Invalid signature on SAML response using Spring Security SAML2 Azure

Viewed 97

I am having an issue trying to get SSO to work with Azure AD using SAML2. I have these properties set:

FYI, where there are "..."'s these are replacing the legitimate UUID's.

Dependencies:

    Spring boot version is 2.7.0

    implementation 'org.springframework.boot:spring-boot-starter-security'
    implementation 'org.springframework.security:spring-security-saml2-service-provider:5.7.2'

application.yaml

spring:
  security:
    saml2:
      relyingparty:
        registration:
          SomeReg:
            entity-id: SomeEntity
            signing.credentials:
              - private-key-location: 'classpath:saml/signingPriv.pem'
                certificate-location: 'classpath:saml/signing.pem'
            identityprovider:
              entity-id: https://sts.windows.net/.../
              verification.credentials:
                - certificate-location: 'classpath:saml/AzureAD.cer'
              singlesignon.url: 'https://login.microsoftonline.com/.../saml2'
              singlesignon.sign-request: true

This is the response I have captured in SAML Trace:

<samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
                ID="_295ce6a6-5964-440e-9842-03dac25e7cff"
                Version="2.0"
                IssueInstant="2022-08-07T02:00:33.331Z"
                Destination="https://localhost:8443/login/saml2/sso/PhyCompSys"
                InResponseTo="ARQ1acff8a-1488-4c17-8f69-c185aca3bd65"
                >
    <Issuer xmlns="urn:oasis:names:tc:SAML:2.0:assertion">https://sts.windows.net/.../</Issuer>
    <samlp:Status>
        <samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success" />
    </samlp:Status>
    <Assertion xmlns="urn:oasis:names:tc:SAML:2.0:assertion"
               ID="_e27b35ca-7a11-45a5-8ddb-182358f17800"
               IssueInstant="2022-08-07T02:00:33.315Z"
               Version="2.0"
               >
        <Issuer>https://sts.windows.net/.../</Issuer>
        <Signature xmlns="http://www.w3.org/2000/09/xmldsig#">
            <SignedInfo>
                <CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
                <SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" />
                <Reference URI="#_e27b35ca-7a11-45a5-8ddb-182358f17800">
                    <Transforms>
                        <Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" />
                        <Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
                    </Transforms>
                    <DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" />
                    <DigestValue>hB9ZjSQ0SVYW57JhO3mKYQ7bN3gUgVNx2fOUB2NYq/Y=</DigestValue>
                </Reference>
            </SignedInfo>
            <SignatureValue>...</SignatureValue>
            <KeyInfo>
                <X509Data>
                    <X509Certificate>...</X509Certificate>
                </X509Data>
            </KeyInfo>
        </Signature>
        <Subject>
            <NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress">user@foo.com</NameID>
            <SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
                <SubjectConfirmationData InResponseTo="ARQ1acff8a-1488-4c17-8f69-c185aca3bd65"
                                         NotOnOrAfter="2022-08-07T03:00:33.221Z"
                                         Recipient="https://localhost:8443/login/saml2/sso/SomeEntity"
                                         />
            </SubjectConfirmation>
        </Subject>
        <Conditions NotBefore="2022-08-07T01:55:33.221Z"
                    NotOnOrAfter="2022-08-07T03:00:33.221Z"
                    >
            <AudienceRestriction>
                <Audience>SomeAudience</Audience>
            </AudienceRestriction>
        </Conditions>
        <AttributeStatement>
            <Attribute Name="http://schemas.microsoft.com/identity/claims/tenantid">
                <AttributeValue>...</AttributeValue>
            </Attribute>
            <Attribute Name="http://schemas.microsoft.com/identity/claims/objectidentifier">
                <AttributeValue>debe9fa9-dc1c-432a-b700-59ebf78549c2</AttributeValue>
            </Attribute>
            <Attribute Name="http://schemas.microsoft.com/identity/claims/displayname">
                <AttributeValue>User Test</AttributeValue>
            </Attribute>
            <Attribute Name="http://schemas.microsoft.com/identity/claims/identityprovider">
                <AttributeValue>https://sts.windows.net/.../</AttributeValue>
            </Attribute>
            <Attribute Name="http://schemas.microsoft.com/claims/authnmethodsreferences">
                <AttributeValue>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</AttributeValue>
            </Attribute>
            <Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname">
                <AttributeValue>Test</AttributeValue>
            </Attribute>
            <Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname">
                <AttributeValue>Test</AttributeValue>
            </Attribute>
            <Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress">
                <AttributeValue>user@foo.com</AttributeValue>
            </Attribute>
            <Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name">
                <AttributeValue>user@foo.com</AttributeValue>
            </Attribute>
        </AttributeStatement>
        <AuthnStatement AuthnInstant="2022-08-06T15:36:02.335Z"
                        SessionIndex="_e27b35ca-7a11-45a5-8ddb-182358f17800"
                        >
            <AuthnContext>
                <AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</AuthnContextClassRef>
            </AuthnContext>
        </AuthnStatement>
    </Assertion>
</samlp:Response>

This results in this warning from OpenSAML:

Signature of Assertion '_e27b35ca-7a11-45a5-8ddb-182358f17800' from Issuer 'https://sts.windows.net/.../' was not valid

Which fails the login attempt.

I found one other post that suggested the issuer URL should be https://sts.windows.net/.../v2, I have tried that in the entity-id but OpenSAML always takes the value in the response to check the signature.

Has anyone else encountered this problem?

0 Answers
Related