Spring Boot集成Okta SAML2.0登录AudienceRestriction验证失败排查
Spring Boot集成Okta SAML2.0登录受众验证失败问题排查请求
我基于Spring Boot开发了集成Okta IDP的SAML2.0登录应用,在Okta端完成登录后,页面跳转至应用时出现错误页面http://localhost:8080/login?error。后台日志提示断言中的AudienceRestriction验证失败,具体错误为:断言中的受众与有效受众列表不匹配。以下是相关配置、代码及日志信息,请求排查受众URI错误的原因:
错误信息
Invalid assertion [id19996480044761791773801931] for SAML response [id19996480042980701198640159]: Condition '{urn:oasis:names:tc:SAML:2.0:assertion}AudienceRestriction' of type 'null' in assertion 'id19996480044761791773801931' was not valid.: None of the audiences within Assertion 'id19996480044761791773801931' matched the list of valid audiances
application.yml配置
spring: security: saml2: relyingparty: registration: okta-saml: assertingparty: entity-id: http://www.okta.com/exkar5e4vbGQS6kYS697 verification.credentials: - certificate-location: "classpath:saml-certificate/okta.cert" singlesignon.url: https://trial-6443640.okta.com/app/trial-6443640_appsaml1_1/exkar5e4vbGQS6kYS697/sso/saml singlesignon.sign-request: false audience: http://localhost:8080/login/saml2/service-provider-metadata/okta-saml logging: file: logs/application-debug.log pattern: console: "%d %-5level %logger : %msg%n" file: "%d %-5level [%thread] %logger : %msg%n" level: org.springframework.web: DEBUG org.springframework.security: TRACE server: port : 8080
SecurityConfiguration类代码
@Configuration public class SecurityConfiguration extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity httpSecurity) throws Exception { // This class is deprecated, but you have to use it if you're using OpenSAML < 4.0 OpenSamlAuthenticationProvider authenticationProvider = new OpenSamlAuthenticationProvider(); authenticationProvider.setAssertionValidator(OpenSamlAuthenticationProvider.createDefaultAssertionValidator()); authenticationProvider.setResponseAuthenticationConverter(OpenSamlAuthenticationProvider.createDefaultResponseAuthenticationConverter()); /*httpSecurity.authorizeRequests(authz -> authz.antMatchers("/login/saml2/sso/*").permitAll() .antMatchers("/login/saml2/service-provider-metadata/*").permitAll() .anyRequest().authenticated())*/ httpSecurity.authorizeRequests(authz -> authz.anyRequest().authenticated()) .saml2Login(saml2 -> saml2.authenticationManager(new ProviderManager(authenticationProvider))); } private Converter<OpenSamlAuthenticationProvider.ResponseToken, Saml2Authentication> groupsConverter() { Converter<org.springframework.security.saml2.provider.service.authentication.OpenSamlAuthenticationProvider.ResponseToken, Saml2Authentication> delegate = OpenSamlAuthenticationProvider.createDefaultResponseAuthenticationConverter(); return (responseToken) -> { Saml2Authentication authentication = delegate.convert(responseToken); Saml2AuthenticatedPrincipal principal = (Saml2AuthenticatedPrincipal) authentication.getPrincipal(); List<String> groups = principal.getAttribute("groups"); Set<GrantedAuthority> authorities = new HashSet<>(); if (groups != null) { groups.stream().map(SimpleGrantedAuthority::new).forEach(authorities::add); } else { authorities.addAll(authentication.getAuthorities()); } return new Saml2Authentication(principal, authentication.getSaml2Response(), authorities); }; } }
控制器代码
@SpringBootApplication @Controller public class SpringSecuritySaml2Application { public static void main(String[] args) { SpringApplication.run(SpringSecuritySaml2Application.class, args); } @RequestMapping("/") public String index() { return "home"; } @RequestMapping("/secured/hello") public String hello(@AuthenticationPrincipal Saml2AuthenticatedPrincipal principal, Model model) { model.addAttribute("name", principal.getName()); return "hello"; } }
日志片段
2024-01-24 12:28:35,274 DEBUG org.springframework.security.saml2.provider.service.authentication.OpenSamlAuthenticationProvider : Found 1 validation errors in SAML response [id3210990765450188248512483]: [[invalid_assertion] Invalid assertion [id32109907656084221846235013] for SAML response [id3210990765450188248512483]: Condition '{urn:oasis:names:tc:SAML:2.0:assertion}AudienceRestriction' of type 'null' in assertion 'id32109907656084221846235013' was not valid.: None of the audiences within Assertion 'id32109907656084221846235013' matched the list of valid audiances] 2024-01-24 12:28:35,275 TRACE org.springframework.security.saml2.provider.service.servlet.filter.Saml2WebSsoAuthenticationFilter : Failed to process authentication request org.springframework.security.saml2.provider.service.authentication.Saml2AuthenticationException: Invalid assertion [id32109907656084221846235013] for SAML response [id3210990765450188248512483]: Condition '{urn:oasis:names:tc:SAML:2.0:assertion}AudienceRestriction' of type 'null' in assertion 'id32109907656084221846235013' was not valid.: None of the audiences within Assertion 'id32109907656084221846235013' matched the list of valid audiances at org.springframework.security.saml2.provider.service.authentication.OpenSamlAuthenticationProvider.createAuthenticationException(OpenSamlAuthenticationProvider.java:699) at org.springframework.security.saml2.provider.service.authentication.OpenSamlAuthenticationProvider.process(OpenSamlAuthenticationProvider.java:519) at org.springframework.security.saml2.provider.service.authentication.OpenSamlAuthenticationProvider.authenticate(OpenSamlAuthenticationProvider.java:447) at org.springframework.security.authentication.ProviderManager.authenticate(ProviderManager.java:182)
Okta配置截图

内容的提问来源于stack exchange,提问作者BK Elizabeth
相关产品推荐
相关产品推荐

