Identity Server does not validate SAML LogoutRequest Signature





.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty{ height:90px;width:728px;box-sizing:border-box;
}







0















I've got WSO2 IS running and a service provider that has SAML inbound authentication set up. I've enabled the "Enable Signature Validation in Authentication Requests and Logout Requests" checkbox for the SAMl service provider.



If I send an AuthnRequest that is not properly signed, it will error. However, if I send a LogoutRequest with no signature (or with a signature made from a completely different cert/key), it will log my user out without error. How can I enable actual signature validation WSO2 IS?



I'm running the latest WSO2 Docker Container. I believe that is IS 5.7.0 according to this startup logging:




Starting WSO2 Carbon...
Operating System : Linux 4.9.93-linuxkit-aufs, amd64
Java Home : /home/wso2carbon/java/jre
Java Version : 1.8.0_144
Java VM : Java HotSpot(TM) 64-Bit Server VM 25.144-b01,Oracle Corporation
Carbon Home : /home/wso2carbon/wso2is-5.7.0
Java Temp Dir : /home/wso2carbon/wso2is-5.7.0/tmp










share|improve this question





























    0















    I've got WSO2 IS running and a service provider that has SAML inbound authentication set up. I've enabled the "Enable Signature Validation in Authentication Requests and Logout Requests" checkbox for the SAMl service provider.



    If I send an AuthnRequest that is not properly signed, it will error. However, if I send a LogoutRequest with no signature (or with a signature made from a completely different cert/key), it will log my user out without error. How can I enable actual signature validation WSO2 IS?



    I'm running the latest WSO2 Docker Container. I believe that is IS 5.7.0 according to this startup logging:




    Starting WSO2 Carbon...
    Operating System : Linux 4.9.93-linuxkit-aufs, amd64
    Java Home : /home/wso2carbon/java/jre
    Java Version : 1.8.0_144
    Java VM : Java HotSpot(TM) 64-Bit Server VM 25.144-b01,Oracle Corporation
    Carbon Home : /home/wso2carbon/wso2is-5.7.0
    Java Temp Dir : /home/wso2carbon/wso2is-5.7.0/tmp










    share|improve this question

























      0












      0








      0








      I've got WSO2 IS running and a service provider that has SAML inbound authentication set up. I've enabled the "Enable Signature Validation in Authentication Requests and Logout Requests" checkbox for the SAMl service provider.



      If I send an AuthnRequest that is not properly signed, it will error. However, if I send a LogoutRequest with no signature (or with a signature made from a completely different cert/key), it will log my user out without error. How can I enable actual signature validation WSO2 IS?



      I'm running the latest WSO2 Docker Container. I believe that is IS 5.7.0 according to this startup logging:




      Starting WSO2 Carbon...
      Operating System : Linux 4.9.93-linuxkit-aufs, amd64
      Java Home : /home/wso2carbon/java/jre
      Java Version : 1.8.0_144
      Java VM : Java HotSpot(TM) 64-Bit Server VM 25.144-b01,Oracle Corporation
      Carbon Home : /home/wso2carbon/wso2is-5.7.0
      Java Temp Dir : /home/wso2carbon/wso2is-5.7.0/tmp










      share|improve this question














      I've got WSO2 IS running and a service provider that has SAML inbound authentication set up. I've enabled the "Enable Signature Validation in Authentication Requests and Logout Requests" checkbox for the SAMl service provider.



      If I send an AuthnRequest that is not properly signed, it will error. However, if I send a LogoutRequest with no signature (or with a signature made from a completely different cert/key), it will log my user out without error. How can I enable actual signature validation WSO2 IS?



      I'm running the latest WSO2 Docker Container. I believe that is IS 5.7.0 according to this startup logging:




      Starting WSO2 Carbon...
      Operating System : Linux 4.9.93-linuxkit-aufs, amd64
      Java Home : /home/wso2carbon/java/jre
      Java Version : 1.8.0_144
      Java VM : Java HotSpot(TM) 64-Bit Server VM 25.144-b01,Oracle Corporation
      Carbon Home : /home/wso2carbon/wso2is-5.7.0
      Java Temp Dir : /home/wso2carbon/wso2is-5.7.0/tmp







      wso2 wso2is wso2carbon






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Nov 27 '18 at 0:58









      macraelmacrael

      8637




      8637
























          1 Answer
          1






          active

          oldest

          votes


















          1














          Seems the signature validation [1] is skipping in the logout request due to an issue in the code. Please refer the git issue [2] to track this.



