tuxtux59

tuxtux59

Hello,

I’m quite new to SAML and Samly, so do not hesitate if I do not provide enough information.

I’m trying to setup properly my Samly (static config) to worked with a local self hosted PingFederate instance.
For now I can reach PingFederate form but after submit SAML Challenge come to my Elixir app, SAMLY throws an error:

access_denied {{:badmatch, []}, [{:xmerl_dsig, :verify, 2, [file: '/Users/xxxx/.../app-umbrella/deps/esaml/src/xmerl_dsig.erl', line: 197]},
{:esaml_sp, :"-validate_assertion/3-fun-2-", 2...

I understand that assertions validation failed and assume that is related to either config in PingFederate side or SAMLY’s.

Here is my local SAMLY static config for my IDP

%{
      id: local_idp_id,
      sp_id: local_sp_id,
      base_url: "#{base_url}/#{local_idp_id}/sso",
      metadata_file: "metadata-pingfederate-local.xml",
      pre_session_create_pipeline: AppWeb.PingoneSamlPipeline,
      allow_idp_initiated_flow: true,
      use_redirect_for_req: false,
      sign_requests: true,
      sign_metadata: true,
      signed_assertion_in_resp: true,
      signed_envelopes_in_resp: false,
      nameid_format: :transient
    }

the related SP is configured and already used by other IDPs.

My frictions points are on some settings set up on PingFederate admin tool.
Here are some one of them:

  1. What value for nameid_format? The assertion creation allows 3 choices: Standard, Pseudonym and Transient. I’m only aware of persistent and transient for SAMLY config so I chose transient
  • STANDARD: Send the SP a known attribute value as the name identifier. The SP will often use account mapping to identify the user locally.
  • TRANSIENT: Send the SP an opaque, temporary value as the name identifier.
  1. What boolean values for sign_requests and signed_assertion_in_resp, in fact in PingFederate we can choose following properties for Signature Policy: Require digitally signed AuthN requests , Always Sign Assertion. and Sign Response As Required , I’ve only checked Always Sign Assertion to match sign_requests and signed_assertion_in_resp .
  2. I’ve checked SP-Initiated SSO to match allow_idp_initiated_flow.

I’ve read :badmatch error upon verifying response from ADFS · Issue #42 · handnot2/samly · GitHub and Why I am getting this badmatch error when trying to connect to websocket but without matching the current problem.

I’m a bit lost to find the right way to fix my configuration, so I’m looking for cross config matching.

Thanks by advance.

Showing Posts 1 to 2

kokolegorille

kokolegorille

That has been quite challenging to make it work…

Mainly I have been using default config from samly doc, but the thing really important is to set the right entity_id in the service_providers section.

I am using transient for nameid_format.

Once done, I started to receive valid challenge.

It took also some time to configure https. I made some fake certifs, but it worked much better with the real one.

BTW I don’t know about PingFederate SP, but I made it work with Azure Federation Services.

tuxtux59

tuxtux59 OP

Hello back @kokolegorille ,
Sorry for the delay !
Thanks for the answer . I had already an https configuration so that was not a problem but it’s a good idea to point this !
I succeeded by setting up the right entity_id in pingfederate and in my app.
I was already using transient as nameid_format and indeed it’s the right one accordingly to my pingfederate setup.

I don’t know really what was the fix but I think it’s a global thing between entity_id and boolean values such as signed_assertion_in_resp . In fact it’s related to my custom pingfederate config so there is no absolute config for a pingfederate config in SAMLY, always related to the config.

Thanks for your answer and your time again @kokolegorille .

— All posts loaded —

Where Next? Top

Trending in Questions Top

RSP87
I’m working on a project that simulates the bumbl example in the programming phoenix book. It acts almost like an email client. We have a...
New
nseaSeb
Hello, I know there is an approach for handling lists that allows for optimized traversal, but I can’t recall the specific method (somet...
New
RemyXRenard
I’m seeing that a list inside a Kino.DataTable will be interpreted as a charlist, even if the Kino.configure() is set to charlists: :as_l...
New
velrest
So my question is quite simple and i have found no conclusive answer on forum, google or AI. Should we use :erlang.float for Integer to ...
New
brecabral
Documentation While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
samoloth
Hi, I’ve just set up an application with ash_authentication. There is only magic link strategy for now, so there is no confirmation add o...
New
FlyingNoodle
If a change or preparation module uses Ash.Changeset.get_argument/2 or Ash.Query.get_argument/2 (or any of the other get_argument functio...
New

Other Trending Topics Top

mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
marciok
Hi there! We created Gust: A task orchestrator inspired by Airflow. For those who have never heard about Aiflow, it’s a Python-based wor...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Dmk
Xamal is a deployment tool for Elixir apps that deploys native releases to bare metal servers over SSH. It’s a port of GitHub - basecamp/...
New
netoum
Corex is an accessible, unstyled UI component library for Phoenix that integrates Zag.js state machines using Vanilla JavaScript and Live...
New
webofbits
With AI doing more of the implementation work, I’ve been wondering how much coding I should deliberately keep doing myself. My main conc...
#ai
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews