I am having an issue trying to get SSO to work with Azure AD using SAML2. I have these properties set:
FYI, where there are "..."'s these are replacing the legitimate UUID's.
Dependencies:
Spring boot version is 2.7.0
implementation 'org.springframework.boot:spring-boot-starter-security'
implementation 'org.springframework.security:spring-security-saml2-service-provider:5.7.2'
application.yaml
spring:
security:
saml2:
relyingparty:
registration:
SomeReg:
entity-id: SomeEntity
signing.credentials:
- private-key-location: 'classpath:saml/signingPriv.pem'
certificate-location: 'classpath:saml/signing.pem'
identityprovider:
entity-id: https://sts.windows.net/.../
verification.credentials:
- certificate-location: 'classpath:saml/AzureAD.cer'
singlesignon.url: 'https://login.microsoftonline.com/.../saml2'
singlesignon.sign-request: true
This is the response I have captured in SAML Trace:
<samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
ID="_295ce6a6-5964-440e-9842-03dac25e7cff"
Version="2.0"
IssueInstant="2022-08-07T02:00:33.331Z"
Destination="https://localhost:8443/login/saml2/sso/PhyCompSys"
InResponseTo="ARQ1acff8a-1488-4c17-8f69-c185aca3bd65"
>
<Issuer xmlns="urn:oasis:names:tc:SAML:2.0:assertion">https://sts.windows.net/.../</Issuer>
<samlp:Status>
<samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success" />
</samlp:Status>
<Assertion xmlns="urn:oasis:names:tc:SAML:2.0:assertion"
ID="_e27b35ca-7a11-45a5-8ddb-182358f17800"
IssueInstant="2022-08-07T02:00:33.315Z"
Version="2.0"
>
<Issuer>https://sts.windows.net/.../</Issuer>
<Signature xmlns="http://www.w3.org/2000/09/xmldsig#">
<SignedInfo>
<CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
<SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" />
<Reference URI="#_e27b35ca-7a11-45a5-8ddb-182358f17800">
<Transforms>
<Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" />
<Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
</Transforms>
<DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" />
<DigestValue>hB9ZjSQ0SVYW57JhO3mKYQ7bN3gUgVNx2fOUB2NYq/Y=</DigestValue>
</Reference>
</SignedInfo>
<SignatureValue>...</SignatureValue>
<KeyInfo>
<X509Data>
<X509Certificate>...</X509Certificate>
</X509Data>
</KeyInfo>
</Signature>
<Subject>
<NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress">user@foo.com</NameID>
<SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
<SubjectConfirmationData InResponseTo="ARQ1acff8a-1488-4c17-8f69-c185aca3bd65"
NotOnOrAfter="2022-08-07T03:00:33.221Z"
Recipient="https://localhost:8443/login/saml2/sso/SomeEntity"
/>
</SubjectConfirmation>
</Subject>
<Conditions NotBefore="2022-08-07T01:55:33.221Z"
NotOnOrAfter="2022-08-07T03:00:33.221Z"
>
<AudienceRestriction>
<Audience>SomeAudience</Audience>
</AudienceRestriction>
</Conditions>
<AttributeStatement>
<Attribute Name="http://schemas.microsoft.com/identity/claims/tenantid">
<AttributeValue>...</AttributeValue>
</Attribute>
<Attribute Name="http://schemas.microsoft.com/identity/claims/objectidentifier">
<AttributeValue>debe9fa9-dc1c-432a-b700-59ebf78549c2</AttributeValue>
</Attribute>
<Attribute Name="http://schemas.microsoft.com/identity/claims/displayname">
<AttributeValue>User Test</AttributeValue>
</Attribute>
<Attribute Name="http://schemas.microsoft.com/identity/claims/identityprovider">
<AttributeValue>https://sts.windows.net/.../</AttributeValue>
</Attribute>
<Attribute Name="http://schemas.microsoft.com/claims/authnmethodsreferences">
<AttributeValue>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</AttributeValue>
</Attribute>
<Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname">
<AttributeValue>Test</AttributeValue>
</Attribute>
<Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname">
<AttributeValue>Test</AttributeValue>
</Attribute>
<Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress">
<AttributeValue>user@foo.com</AttributeValue>
</Attribute>
<Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name">
<AttributeValue>user@foo.com</AttributeValue>
</Attribute>
</AttributeStatement>
<AuthnStatement AuthnInstant="2022-08-06T15:36:02.335Z"
SessionIndex="_e27b35ca-7a11-45a5-8ddb-182358f17800"
>
<AuthnContext>
<AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</AuthnContextClassRef>
</AuthnContext>
</AuthnStatement>
</Assertion>
</samlp:Response>
This results in this warning from OpenSAML:
Signature of Assertion '_e27b35ca-7a11-45a5-8ddb-182358f17800' from Issuer 'https://sts.windows.net/.../' was not valid
Which fails the login attempt.
I found one other post that suggested the issuer URL should be https://sts.windows.net/.../v2, I have tried that in the entity-id but OpenSAML always takes the value in the response to check the signature.
Has anyone else encountered this problem?