          [1] https://github.com/wso2-extensions/identity-inbound-auth-saml/blob/ee338982c1add8f75f1132a6b3bacb30cee7989b/components/org.wso2.carbon.identity.sso.saml/src/main/java/org/wso2/carbon/identity/sso/saml/processors/SPInitLogoutRequestProcessor.java#L130

          [2] https://github.com/wso2/product-is/issues/4048






          share|improve this answer
























            Your Answer






            StackExchange.ifUsing("editor", function () {
            StackExchange.using("externalEditor", function () {
            StackExchange.using("snippets", function () {
            StackExchange.snippets.init();
            });
            });
            }, "code-snippets");

            StackExchange.ready(function() {
            var channelOptions = {
            tags: "".split(" "),
            id: "1"
            };
            initTagRenderer("".split(" "), "".split(" "), channelOptions);

            StackExchange.using("externalEditor", function() {
            // Have to fire editor after snippets, if snippets enabled
            if (StackExchange.settings.snippets.snippetsEnabled) {
            StackExchange.using("snippets", function() {
            createEditor();
            });
            }
            else {
            createEditor();
            }
            });

            function createEditor() {
            StackExchange.prepareEditor({
            heartbeatType: 'answer',
            autoActivateHeartbeat: false,
            convertImagesToLinks: true,
            noModals: true,
            showLowRepImageUploadWarning: true,
            reputationToPostImages: 10,
            bindNavPrevention: true,
            postfix: "",
            imageUploader: {
            brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
            contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
            allowUrls: true
            },
            onDemand: true,
            discardSelector: ".discard-answer"
            ,immediatelyShowMarkdownHelp:true
            });


            }
            });














            draft saved

            draft discarded


















            StackExchange.ready(
            function () {
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53491302%2fidentity-server-does-not-validate-saml-logoutrequest-signature%23new-answer', 'question_page');
            }
            );

            Post as a guest















            Required, but never shown

























            1 Answer
            1






            active

            oldest

            votes








            1 Answer
            1






            active

            oldest

            votes









            active

            oldest

            votes






            active

            oldest

            votes









            1














            Seems the signature validation [1] is skipping in the logout request due to an issue in the code. Please refer the git issue [2] to track this.



            [1] https://github.com/wso2-extensions/identity-inbound-auth-saml/blob/ee338982c1add8f75f1132a6b3bacb30cee7989b/components/org.wso2.carbon.identity.sso.saml/src/main/java/org/wso2/carbon/identity/sso/saml/processors/SPInitLogoutRequestProcessor.java#L130

            [2] https://github.com/wso2/product-is/issues/4048






            share|improve this answer




























              1














              Seems the signature validation [1] is skipping in the logout request due to an issue in the code. Please refer the git issue [2] to track this.



              [1] https://github.com/wso2-extensions/identity-inbound-auth-saml/blob/ee338982c1add8f75f1132a6b3bacb30cee7989b/components/org.wso2.carbon.identity.sso.saml/src/main/java/org/wso2/carbon/identity/sso/saml/processors/SPInitLogoutRequestProcessor.java#L130

              [2] https://github.com/wso2/product-is/issues/4048






              share|improve this answer


























                1












                1








                1







                Seems the signature validation [1] is skipping in the logout request due to an issue in the code. Please refer the git issue [2] to track this.



                [1] https://github.com/wso2-extensions/identity-inbound-auth-saml/blob/ee338982c1add8f75f1132a6b3bacb30cee7989b/components/org.wso2.carbon.identity.sso.saml/src/main/java/org/wso2/carbon/identity/sso/saml/processors/SPInitLogoutRequestProcessor.java#L130

                [2] https://github.com/wso2/product-is/issues/4048






                share|improve this answer













                Seems the signature validation [1] is skipping in the logout request due to an issue in the code. Please refer the git issue [2] to track this.



                [1] https://github.com/wso2-extensions/identity-inbound-auth-saml/blob/ee338982c1add8f75f1132a6b3bacb30cee7989b/components/org.wso2.carbon.identity.sso.saml/src/main/java/org/wso2/carbon/identity/sso/saml/processors/SPInitLogoutRequestProcessor.java#L130

                [2] https://github.com/wso2/product-is/issues/4048







                share|improve this answer












                share|improve this answer



                share|improve this answer










                answered Nov 28 '18 at 5:53









                ashenswashensw

                546713




                546713
































                    draft saved

                    draft discarded




















































                    Thanks for contributing an answer to Stack Overflow!


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid



                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.


                    To learn more, see our tips on writing great answers.




                    draft saved


                    draft discarded














                    StackExchange.ready(
                    function () {
                    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53491302%2fidentity-server-does-not-validate-saml-logoutrequest-signature%23new-answer', 'question_page');
                    }
                    );

                    Post as a guest















                    Required, but never shown





















































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown

































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown







                    Popular posts from this blog

                    Wiesbaden

                    Marschland

                    Dieringhausen