gpt4 book ai didi

ruby-on-rails-4 - Rails omniauth-saml + devise + ADFS 问题

转载 作者:行者123 更新时间:2023-12-04 17:58:42 25 4
gpt4 key购买 nike

我正在尝试将我们的 ADFS 登录与我们的应用程序集成,该应用程序结合使用 ActiveAdmin 和 Devise。为此,我成功添加了 omniauth-saml。应用程序现在重定向到 ADFS,登录成功但回调失败。我收到错误 Invalid ticket .

当我尝试在 omniauth-saml 库中查看服务器上的响应时,我可以看到它说:@document=<UNDEFINED> ... </>@decrypted_document=<UNDEFINED> ... </>

initializers/devise.rb阅读:

config.omniauth :saml,
assertion_consumer_service_url: 'https://my_server/admin/auth/saml/callback',
issuer: 'https://my_server/',
authn_context: 'urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport',
idp_sso_target_url: 'https://my_adfs_server/adfs/ls/',
assertion_consumer_service_binding: 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST',
assertion_consumer_logout_service_binding: 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
idp_sso_target_url_runtime_params: {original_request_param: :mapped_idp_param},
name_identifier_format: 'urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress',
idp_cert: idp_certificate,
request_attributes: {},
attribute_statements: {email: ['http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress'],
name: ['http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name'],
first_name: ['http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname'],
last_name: ['http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname']},
private_key: sp_key,
certificate: sp_certificate,
security: {authn_requests_signed: true,
logout_requests_signed: true,
logout_responses_signed: true,
metadata_signed: true,
digest_method: XMLSecurity::Document::SHA1,
signature_method: XMLSecurity::Document::RSA_SHA1,
embed_sign: false}

我该如何解决这个问题?

添加:REXML::Document 似乎无法解密 SAML 响应中的 Cypher。它无法在没有错误的情况下这样做。当我尝试使用 https://www.samltool.com/decrypt.php 自己做时不过我看不出有什么问题。

最佳答案

我从 ADFS 元数据 xml 中选择了错误的证书。需要选择签名,而不是加密证书。

通过使用 https://www.samltool.com/validate_response.php 找到了这个用于调试。

关于ruby-on-rails-4 - Rails omniauth-saml + devise + ADFS 问题,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/37925502/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com