Search in sources :

Example 1 with SAML2SubjectConfirmation

use of org.forgerock.openam.sts.token.SAML2SubjectConfirmation in project OpenAM by OpenRock.

the class SoapSamlTokenProvider method createToken.

/**
     * @see org.apache.cxf.sts.token.provider.TokenProvider
     */
@Override
public TokenProviderResponse createToken(TokenProviderParameters tokenProviderParameters) {
    try {
        final TokenProviderResponse tokenProviderResponse = new TokenProviderResponse();
        final SAML2SubjectConfirmation subjectConfirmation = determineSubjectConfirmation(tokenProviderParameters);
        final SoapTokenProviderBase.AuthenticationContextMapperState mapperState = getAuthenticationContextMapperState(tokenProviderParameters);
        String authNContextClassRef;
        if (mapperState.isDelegatedContext()) {
            authNContextClassRef = authnContextMapper.getAuthnContextForDelegatedToken(mapperState.getSecurityPolicyBindingTraversalYield(), mapperState.getDelegatedToken());
        } else {
            authNContextClassRef = authnContextMapper.getAuthnContext(mapperState.getSecurityPolicyBindingTraversalYield());
        }
        ProofTokenState proofTokenState = null;
        if (SAML2SubjectConfirmation.HOLDER_OF_KEY.equals(subjectConfirmation)) {
            proofTokenState = getProofTokenState(tokenProviderParameters);
        }
        String assertion;
        try {
            assertion = getAssertion(authNContextClassRef, subjectConfirmation, proofTokenState);
        } catch (TokenCreationException e) {
            throw new AMSTSRuntimeException(e.getCode(), e.getMessage(), e);
        }
        Document assertionDocument = xmlUtilities.stringToDocumentConversion(assertion);
        if (assertionDocument == null) {
            logger.error("Could not turn assertion string returned from TokenGenerationService into DOM Document. " + "The assertion string: " + assertion);
            throw new AMSTSRuntimeException(ResourceException.INTERNAL_ERROR, "Could not turn assertion string returned from TokenGenerationService into DOM Document.");
        }
        final Element assertionElement = assertionDocument.getDocumentElement();
        tokenProviderResponse.setToken(assertionElement);
        final String tokenId = assertionElement.getAttributeNS(null, "ID");
        /*
            The tokenId cannot be null or empty because a reference to the issued token is created using this id in the wss
            security header in the RequestSecurityTokenResponse. A null or empty id will generate a cryptic error in the cxf
            runtime. And if we are dealing with an encrypted assertion, there is no ID attribute, so in this case,
            a random uuid should be generated, as I believe the id serves only to refer to the token within the
            security header, and does not have to be connected to the token itself. An encrypted SAML2 assertion only
            contains some information on the encryption method, the symmetric key used for encryption, itself encrypted
            with the recipient's public key, and the encrypted assertion. So if no ID attribute is present, we are dealing
            with an encrypted assertion, and will generate a random UUID to serve as the key id.
            */
        if (StringUtils.isEmpty(tokenId)) {
            tokenProviderResponse.setTokenId(UUID.randomUUID().toString());
        } else {
            tokenProviderResponse.setTokenId(tokenId);
        }
        return tokenProviderResponse;
    } finally {
        try {
            amSessionInvalidator.invalidateAMSessions(threadLocalAMTokenCache.getToBeInvalidatedAMSessionIds());
        } catch (Exception e) {
            String message = "Exception caught invalidating interim AMSession in SoapSamlTokenProvider: " + e;
            logger.warn(message, e);
        /*
                The fact that the interim OpenAM session was not invalidated should not prevent a token from being issued, so
                I will not throw a AMSTSRuntimeException
                */
        }
    }
}
Also used : SAML2SubjectConfirmation(org.forgerock.openam.sts.token.SAML2SubjectConfirmation) Element(org.w3c.dom.Element) AMSTSRuntimeException(org.forgerock.openam.sts.AMSTSRuntimeException) TokenProviderResponse(org.apache.cxf.sts.token.provider.TokenProviderResponse) SoapTokenProviderBase(org.forgerock.openam.sts.soap.token.provider.SoapTokenProviderBase) ProofTokenState(org.forgerock.openam.sts.user.invocation.ProofTokenState) Document(org.w3c.dom.Document) TokenCreationException(org.forgerock.openam.sts.TokenCreationException) AMSTSRuntimeException(org.forgerock.openam.sts.AMSTSRuntimeException) TokenMarshalException(org.forgerock.openam.sts.TokenMarshalException) ResourceException(org.forgerock.json.resource.ResourceException) TokenCreationException(org.forgerock.openam.sts.TokenCreationException)

