WSS4J
  1. WSS4J
  2. WSS-90

SamlUtil.java throws XMLSecurityException when SAML SubjectConfirmation element doesn't have KeyInfo child

    Details

    • Type: Bug Bug
    • Status: Closed
    • Priority: Critical Critical
    • Resolution: Won't Fix
    • Affects Version/s: 1.5.6
    • Fix Version/s: 1.5.7, 1.6
    • Component/s: None
    • Labels:
      None
    • Environment:
      Windows XP, Axis2 1.3, WSS4J 1.5.3,

      Description

      The SAML Core 1.1 specification mentions that the <ds:KeyInfo> element is optional under the <SubjectConfirmation> element (under <Subject>).

      The following call fails when the incoming SAML assertion contains a <subjectconfirmation> element without a KeyInfo child element:

      Element e = samlSubj.getKeyInfo(); [ Line 122]
      X509Certificate[] certs = null;
      try {
      KeyInfo ki = new KeyInfo(e, null);

      The constructor KeyInfo(e, null) fails and throws a XMLSecurityException when e is null (which is true when samlSubj.getKeyInfo() returns null)

        Activity

        Hide
        Colm O hEigeartaigh added a comment -


        The above code is for processing holder-of-key assertions, where the spec mandates that a KeyInfo element is required for SubjectConfirmation, so marking this as in-valid.

        Show
        Colm O hEigeartaigh added a comment - The above code is for processing holder-of-key assertions, where the spec mandates that a KeyInfo element is required for SubjectConfirmation, so marking this as in-valid.
        Hide
        Colm O hEigeartaigh added a comment -


        A triage of possible additional fixes for 1.5.5

        Show
        Colm O hEigeartaigh added a comment - A triage of possible additional fixes for 1.5.5
        Hide
        Steve LeGault added a comment -

        I generated a sender-vouches SAML Assertion with WSS4J and fed it back to Axis2 with SOAPUI and I get this exception.

        Show
        Steve LeGault added a comment - I generated a sender-vouches SAML Assertion with WSS4J and fed it back to Axis2 with SOAPUI and I get this exception.

          People

          • Assignee:
            Ruchith Udayanga Fernando
            Reporter:
            Murali Gunasekaran
          • Votes:
            1 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:

              Development