I tried to implement saml flow in Golang and I used go-saml package. In the go-saml example, they used different Identity Provider. I want to change this Identity Provider with different company IP. Also, I tried to add different metadata xml which designed for my Identity Provider. Here is my code:
package main
import (
"crypto/rsa"
"crypto/tls"
"crypto/x509"
"fmt"
"net/http"
"net/url"
"os"
"github.com/crewjam/saml/samlsp"
)
func hello(w http.ResponseWriter, r *http.Request) {
fmt.Fprintf(w, "Hello, %s!", samlsp.AttributeFromContext(r.Context(), "cn"))
}
func main() {
keyPair, err := tls.LoadX509KeyPair("myservice.cert", "myservice.key")
if err != nil {
panic(err)
}
keyPair.Leaf, err = x509.ParseCertificate(keyPair.Certificate[0])
if err != nil {
panic(err)
}
xmlFile, _ := os.ReadFile("metadata.xml")
if err != nil {
fmt.Println(err)
}
metadata, err := samlsp.ParseMetadata(xmlFile)
if err != nil {
fmt.Println(err)
}
rootURL, err := url.Parse("http://localhost:8000")
if err != nil {
panic(err) // TODO handle error
}
samlSP, _ := samlsp.New(samlsp.Options{
URL: *rootURL,
Key: keyPair.PrivateKey.(*rsa.PrivateKey),
Certificate: keyPair.Leaf,
IDPMetadata: metadata,
})
app := http.HandlerFunc(hello)
http.Handle("/hello", samlSP.RequireAccount(app))
http.Handle("/saml/", samlSP)
http.ListenAndServe(":8000", nil)
}
Also, this is content of metadata:
<?xml version="1.0" encoding="utf-8"?>
<md:EntityDescriptor entityID="https://login.test.com.tr" ID="_4a04b975-8da9-4877-8603-935761262d34" xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata">
<md:IDPSSODescriptor ID="_7c693b4c-76dd-43c8-b5ef-5615d32ef154" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" WantAuthnRequestsSigned="true">
<md:KeyDescriptor>
<KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
<X509Data>
<X509Certificate>I will add Certificate</X509Certificate>
</X509Data>
</KeyInfo>
</md:KeyDescriptor>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://login.test.com.tr/SAML/SService.aspx" />
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://login.test.com.tr/SAML/SService.aspx" />
<md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</md:NameIDFormat>
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://login.test.com.tr/SAML/SService.aspx" />
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://login.test.com.tr/SAML/SService.aspx" />
</md:IDPSSODescriptor>
</md:EntityDescriptor>
The above file was given to me by my customer for test. I just changed link as "test". However when I try to reach "hello" path it routes me the right login page but it gives me an error: "The partner service provider http://localhost:8000/saml/metadata is not configured."