cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Dubravko Penezic <address@concealed>
- To: address@concealed
- Subject: Re: [[cat-users]] Unable to authenticate
- Date: Mon, 3 Aug 2020 08:40:12 +0200
Hi all,
after some investigation situation is as follow.
CAT request authentication , and user decide from discovery service for
IdP, discovery service send request for authentication to
https://shib.highlands.ac.uk/idp (via user browser) and attach
certificate in it and encryption algorithm for signature.
In next step arrive response from https://shib.highlands.ac.uk/idp , and
that xml have 2 keys.
First one is declared like rsa-sha256 , for signature, and system is not
able to check signature with this one. Looking in other request
responses, it is look like that signature certificate are one of issue
(in few other case using aes128-gcm validation is done correctly).
Second issue is connected with xmlseclibs SSP use , and I did upgrade,
to latest one according https://github.com/simplesamlphp/saml2/issues/179 .
So please check your signature certificate, and then try to check if
system now work (I dont have any Shib to test with).
Regards,
Dubravko Penezic
On 7/31/20 10:55 AM, Matthew Slowe wrote:
> On 28 Jul 2020, at 10:18, Matthew Slowe <address@concealed> wrote:
>>
>> On behalf of a new CAT member organisation, they're having trouble
>> authenticating to the CAT Admin portal. SimpleSAMLphp is returning an
>> error "Failed to decrypt XML element". We've checked the logs on the IdP
>> (look ok) and can access the UK Federation's Test SP ok, too.
>>
>> SimpleSAML_Error_Error: UNHANDLEDEXCEPTION
>> ...
>> Caused by: Exception: Failed to decrypt XML element.
>>
>> The tracking code was 5d4e392eee at about 08:53Z today.
>>
>> Is this something at the SimpleSAMLphp end or something wrong with the
>> assertion being generated by their IdP?
>
> Following up my own question, this could be because the IdP is a new
> Shibboleth v4 which is using AES-GCM encryption rather than the older
> AES-CBC and SimpleSAMLphp doesn't know how to decrypt it?
>
> Could the metadata registration for the CAT SP be updated to include an
> <EncryptionMethod> element to assert its support options?
>
> https://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-metadata-algsupport-v1.0-cs01.html#__RefHeading__13608_557150731
>
> This should instruct IdPs to use the correct algorithm rather than the new
> default in ShibIdP4.
>
> Thanks,
>
--
Dubravko Penezic
Information Systems and Applications Department
SRCE - University of Zagreb University Computing Centre, www.srce.unizg.hr
address@concealed, tel: +385 1 616 5555, fax: +385 1 616 5559
-
Re: [[cat-users]] Unable to authenticate,
Dubravko Penezic, 08/03/2020
-
Re: [[cat-users]] Unable to authenticate,
Matthew Slowe, 08/03/2020
-
RE: [[cat-users]] Unable to authenticate,
Alan Cox - UKRI, 08/06/2020
-
RE: [[cat-users]] Unable to authenticate,
Alan Cox - UKRI, 08/06/2020
-
Re: [[cat-users]] Unable to authenticate,
Dubravko Penezic, 08/06/2020
- RE: [[cat-users]] Unable to authenticate, Alan Cox - UKRI, 08/07/2020
-
Re: [[cat-users]] Unable to authenticate,
Dubravko Penezic, 08/06/2020
-
Re: [[cat-users]] Unable to authenticate,
Matthew Slowe, 08/06/2020
-
RE: [[cat-users]] Unable to authenticate,
Alan Cox - UKRI, 08/06/2020
- Re: [[cat-users]] Unable to authenticate, Stefan Paetow, 08/06/2020
-
Re: [[cat-users]] Unable to authenticate,
Dubravko Penezic, 08/06/2020
- Re: [[cat-users]] Unable to authenticate, Matthew Slowe, 08/07/2020
-
RE: [[cat-users]] Unable to authenticate,
Alan Cox - UKRI, 08/06/2020
-
RE: [[cat-users]] Unable to authenticate,
Alan Cox - UKRI, 08/06/2020
-
RE: [[cat-users]] Unable to authenticate,
Alan Cox - UKRI, 08/06/2020
-
Re: [[cat-users]] Unable to authenticate,
Matthew Slowe, 08/03/2020
Archive powered by MHonArc 2.6.19+.
