pac4j SAML SP连接Hana IDP无请求送达问题排查求助
问题描述
我们已成功使用pac4j创建SP元数据,下一步尝试从应用连接Hana IDP。参考文档和论坛示例编写代码后,Hana IDP未收到任何请求,请求排查代码中遗漏的关键配置。
代码片段
SAML2Configuration cfg = new SAML2Configuration("sampletestKeystore.jks", "Password@123", "Password@1231", "idp_metadata.xml"); //Hana IDP Metadata cfg.setMaximumAuthenticationLifetime(6000); cfg.setServiceProviderEntityId("BOE_SP_ID"); cfg.setServiceProviderMetadataPath("sp-meta-downloaded_Rajib.xml"); cfg.setPostLogoutURL(http://xx.xxx.xxx.xxx:8080/SampleWeb/logout.html); cfg.setSpLogoutRequestBindingType(http://xx.xxx.xxx.xxx:8080/SampleWeb/logoutbinding.html); SAML2Client saml2Client = new SAML2Client(cfg); saml2Client.setName("BOE Client"); saml2Client.setCallbackUrl(http:// xx.xxx.xxx.xxx:8080/SampleWeb/BOE.html); final Clients clients = new Clients(); clients.setClients(saml2Client);
Pac4j运行日志
2024-07-17 05:58:34 INFO org.pac4j.saml.util.Configuration - Bootstrapping OpenSAML configuration via Pac4j... 2024-07-17 05:58:34 WARN o.p.core.adapter.FrameworkAdapter - No framework adapter found. Using DefaultFrameworkAdapter... 2024-07-17 05:58:34 INFO o.o.c.config.InitializationService - Initializing OpenSAML using the Java Services API 2024-07-17 05:58:35 INFO o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2001/04/xmlenc#ripemd160 2024-07-17 05:58:35 INFO o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2001/04/xmldsig-more#hmac-ripemd160 2024-07-17 05:58:35 INFO o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2001/04/xmldsig-more#rsa-ripemd160 2024-07-17 05:58:35 INFO o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2007/05/xmldsig-more#sha1-rsa-MGF1 2024-07-17 05:58:35 INFO o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2007/05/xmldsig-more#sha224-rsa-MGF1 2024-07-17 05:58:35 INFO o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2007/05/xmldsig-more#sha256-rsa-MGF1 2024-07-17 05:58:35 INFO o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2007/05/xmldsig-more#sha384-rsa-MGF1 2024-07-17 05:58:35 INFO o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2007/05/xmldsig-more#sha3-224-rsa-MGF1 2024-07-17 05:58:35 INFO o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2007/05/xmldsig-more#sha3-256-rsa-MGF1 2024-07-17 05:58:35 INFO o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2007/05/xmldsig-more#sha3-384-rsa-MGF1 2024-07-17 05:58:35 INFO o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2007/05/xmldsig-more#sha3-512-rsa-MGF1 2024-07-17 05:58:35 INFO o.o.x.algorithm.AlgorithmRegistry - Algorithm failed runtime support check, will not be usable: http://www.w3.org/2007/05/xmldsig-more#sha512-rsa-MGF1
已在pac4j用户组、官方demo及文档中调研过,仍未解决,求技术建议。
排查建议
1. 修正配置参数的类型与取值错误
代码中setPostLogoutURL、setSpLogoutRequestBindingType、setCallbackUrl的URL参数未加引号,会直接导致编译失败;且setSpLogoutRequestBindingType的取值错误,它需要传入SAML标准绑定类型的URI,而非应用URL。修正后代码示例:
cfg.setPostLogoutURL("http://xx.xxx.xxx.xxx:8080/SampleWeb/logout.html"); // 使用SAML标准绑定类型,比如HTTP-Redirect或HTTP-POST cfg.setSpLogoutRequestBindingType("urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"); saml2Client.setCallbackUrl("http://xx.xxx.xxx.xxx:8080/SampleWeb/BOE.html");
2. 补全框架适配器配置
日志提示No framework adapter found. Using DefaultFrameworkAdapter,默认适配器无法适配具体Web框架(如Spring MVC、Jakarta EE)的请求流转逻辑,会导致无法触发跳转至IDP的动作。需要:
- 引入对应框架的pac4j依赖(如Spring MVC用
pac4j-springmvc,Jakarta EE用pac4j-jakartaee) - 确保依赖自动加载了对应框架的适配器实现,或手动指定适配器
3. 验证SP与IDP配置同步
- 确认
sp-meta-downloaded_Rajib.xml中的实体ID与代码中BOE_SP_ID完全一致 - 已将该SP元数据上传至Hana IDP,且IDP中配置的ACS URL与代码里的
callbackUrl完全匹配(包括HTTP/HTTPS、端口、路径) - 检查Hana IDP要求的签名/加密算法,若日志中不可用的算法包含IDP要求的类型,需更换支持对应算法的密钥库
4. 触发认证流程
仅配置Clients对象不足以发起认证,需要在Web应用中添加pac4j的过滤器/拦截器:
- 添加
CallbackFilter处理SAML回调请求 - 添加
SecurityFilter保护需要认证的资源,或手动调用SAML2Client的redirect方法触发跳转至IDP的逻辑
5. 增加日志细节
将pac4j的日志级别调整为DEBUG,查看SAML请求生成、跳转的详细日志,确认是否生成AuthnRequest、是否发起HTTP重定向、是否有未捕获的异常。
内容的提问来源于stack exchange,提问作者user25326988
相关产品推荐
相关产品推荐