Example 2 with SAML2SubjectConfirmation

use of org.forgerock.openam.sts.token.SAML2SubjectConfirmation in project OpenAM by OpenRock.

the class SAML2TokenCreationState method fromJson.

public static SAML2TokenCreationState fromJson(JsonValue jsonValue) throws TokenMarshalException {
    String subjectConfirmationString = jsonValue.get(SUBJECT_CONFIRMATION).asString();
    if (subjectConfirmationString == null) {
        throw new TokenMarshalException(ResourceException.BAD_REQUEST, "Value corresponding to " + SUBJECT_CONFIRMATION + " key is null");
    }
    SAML2SubjectConfirmation saml2SubjectConfirmation;
    try {
        saml2SubjectConfirmation = SAML2SubjectConfirmation.valueOf(subjectConfirmationString);
    } catch (IllegalArgumentException e) {
        throw new TokenMarshalException(ResourceException.BAD_REQUEST, "Invalid subject confirmation type specified.");
    }
    SAML2TokenStateBuilder builder = SAML2TokenCreationState.builder().saml2SubjectConfirmation(saml2SubjectConfirmation);
    JsonValue jsonProofToken = jsonValue.get(PROOF_TOKEN_STATE);
    if (!jsonProofToken.isNull()) {
        builder.proofTokenState(ProofTokenState.fromJson(jsonProofToken));
    }
    return builder.build();
}
Also used : SAML2SubjectConfirmation(org.forgerock.openam.sts.token.SAML2SubjectConfirmation) TokenMarshalException(org.forgerock.openam.sts.TokenMarshalException) JsonValue(org.forgerock.json.JsonValue)

Example 3 with SAML2SubjectConfirmation

use of org.forgerock.openam.sts.token.SAML2SubjectConfirmation in project OpenAM by OpenRock.

the class TokenRequestMarshallerImpl method createSAML2TokenProviderParameters.

private RestTokenProviderParameters<Saml2TokenCreationState> createSAML2TokenProviderParameters(final TokenTypeId inputTokenType, final JsonValue inputToken, final JsonValue desiredToken) throws TokenMarshalException {
    final SAML2SubjectConfirmation subjectConfirmation = getSubjectConfirmation(desiredToken);
    if (SAML2SubjectConfirmation.HOLDER_OF_KEY.equals(subjectConfirmation)) {
        final ProofTokenState proofTokenState = getProofTokenState(desiredToken);
        final Saml2TokenCreationState saml2TokenCreationState = new Saml2TokenCreationState(subjectConfirmation, proofTokenState);
        return new Saml2RestTokenProviderParameters(saml2TokenCreationState, inputTokenType, inputToken);
    } else {
        final Saml2TokenCreationState saml2TokenCreationState = new Saml2TokenCreationState(subjectConfirmation);
        return new Saml2RestTokenProviderParameters(saml2TokenCreationState, inputTokenType, inputToken);
    }
}
Also used : SAML2SubjectConfirmation(org.forgerock.openam.sts.token.SAML2SubjectConfirmation) Saml2TokenCreationState(org.forgerock.openam.sts.rest.token.provider.saml.Saml2TokenCreationState) Saml2RestTokenProviderParameters(org.forgerock.openam.sts.rest.operation.translate.Saml2RestTokenProviderParameters) ProofTokenState(org.forgerock.openam.sts.user.invocation.ProofTokenState)

Example 4 with SAML2SubjectConfirmation

use of org.forgerock.openam.sts.token.SAML2SubjectConfirmation in project OpenAM by OpenRock.

the class DefaultSubjectProvider method get.

