp-encryption.crt]>
2017-01-17 10:51:06,537 DEBUG 
[org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] 
- <Created encryption credential>
2017-01-17 10:51:06,539 DEBUG 
[org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] 
- <Attempting to resolve the encryption key for entity id 
[http://172.24.98.169:8080/saml_test2]>
2017-01-17 10:51:06,539 DEBUG 
[org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] 
- <Key encryption algorithm for [http://172.24.98.169:8080/saml_test2] is 
[http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p]>
2017-01-17 10:51:06,540 DEBUG 
[org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] 
- <Data encryption algorithm for [http://172.24.98.169:8080/saml_test2] is 
[http://www.w3.org/2001/04/xmlenc#aes128-cbc]>
2017-01-17 10:51:06,545 DEBUG 
[org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlObjectEncrypter] 
- <Attempting to encrypt [org.opensaml.saml.saml2.core.impl.AssertionImpl] for 
[http://172.24.98.169:8080/saml_test2] with key placement of [PEER]>
2017-01-17 10:51:06,599 DEBUG 
[org.apereo.cas.support.saml.web.idp.profile.builders.SamlProfileSamlResponseBuilder]
 - <Built assertion is encrypted, so the response will add it to the encrypted 
assertions collection>



<?xml version="1.0" encoding="UTF-8"?>
<EntityDescriptor  xmlns="urn:oasis:names:tc:SAML:2.0:metadata" 
xmlns:ds="http://www.w3.org/2000/09/xmldsig#" 
                xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" 
xmlns:xml="http://www.w3.org/XML/1998/namespace" 
                xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" 
entityID="http://172.24.98.169:8080/saml_test2";>
    <SPSSODescriptor 
protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
        <Extensions>
            <shibmd:Scope 
regexp="false">http://172.24.98.169:8080/saml_test2</shibmd:Scope>
        </Extensions>
        <KeyDescriptor use="signing">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
---- My Public Cert ----
</ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>
        <KeyDescriptor use="encryption">
            <ds:KeyInfo>
                    <ds:X509Data>
                        <ds:X509Certificate>
---- My Public Cert ----
</ds:X509Certificate>
                    </ds:X509Data>
            </ds:KeyInfo>
        </KeyDescriptor>

        <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
        
<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>

        <SingleLogoutService 
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" 
                             
Location="https://cas.morleyweb.com:8443/cas/idp/profile/SAML2/POST/SLO"/>

        <SingleSignOnService 
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" 
                             
Location="https://cas.morleyweb.com:8443/cas/idp/profile/SAML2/POST/SSO"/>
        <SingleSignOnService 
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" 
                             
Location="https://cas.morleyweb.com:8443/cas/idp/profile/SAML2/Redirect/SSO"/>
        <AssertionConsumerService
            isDefault="true"
            index="0"
            Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact"
            Location="http://172.24.98.169:8080/saml_test2/sso"/>
    </SPSSODescriptor>
</EntityDescriptor>


{
  @class: org.apereo.cas.support.saml.services.SamlRegisteredService
  serviceId: ^http://172.24.98.169:8080/saml_test2
  name: SAMLTest
  id: 3032504042888199
  description: SAML Testing
  evaluationOrder: 1
  logoutType: NONE
  attributeReleasePolicy:
  {
    @class: org.apereo.cas.services.ReturnAllAttributeReleasePolicy
    principalAttributesRepository:
    {
      @class: 
org.apereo.cas.authentication.principal.DefaultPrincipalAttributesRepository
      expiration: 2
      timeUnit: HOURS
    }
    authorizedToReleaseCredentialPassword: false
    authorizedToReleaseProxyGrantingTicket: false
  }
  multifactorPolicy:
  {
    @class: org.apereo.cas.services.DefaultRegisteredServiceMultifactorPolicy
    failureMode: CLOSED
  }
  accessStrategy:
  {
    @class: org.apereo.cas.services.DefaultRegisteredServiceAccessStrategy
    enabled: true
    ssoEnabled: true
    requireAllAttributes: false
    caseInsensitive: false
  }
  metadataLocation: /etc/cas/saml/saml_test2.xml
  metadataMaxValidity: 0
  signAssertions: false
  signResponses: true
  encryptAssertions: true
  metadataCriteriaRoles: SPSSODescriptor
  metadataCriteriaRemoveEmptyEntitiesDescriptors: false
  metadataCriteriaRemoveRolelessEntityDescriptors: false
}


--
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
---
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/b66a03c4-e1ba-4335-a6ff-b34cfcb325ed%40apereo.org.

-- 
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/etPan.587e951b.22c66492.5e2e%40unicon.net.

Reply via email to