Private Key error in Saml2Configuration.SigningCertificate with Self-Signed Cert

Viewed 147

I would like to test this implementation using self-signed certificates. I'm using the MVC implementation and am running into The remote server returned an error: (500) Internal Server Error.

Debugging shows the error occurs in Saml2SignedXml.ComputeSignature(...) at line 36: ComputeSignature(), which is inherited from Microsoft's SignedMxl and I can't step into it.

Saml2Configuration.SigningCertificate shows HasPrivateKey = true, but an error for the PrivateKey property: Saml2Configuration.SigningCertificate.PrivateKey threw an exception of type System.NotSupportedException.

I see the private key in the same property when using the provide ITFoxtec cert.

I am using a self-signed cert because the tfoxtec.identity.saml2.testidpcore_Certificate.pfx cert causes a Incorrect URI format error in MVC.

Honestly, I don't think this is a code problem so much as a certificate problem, but I'm not sure where to look at this point.

1 Answers

You probably need to use another self-signed certificate.

It is possible to create at self-signed certificate in .NET core or .NET 5.0 like this:

/// <summary>
/// Create self-signed certificate with subject name. .
/// </summary>
/// <param name="subjectName">Certificate subject name, example: "CN=my-certificate, O=some-organisation".</param>
/// <param name="expiry">Certificate expiry, default 365 days.</param>
public static Task<X509Certificate2> CreateSelfSignedCertificateAsync(this string subjectName, TimeSpan? expiry = null)
{
    using (var rsa = RSA.Create(2048))
    {
        var certRequest = new CertificateRequest(subjectName, rsa, HashAlgorithmName.SHA256, RSASignaturePadding.Pkcs1);

        certRequest.CertificateExtensions.Add(
            new X509BasicConstraintsExtension(false, false, 0, false));

        certRequest.CertificateExtensions.Add(
            new X509SubjectKeyIdentifierExtension(certRequest.PublicKey, false));

        certRequest.CertificateExtensions.Add(
            new X509KeyUsageExtension(
                X509KeyUsageFlags.DigitalSignature | X509KeyUsageFlags.KeyEncipherment | X509KeyUsageFlags.DataEncipherment | X509KeyUsageFlags.KeyAgreement,
                false));

        var now = DateTimeOffset.UtcNow;
        return Task.FromResult(certRequest.CreateSelfSigned(now.AddDays(-1), now.Add(expiry ?? TimeSpan.FromDays(365))));
    }
}

The code is from ITfoxtec.Identity X509Certificate2Extensions.cs and the code is e.g. used in FoxIDs.

Related