Outlook connectivity test fails / Office365 SMTP - SAML Assertion Invalid Signature

Viewed 22

we have developed our own SAML IDP and have configured Office365 for federation to our SAML IDP. We can login to Office365, Teams, etc all with no errors. However, when we try the Outlook connectivity test at https://testconnectivity.microsoft.com, or when we attempt to send an SMTP email through smtp.office365.com, then we are getting a failure. The failure is shown below for the Outlook connectivity test (personal information changed)

Attempting to send an Autodiscover POST request to potential Autodiscover URLs. Autodiscover settings weren't obtained when the Autodiscover POST request was sent. Test Steps

The Microsoft Connectivity Analyzer is attempting to retrieve an XML Autodiscover response from URL https://autodiscover-s.outlook.com:443/Autodiscover/Autodiscover.xml for user nehal_bhansali@softexinc.com. The Microsoft Connectivity Analyzer failed to obtain an Autodiscover XML response. Additional Details A Web exception occurred because an HTTP 503 - 503 response was received from Unknown. HTTP Response Headers: Retry-After: 30 request-id: 8aa93fbb-2af7-4830-19ce-c48b4c8a42b5 Alt-Svc: h3=":443",h3-29=":443" X-CalculatedBETarget: MW4PR14MB5440.namprd14.PROD.OUTLOOK.COM X-BackEndHttpStatus: 503 X-RUM-Validated: 1 X-AutoDiscovery-Error: LiveIdBasicAuth:FederatedStsUnreachable:UNH:<PII.Email:7J+GS+4rufdDUc9R4mr7Ifl48VhyJ296RJq6lQpEsKg=@ourdomain.com><RequestId=69ac563d-4688-4ee7-8184-2ac1c507baba,ST=23:03:23>UIPH:<PII.IP:aU/9Mm6Oy7mcCIl2kWkA43wQoeRe2WNIcRrp/8UOlNo=><HitHrdX-forwarded-for:<PII.IP:aU/9Mm6Oy7mcCIl2kWkA43wQoeRe2WNIcRrp/8UOlNo=>PTS:False<HRD-Business-225ms-582ms-ppserver=>STSUrl:https://ouridp.ourdomain.com/our-saml-soap-endpointHRDCached:True<BA:255,UP:-46840,ExCaught:False,BlockStatus:1><IOOH<IV1OOH<SAML_F:T:,M:STSFailure,E:Saml Assertion has invalid signature<SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/">SOAP-ENV:Header<ECP:Response xmlns:ECP="urn:oasis:names:tc:SAML:2:0:profiles:SSO:ecp" AssertionConsumerServiceURL="https://login.microsoftonline.com/login.srf" SOAP-ENV:actor="http://schemas.xmlsoap.org/soap/actor/next" SOAP-ENV:mustUnderstand="1" /></SOAP-ENV:Header>SOAP-ENV:Body<saml2p:Response Destination="https://login.microsoftonline.com/login.srf" ID="id8f11d5db1760473f8c529ceb9dbffe26" Version="2.0" IssueInstant="2022-09-09T03:46:47Z" InResponseTo="_e0b08565-4668-42fc-a944-38f13746cc34" xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"><saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">https://ouridp.ourdomain.com/ourissuer</saml2:Issuer><ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><ds:SignedInfo><ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" /><ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1" /><ds:Reference URI="#id8f11d5db1760473f8c529ceb9dbffe26"><ds:Transforms><ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" /><ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" /></ds:Transforms><ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1" /><ds:DigestValue>pcQNhMcMgqfBFBs3mjD7A+3sJ04=</ds:DigestValue></ds:Reference></ds:SignedInfo><ds:SignatureValue>BSyVm3/mptGVCxK+ZAf4nC6qmEjy495eSxtKcP8LR0Eyy66I4fm2f3vjKbwa/I21H4+68LG0VSDSTZWW43t9b9hwD9xJ/xyWVo+PRIa64MJr6haz/OAruljjmc/aWXadbL/t2BHiK7VXbh/79T2jWxZRoYughNGi9ArCdl+Tz8DKWE/w93WfQqWB/Wy3VxWgX3jukAgxJD5L2iyEdmz+ibFIMUGlph19bYgbDqHiCCivU14aw0LibRLYb7xyjFp1SRXfJtzHKtG716+lpm6nn1bwgyAbgOBaLlB6qmmxtruVv69Y36sOyuVabICCOWev6TpeTsOKtiUIIO7fbp+j6g==</ds:SignatureValue><ds:KeyInfo><ds:X509Data><ds:X509Certificate>saml signing certificate here</ds:X509Certificate></ds:X509Data></ds:KeyInfo></ds:Signature>saml2p:Status<saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success" /></saml2p:Status><saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:xsd="http://www.w3.org/2001/XMLSchema" Version="2.0" ID="_9780d766-a51c-47c5-819f-c78863ef70d8" IssueInstant="2022-09-09T03:46:47Z">saml2:Issuerhttps://ouridp.ourdomain.com/ourIssuer</saml2:Issuer><ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><ds:SignedInfo><ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" /><ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1" /><ds:Reference