You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用ITfoxtec SAML配置SP元数据时遇“Signature is invalid”错误

排查SAML单点登录中“Signature is invalid”错误原因

问题背景

我在.NET Core Web应用中使用ITfoxtec SAML库搭建服务提供商(SP),对接SAML身份提供商(IdP)实现单点登录。配置IdP所需的SP元数据后,测试单点登录时应用启动正常,但出现**“Signature is invalid”**错误。

我的appsettings.json配置

"Saml2": {
    "IdPMetadata": "https://zion.xyz.edu/idp ",
    "Issuer": "Arizona State",
    "SignatureAlgorithm": "http://www.w3.org/2001/04/xmldsig-more#rsa-sha256",
    "SigningCertificateFile": "itfoxtec.identity.saml2.testwebappcore_Certificate.pfx",
    "SigningCertificatePassword": "!QAZ2wsx",
    "CertificateValidationMode": "None",
    "RevocationMode": "NoCheck",
    "samlMetadataUrl": "~/SP_webapp/Metadata"
}

MetadataController.cs代码

public class MetadataController : Controller
{
    private readonly Saml2Configuration config;

    public MetadataController(IOptions<Saml2Configuration> configAccessor)
    {
        config = configAccessor.Value;
    }

    public IActionResult Index()
    {
        var defaultSite = new Uri($"{Request.Scheme}://{Request.Host.ToUriComponent()}/");

        var entityDescriptor = new EntityDescriptor(config);
        entityDescriptor.ValidUntil = 365;
        entityDescriptor.SPSsoDescriptor = new SPSsoDescriptor
        {
            WantAssertionsSigned = true,
            SigningCertificates = new X509Certificate2[]
            {
                config.SigningCertificate
            },
            //EncryptionCertificates = new X509Certificate2[]
            //{
            //    config.DecryptionCertificate
            //},
            SingleLogoutServices = new SingleLogoutService[]
            {
                new SingleLogoutService { Binding = ProtocolBindings.HttpPost, Location = new Uri(defaultSite, "Auth/SingleLogout"), ResponseLocation = new Uri(defaultSite, "Auth/LoggedOut") }
            },
            NameIDFormats = new Uri[] { NameIdentifierFormats.X509SubjectName },
            AssertionConsumerServices = new AssertionConsumerService[]
            {
                new AssertionConsumerService { Binding = ProtocolBindings.HttpPost, Location = new Uri(defaultSite, "Auth/AssertionConsumerService") },
            },
            AttributeConsumingServices = new AttributeConsumingService[]
            {
                new AttributeConsumingService { ServiceName = new ServiceName("Some SP", "en"), RequestedAttributes = CreateRequestedAttributes() }
            },
        };
        entityDescriptor.ContactPersons = new[] {
            new ContactPerson(ContactTypes.Administrative)
            {
                Company = "Arizona State",
                GivenName = "Redding",
                SurName = "Smith",
                EmailAddress = "rs23@123.edu",
                TelephoneNumber = "xxx-214-3932",
            }
            //}
        };
        return new Saml2Metadata(entityDescriptor).CreateMetadata().ToActionResult();
    }

    private IEnumerable<RequestedAttribute> CreateRequestedAttributes()
    {
        yield return new RequestedAttribute("urn:oid:2.5.4.4");
        yield return new RequestedAttribute("urn:oid:2.5.4.3", false);
        yield return new RequestedAttribute("urn:xxx", true, "test-value");
    }
}

可能的错误原因及排查方向

  • IdP元数据URL格式错误:IdPMetadata配置的URL末尾存在空格(https://zion.xyz.edu/idp ),会导致SP无法正确加载IdP的元数据,进而无法获取IdP的签名证书用于验证断言签名。需去掉URL末尾的空格。

  • SP签名证书加载异常:

    • 确认SigningCertificateFile指定的PFX文件路径是否正确,确保文件存在于项目可访问的目录(如根目录或wwwroot),必要时使用绝对路径。
    • 检查PFX证书是否包含私钥,ITfoxtec库需要私钥生成签名,同时公钥要在SP元数据中提供给IdP;如果证书无对应私钥,会导致签名生成或验证失败。
    • 验证SigningCertificatePassword是否正确,密码错误会导致证书无法正常加载。
  • 签名算法不匹配:

    • 确认SP配置的SignatureAlgorithm与IdP端使用的签名算法一致。如果IdP使用的是SHA1等其他算法,会导致SP验证签名时不通过。
    • 检查SP元数据中是否正确声明了该签名算法,确保IdP使用SP指定的算法来签名断言。
  • SP元数据与IdP配置不一致:

    • 检查MetadataController中SPSsoDescriptor.SigningCertificates是否正确加载了config.SigningCertificate,确保元数据中暴露的公钥与SP实际使用的签名证书公钥一致;若IdP缓存了旧的SP证书,会导致签名验证失败。
    • 确认IdP端已正确导入最新的SP元数据,清除IdP侧可能存在的旧元数据缓存。
  • 签名验证日志缺失:

    • 启用ITfoxtec SAML库的日志功能,查看详细的签名验证错误细节,比如是证书不匹配、算法不兼容还是断言数据被篡改,这能精准定位问题根源。

内容的提问来源于stack exchange,提问作者SkyeBoniwell

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 15:12:49