You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SamlResponse通过第三方签名验证,为何ITfoxtec.Identity.Saml2验证失败?

ITfoxtec.Identity.Saml2.MvcCore对接IBM IdP签名验证失败问题

问题背景

我使用ITfoxtec.Identity.Saml2.MvcCore实现SAML2单点登录(SSO),对接IBM商用IdP服务器产品。SamlResponse包含已签名的Assertion元素,无其他签名或加密操作。

跳过Saml2PostBinding.Unbind调用时,SSO认证可正常工作,但项目要求及企业政策规定必须验证签名。

调试发现的核心问题

调用Saml2PostBinding.Unbind时,调试最新版ITfoxtec源码(4.10.4)可见:签名检测、签名证书识别、签名算法(http://www.w3.org/2001/04/xmldsig-more#rsa-sha256)与规范化算法(http://www.w3.org/2001/10/xml-exc-c14n#)应用均正常,直到执行以下代码时验证失败返回false:

return CheckSignature(Saml2Signer.Certificate.GetRSAPublicKey());

开启符号服务器调试.NET源码后发现,失败发生在System.Security.Cryptography.Xml.SignedXml.CheckDigestedReferences()的如下代码段:

try
{
    calculatedHash = digestedReference.CalculateHashValue(_containingDocument, m_signature.ReferencedItems);
}
catch (CryptoSignedXmlRecursionException)
{
    SignedXmlDebugLog.LogSignedXmlRecursionLimit(this, digestedReference);
    return false;
}
SignedXmlDebugLog.LogVerifyReferenceHash(this, digestedReference, calculatedHash, digestedReference.DigestValue);
if (!CryptographicEquals(calculatedHash, digestedReference.DigestValue))
{
    return false;
}

具体原因是calculatedHash与digestedReference.DigestValue不相等。

环境与额外验证情况

  • 签名证书、中间证书及根证书均有效,已显式导入并信任于测试机器的证书存储(Windows 10 Business 21H2,版本19044.3086,Windows Feature Experience Pack 1000.19041.1000.0)
  • 验证失败的SamlResponse可通过第三方SAML响应验证工具通过,修改Assertion内任一字符会导致该工具验证失败,说明IBM IdP的签名本身无问题

已尝试操作

  • 调试ITfoxTec与.NET源码,定位到哈希值不匹配的问题点
  • 使用外部工具验证签名,确认签名本身有效

结果对比

  • 预期结果:签名在ITfoxTec与外部工具中均验证通过
  • 实际结果:仅外部工具验证通过,ITfoxTec验证失败

内容的提问来源于stack exchange,提问作者user22958864

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 17:07:44