URI="#_9780d766-a51c-47c5-819f-c78863ef70d8"><ds:Transforms><ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" /><ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" /></ds:Transforms><ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1" /><ds:DigestValue>WqjQVBBBTaz3GeY5kQAVQHZ39Ck=</ds:DigestValue></ds:Reference></ds:SignedInfo><ds:SignatureValue>SWSelRmGKEP652VDjhEIbGH9aQguIVa6WKNYHqHz0XYX417XRfkW0qDguJAArwYVURK3ikZIo+vJQc3LJO/DES9pw6y/HNXIaHwwUQGKrCvfGWIVCaj9FLdIIt5bTOlSpSPBG7PgvyUYVsfYecia6bnIs825xmv7lAEcew4k2btEJ5Kli1DeEqFKjpLYKNmWefgXQLB/CbgW1+oRi305GIhO7nFwg4XRZ19psucr5Rbs/0TeI5Mrf55t/1yTfLBt0+a3dg0jGsQZqJLtdouJSCwk0ZVC1yqMprUodnibSZe8XhbaKsopfrmXW/6r7xmIAZ8bA5Cv0InI9O4OQnqTuw==</ds:SignatureValue><ds:KeyInfo><ds:X509Data><ds:X509Certificate>[our SAML signing certificate]</ds:X509Certificate></ds:X509Data></ds:KeyInfo></ds:Signature>saml2:Subject<saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" NameQualifier="https://ouridp.ourdomain.com/ourIssuer" SPNameQualifier="urn:federation:MicrosoftOnline">[user ImmutableID]</saml2:NameID><saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><saml2:SubjectConfirmationData NotOnOrAfter="2022-09-09T03:51:47Z" InResponseTo="_e0b08565-4668-42fc-a944-38f13746cc34" Recipient="https://login.microsoftonline.com/login.srf" /></saml2:SubjectConfirmation></saml2:Subject><saml2:Conditions NotBefore="2022-09-09T03:45:47Z" NotOnOrAfter="2022-09-09T03:51:47Z">saml2:AudienceRestrictionsaml2:Audienceurn:federation:MicrosoftOnline</saml2:Audience></saml2:AudienceRestriction></saml2:Conditions><saml2:AuthnStatement AuthnInstant="2022-09-09T03:46:47Z" SessionIndex="383cbd2e7528491ebdeb6251a42cc1a2">saml2:AuthnContextsaml2:AuthnContextClassRefurn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef></saml2:AuthnContext></saml2:AuthnStatement>saml2:AttributeStatement<saml2:Attribute Name="IDPEmail">saml2:AttributeValue[user upn/email]</saml2:AttributeValue></saml2:Attribute></saml2:AttributeStatement></saml2:Assertion></saml2p:Response></SOAP-ENV:Body></SOAP-ENV:Envelope>>SAML:AddV2NUserType:Federated<AS:FederatedStsFailed><Tid=8ccccceb-0040-4e3e-a7bc-733ee9f8ef80><V1; X-DiagInfo: MW4PR14MB5440 X-BEServer: MW4PR14MB5440 X-Proxy-RoutingCorrectness: 1 X-Proxy-BackendServerStatus: 503 X-FirstHopCafeEFZ: DSM X-FEProxyInfo: DM6PR02CA0164.NAMPRD02.PROD.OUTLOOK.COM X-FEEFZInfo: DSM X-FEServer: DM6PR02CA0164 Content-Length: 0 Date: Fri, 09 Sep 2022 03:46:46 GMT Server: Microsoft-IIS/10.0 X-Powered-By: ASP.NET

We get a call into our IDP's SAML ECP SOAP endpoint (ActiveLogOnUri) where we build the SAML Response/Assertion to return and we sign both the Response and Assertion with our SAML signing certificate (same certificate that is set in Office 365 federation as the SigningCertificate). We return successfully from our SAML ECP SOAP endpoint, and then see the error above.

If we take our SAML Response and put it in the SAML Response Validater at https://www.samltool.com/validate_response.php, we see that the response and XML signature is validated. We also wrote a C# code to read the SAML response and validate the signature using the SignedXML class. One note: our SAML response is returned with no extra whitespace/newlines. We sign the SAML response with no extra whitespace/newlines and return the response from the SAML ECP SOAP endpoint the same way, so we don't think this is related to whitespace.

We can not figure out why Office365 returns this SAML Invalid Signature error ONLY when the SAML ECP SOAP endpoint is invoked via the Outlook connectivity test or SMTP email sending. Any help is appreciated.

0 Answers
Related