You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

pac4j SAML SP连接Hana IDP无请求送达问题排查求助

问题描述

我们已成功使用pac4j创建SP元数据,下一步尝试从应用连接Hana IDP。参考文档和论坛示例编写代码后,Hana IDP未收到任何请求,请求排查代码中遗漏的关键配置。

代码片段

SAML2Configuration cfg = new SAML2Configuration("sampletestKeystore.jks", "Password@123", "Password@1231", "idp_metadata.xml");  //Hana IDP Metadata

cfg.setMaximumAuthenticationLifetime(6000);

cfg.setServiceProviderEntityId("BOE_SP_ID");

cfg.setServiceProviderMetadataPath("sp-meta-downloaded_Rajib.xml");

cfg.setPostLogoutURL(http://xx.xxx.xxx.xxx:8080/SampleWeb/logout.html);

cfg.setSpLogoutRequestBindingType(http://xx.xxx.xxx.xxx:8080/SampleWeb/logoutbinding.html);

SAML2Client saml2Client = new SAML2Client(cfg);

saml2Client.setName("BOE Client");

saml2Client.setCallbackUrl(http:// xx.xxx.xxx.xxx:8080/SampleWeb/BOE.html);

final Clients clients = new Clients();

clients.setClients(saml2Client);

Pac4j运行日志

2024-07-17 05:58:34 INFO  org.pac4j.saml.util.Configuration - Bootstrapping OpenSAML configuration via Pac4j...
2024-07-17 05:58:34 WARN  o.p.core.adapter.FrameworkAdapter - No framework adapter found. Using DefaultFrameworkAdapter...
2024-07-17 05:58:34 INFO  o.o.c.config.InitializationService - Initializing OpenSAML using the Java Services API
2024-07-17 05:58:35 INFO  o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2001/04/xmlenc#ripemd160
2024-07-17 05:58:35 INFO  o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2001/04/xmldsig-more#hmac-ripemd160
2024-07-17 05:58:35 INFO  o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2001/04/xmldsig-more#rsa-ripemd160
2024-07-17 05:58:35 INFO  o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2007/05/xmldsig-more#sha1-rsa-MGF1
2024-07-17 05:58:35 INFO  o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2007/05/xmldsig-more#sha224-rsa-MGF1
2024-07-17 05:58:35 INFO  o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2007/05/xmldsig-more#sha256-rsa-MGF1
2024-07-17 05:58:35 INFO  o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2007/05/xmldsig-more#sha384-rsa-MGF1
2024-07-17 05:58:35 INFO  o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2007/05/xmldsig-more#sha3-224-rsa-MGF1
2024-07-17 05:58:35 INFO  o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2007/05/xmldsig-more#sha3-256-rsa-MGF1
2024-07-17 05:58:35 INFO  o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2007/05/xmldsig-more#sha3-384-rsa-MGF1
2024-07-17 05:58:35 INFO  o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2007/05/xmldsig-more#sha3-512-rsa-MGF1
2024-07-17 05:58:35 INFO  o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2007/05/xmldsig-more#sha512-rsa-MGF1

已在pac4j用户组、官方demo及文档中调研过,仍未解决,求技术建议。


排查建议

1. 修正配置参数的类型与取值错误

代码中setPostLogoutURL、setSpLogoutRequestBindingType、setCallbackUrl的URL参数未加引号,会直接导致编译失败;且setSpLogoutRequestBindingType的取值错误,它需要传入SAML标准绑定类型的URI,而非应用URL。修正后代码示例:

cfg.setPostLogoutURL("http://xx.xxx.xxx.xxx:8080/SampleWeb/logout.html");
// 使用SAML标准绑定类型,比如HTTP-Redirect或HTTP-POST
cfg.setSpLogoutRequestBindingType("urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect");
saml2Client.setCallbackUrl("http://xx.xxx.xxx.xxx:8080/SampleWeb/BOE.html");

2. 补全框架适配器配置

日志提示No framework adapter found. Using DefaultFrameworkAdapter,默认适配器无法适配具体Web框架(如Spring MVC、Jakarta EE)的请求流转逻辑,会导致无法触发跳转至IDP的动作。需要:

  • 引入对应框架的pac4j依赖(如Spring MVC用pac4j-springmvc,Jakarta EE用pac4j-jakartaee)
  • 确保依赖自动加载了对应框架的适配器实现,或手动指定适配器

3. 验证SP与IDP配置同步

  • 确认sp-meta-downloaded_Rajib.xml中的实体ID与代码中BOE_SP_ID完全一致
  • 已将该SP元数据上传至Hana IDP,且IDP中配置的ACS URL与代码里的callbackUrl完全匹配(包括HTTP/HTTPS、端口、路径)
  • 检查Hana IDP要求的签名/加密算法,若日志中不可用的算法包含IDP要求的类型,需更换支持对应算法的密钥库

4. 触发认证流程

仅配置Clients对象不足以发起认证,需要在Web应用中添加pac4j的过滤器/拦截器:

  • 添加CallbackFilter处理SAML回调请求
  • 添加SecurityFilter保护需要认证的资源,或手动调用SAML2Client的redirect方法触发跳转至IDP的逻辑

5. 增加日志细节

将pac4j的日志级别调整为DEBUG,查看SAML请求生成、跳转的详细日志,确认是否生成AuthnRequest、是否发起HTTP重定向、是否有未捕获的异常。

内容的提问来源于stack exchange,提问作者user25326988

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 20:27:09