public Subject get(String subjectId, String spAcsUrl, SAML2Config saml2Config, SAML2SubjectConfirmation subjectConfirmation, Date assertionIssueInstant, ProofTokenState proofTokenState) throws TokenCreationException {
    try {
        Subject subject = AssertionFactory.getInstance().createSubject();
        setNameIdentifier(subject, subjectId, saml2Config.getNameIdFormat());
        SubjectConfirmation subConfirmation = AssertionFactory.getInstance().createSubjectConfirmation();
        switch(subjectConfirmation) {
            case BEARER:
                subConfirmation.setMethod(SAML2Constants.SUBJECT_CONFIRMATION_METHOD_BEARER);
                /*
                    see section 4.1.4.2 of http://docs.oasis-open.org/security/saml/v2.0/saml-profiles-2.0-os.pdf -
                    Recipient attribute of SubjectConfirmation element must be set to the Service Provider
                    ACS url.
                     */
                SubjectConfirmationData bearerConfirmationData = AssertionFactory.getInstance().createSubjectConfirmationData();
                bearerConfirmationData.setRecipient(spAcsUrl);
                /*
                    see section 4.1.4.2 of http://docs.oasis-open.org/security/saml/v2.0/saml-profiles-2.0-os.pdf - NotBefore cannot
                    be set, but NotOnOrAfter must be set.
                     */
                bearerConfirmationData.setNotOnOrAfter(new Date(assertionIssueInstant.getTime() + (saml2Config.getTokenLifetimeInSeconds() * 1000)));
                subConfirmation.setSubjectConfirmationData(bearerConfirmationData);
                break;
            case SENDER_VOUCHES:
                subConfirmation.setMethod(SAML2Constants.SUBJECT_CONFIRMATION_METHOD_SENDER_VOUCHES);
                break;
            case HOLDER_OF_KEY:
                subConfirmation.setMethod(SAML2Constants.SUBJECT_CONFIRMATION_METHOD_HOLDER_OF_KEY);
                subConfirmation.setSubjectConfirmationData(getHoKSubjectConfirmationData(proofTokenState.getX509Certificate()));
                break;
            default:
                throw new TokenCreationException(ResourceException.INTERNAL_ERROR, "Unexpected SubjectConfirmation value in DefaultSubjectProvider: " + subjectConfirmation);
        }
        List<SubjectConfirmation> subjectConfirmationList = new ArrayList<>();
        subjectConfirmationList.add(subConfirmation);
        subject.setSubjectConfirmation(subjectConfirmationList);
        return subject;
    } catch (SAML2Exception e) {
        throw new TokenCreationException(ResourceException.INTERNAL_ERROR, "Exception caught setting subject confirmation state in DefaultSubjectProvider: " + e, e);
    }
}
Also used : SAML2Exception(com.sun.identity.saml2.common.SAML2Exception) SAML2SubjectConfirmation(org.forgerock.openam.sts.token.SAML2SubjectConfirmation) SubjectConfirmation(com.sun.identity.saml2.assertion.SubjectConfirmation) ArrayList(java.util.ArrayList) SubjectConfirmationData(com.sun.identity.saml2.assertion.SubjectConfirmationData) TokenCreationException(org.forgerock.openam.sts.TokenCreationException) Subject(com.sun.identity.saml2.assertion.Subject) Date(java.util.Date)

Aggregations

SAML2SubjectConfirmation (org.forgerock.openam.sts.token.SAML2SubjectConfirmation)4 TokenCreationException (org.forgerock.openam.sts.TokenCreationException)2 TokenMarshalException (org.forgerock.openam.sts.TokenMarshalException)2 ProofTokenState (org.forgerock.openam.sts.user.invocation.ProofTokenState)2 Subject (com.sun.identity.saml2.assertion.Subject)1 SubjectConfirmation (com.sun.identity.saml2.assertion.SubjectConfirmation)1 SubjectConfirmationData (com.sun.identity.saml2.assertion.SubjectConfirmationData)1 SAML2Exception (com.sun.identity.saml2.common.SAML2Exception)1 ArrayList (java.util.ArrayList)1 Date (java.util.Date)1 TokenProviderResponse (org.apache.cxf.sts.token.provider.TokenProviderResponse)1 JsonValue (org.forgerock.json.JsonValue)1 ResourceException (org.forgerock.json.resource.ResourceException)1 AMSTSRuntimeException (org.forgerock.openam.sts.AMSTSRuntimeException)1 Saml2RestTokenProviderParameters (org.forgerock.openam.sts.rest.operation.translate.Saml2RestTokenProviderParameters)1 Saml2TokenCreationState (org.forgerock.openam.sts.rest.token.provider.saml.Saml2TokenCreationState)1 SoapTokenProviderBase (org.forgerock.openam.sts.soap.token.provider.SoapTokenProviderBase)1 Document (org.w3c.dom.Document)1 Element (org.w3c.dom.Element)1