Uploaded image for project: 'CXF'
  1. CXF
  2. CXF-7941

SamlValidator does not work with chain trust

Attach filesAttach ScreenshotVotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Major
    • Resolution: Not A Problem
    • Affects Version/s: 3.2.7
    • Fix Version/s: None
    • Component/s: WS-* Components
    • Labels:
      None
    • Estimated Complexity:
      Unknown

      Description

      As explained here http://coheigea.blogspot.com/2012/08/subject-dn-certificate-constraint.html, WSS4J supports specifying constraints on the subject DN of the certificate used for signature validation.

      We have successfully applied "direct trust" when receiving SOAP requests containing a signed SAML token.

      We attempted to migrate to "chain trust" by removing the certificate used to sign the requests from the Merlin trust store, and setting an appropriate Subject DN Cert Constraint.

      It did not work. Our analysis is that WSS4J's SamlValidator is not able to handle a scenario where the certificate used to sign the requests is not in the trust store. The problem seems to be in the method findPublicKeyInKeyStore() of Merlin.java.

      We were able to make chain trust (and the Subject DN Cert Constraint) work by including the needed PKI code in a customised SamlValidator, but we would rather not go this route.

      Please fix chain trust in WSS4J SAML validation.

        Attachments

        1. stacktrace-request-test-broken.txt
          5 kB
          Tomas Vanhala
        2. request-test-working-sanitised.xml
          7 kB
          Tomas Vanhala
        3. request-test-broken-sanitised.xml
          8 kB
          Tomas Vanhala
        4. request-real-sanitised.xml
          6 kB
          Tomas Vanhala
        5. obsolete-code.txt
          7 kB
          Tomas Vanhala
        6. cxf7941.zip
          11 kB
          Tomas Vanhala

          Activity

            People

            • Assignee:
              coheigea Colm O hEigeartaigh
              Reporter:
              tomasv Tomas Vanhala

              Dates

              • Created:
                Updated:
                Resolved:

                Issue deployment