TT Lab
Get started
Learn Learning paths Courses

Enterprise Authentication Integration

Taking a SAML Assertion Apart

Continue in TT Lab

Goal

You decode a SAML Response in its real form, extract the Issuer, NameID, Conditions, attributes, and signature elements yourself, and write up the items an SP must verify.

Why it matters

SAML integration is usually handled by a library, but when an outage occurs, you end up looking at the XML directly. When you receive an error message such as "Audience mismatch," "NotOnOrAfter exceeded," or "InResponseTo missing," you need to know where in the document to look. And the real purpose of this lab is to understand the pitfalls of signature verification. An XML Signature Wrapping attack creates a state where the signature verification passes but the data the app reads is fake. Once you confirm on the document that "is the signature valid" and "is the node I am reading the signed node" are different questions, you will be able to explain for yourself why you must not implement SAML directly.

Steps

  1. Decode /opt/lab/fixtures/auth/saml/response.b64 and save it as /root/saml/response.xml. It must be valid XML.
  2. Create /root/saml/head.txt. It has four lines, in the format below.
    issuer=<Response 의 Issuer 값>
    destination=<Destination 속성>
    inresponseto=<InResponseTo 속성>
    status=<StatusCode 의 Value 속성>
    
  3. Create /root/saml/subject.txt. It has two lines.
    nameid=<NameID 값>
    format=<NameID 의 Format 속성>
    
  4. Create /root/saml/conditions.txt. It has four lines.
    notbefore=<NotBefore>
    notonorafter=<NotOnOrAfter>
    audience=<Audience 값>
    valid=<현재 시각 기준 유효하면 Y, 아니면 N>
    
  5. Extract the attributes of the AttributeStatement and create /root/saml/attrs.csv. The first line is name,value, sorted by name in ascending order.
  6. Create /root/saml/sig.txt. It has three lines.
    reference_uri=<Reference 의 URI 속성>
    digest_alg=<DigestMethod 의 Algorithm 속성>
    signature_alg=<SignatureMethod 의 Algorithm 속성>
    
  7. Restore the contents of the X509Certificate in the XML to PEM format and save it to /root/saml/idp.pem. openssl x509 -in /root/saml/idp.pem -noout -subject must succeed.
  8. Write /root/saml/checklist.md. List 7 or more items the SP must verify, and add one line to each item about the risk if verification fails. The body must contain all seven words Audience, NotOnOrAfter, InResponseTo, Destination, Issuer, 서명 (signature), and 재사용 (reuse).

Notes

Decode the SAMLResponse

Decode /opt/lab/fixtures/auth/saml/response.b64 and save it as /root/saml/response.xml. It must be valid XML.

The SAMLResponse parameter is base64. Also remember that with the POST binding there is no compression, while with the Redirect binding deflate compression is added.

Extract the Response header information

Create /root/saml/head.txt. It has four lines, in the format below.

issuer=<Response 의 Issuer 값>
destination=<Destination 속성>
inresponseto=<InResponseTo 속성>
status=<StatusCode 의 Value 속성>

This is XML with several namespaces. In xmlstarlet, if you use the method of finding by local name, you are not shaken by the prefixes.

NameID and its format

Create /root/saml/subject.txt. It has two lines.

nameid=<NameID 값>
format=<NameID 의 Format 속성>

The way the SP identifies users differs depending on what the NameID's Format is. Think about the difference between persistent and transient.

Check the validity time and audience

Create /root/saml/conditions.txt. It has four lines.

notbefore=<NotBefore>
notonorafter=<NotOnOrAfter>
audience=<Audience 값>
valid=<현재 시각 기준 유효하면 Y, 아니면 N>

NotOnOrAfter means "invalid after this time." Judge by comparing it with the current time. This fixture was issued in the past.

Extract attributes

Extract the attributes of the AttributeStatement and create /root/saml/attrs.csv. The first line is name,value, sorted by name in ascending order.

Inside AttributeStatement there are several Attribute elements, each with one or more values. Pair up the names and values and sort them.

Check the signature element

Create /root/saml/sig.txt. It has three lines.

reference_uri=<Reference 의 URI 속성>
digest_alg=<DigestMethod 의 Algorithm 속성>
signature_alg=<SignatureMethod 의 Algorithm 속성>

The key is what the Reference's URI points to. Checking whether it is the same as the node we actually read is half of signature verification.

Restore the IdP certificate

Restore the contents of the X509Certificate in the XML to PEM format and save it to /root/saml/idp.pem. openssl x509 -in /root/saml/idp.pem -noout -subject must succeed.

The content of the X509Certificate element holds only the body (base64) of the PEM. You must add the header and footer and insert line breaks for openssl to read it.

SP verification checklist

Write /root/saml/checklist.md. List 7 or more items the SP must verify, and add one line to each item about the risk if verification fails. The body must contain all seven words Audience, NotOnOrAfter, InResponseTo, Destination, Issuer, 서명 (signature), and 재사용 (reuse).

"Is the signature valid" and "is the node I am reading the signed node" are different questions. This difference is the core of the XML Signature Wrapping attack.