使用samlify对接Okta时遇ERR_EXCEPTION_OF_ASSERTION_DECRYPTION错误
问题:使用samlify对接Okta SAML验证时出现断言解密异常
代码片段
import * as samlify from 'samlify'; import * as fs from 'fs'; import * as validator from '@authenio/samlify-node-xmllint'; const binding = samlify.Constants.namespace.binding; samlify.setSchemaValidator(validator); const filePathIdpMeta = __dirname + '/../' + 'meta1123/meta/Testv2-xml-idp.xml'; const filePathSPMeta = __dirname + '/../' + 'meta1123/meta/Testv2-xml-sp.xml'; const filePathSpKey = __dirname + '/../' + 'meta1123/key/encryptKey.pem'; console.info("----PATHS----") console.info(filePathIdpMeta); console.info(filePathSPMeta); console.info(filePathSpKey); const idp = samlify.IdentityProvider({ metadata: fs.readFileSync(filePathIdpMeta), messageSigningOrder: 'sign-then-encrypt', isAssertionEncrypted: true, wantAuthnRequestsSigned: false })
错误信息
http://www.w3.org/2001/04/xmlenc#rsa-1_5 is no longer recommended due to security reasons. Please deprecate its use as soon as possible. Error: Not found: child not in parent at assertPreInsertionValidity1to5 (/home/my_local_path/Service_Providers/sp-oauth0/node_modules/samlify/node_modules/@xmldom/xmldom/lib/dom.js:798:9) at _insertBefore (/home/my_local_path/Service_Providers/sp-oauth0/node_modules/samlify/node_modules/@xmldom/xmldom/lib/dom.js:938:2) at Document.replaceChild (/home/my_local_path/Service_Providers/sp-oauth0/node_modules/samlify/node_modules/@xmldom/xmldom/lib/dom.js:1054:3) at /home/my_local_path/Service_Providers/sp-oauth0/node_modules/samlify/src/libsaml.ts:681:15 at Object.decrypt (/home/my_local_path/Service_Providers/sp-oauth0/node_modules/@authenio/xml-encryption/lib/xmlenc.js:202:16) at /home/my_local_path/Service_Providers/sp-oauth0/node_modules/samlify/src/libsaml.ts:670:23 at new Promise (<anonymous>) at Object.decryptAssertion (/home/my_local_path/Service_Providers/sp-oauth0/node_modules/samlify/src/libsaml.ts:655:14) at /home/my_local_path/Service_Providers/sp-oauth0/node_modules/samlify/src/flow.ts:225:34 at step (/home/my_local_path/Service_Providers/sp-oauth0/node_modules/samlify/build/src/flow.js:33:23) { code: 8 } [FATAL] when parsing login response sent from okta Error: ERR_EXCEPTION_OF_ASSERTION_DECRYPTION at /home/my_local_path/Service_Providers/sp-oauth0/node_modules/samlify/src/libsaml.ts:675:27 at Object.decrypt (/home/my_local_path/Service_Providers/sp-oauth0/node_modules/@authenio/xml-encryption/lib/xmlenc.js:214:12) at /home/my_local_path/Service_Providers/sp-oauth0/node_modules/samlify/src/libsaml.ts:670:23 at new Promise (<anonymous>) at Object.decryptAssertion (/home/my_local_path/Service_Providers/sp-oauth0/node_modules/samlify/src/libsaml.ts:655:14) at /home/my_local_path/Service_Providers/sp-oauth0/node_modules/samlify/src/flow.ts:225:34 at step (/home/my_local_path/Service_Providers/sp-oauth0/node_modules/samlify/build/src/flow.js:33:23) at Object.next (/home/my_local_path/Service_Providers/sp-oauth0/node_modules/samlify/build/src/flow.js:14:53) at fulfilled (/home/my_local_path/Service_Providers/sp-oauth0/node_modules/samlify/build/src/flow.js:5:58) at processTicksAndRejections (internal/process/task_queues.js:93:5)
解决步骤
- 替换不安全的加密算法:在Okta的SAML应用配置中,将断言加密算法从
http://www.w3.org/2001/04/xmlenc#rsa-1_5改为http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p,rsa-1_5存在安全漏洞,这也是警告的原因,同时可能引发解密兼容性问题。 - 完善SP配置:确保ServiceProvider实例正确加载私钥,解密需要SP的私钥来处理Okta加密的断言,补充SP配置代码:
const sp = samlify.ServiceProvider({ metadata: fs.readFileSync(filePathSPMeta), privateKey: fs.readFileSync(filePathSpKey), isAssertionEncrypted: true }); - 检查密钥与证书匹配性:确认
encryptKey.pem是SP的私钥,格式为标准PEM(无多余字符、换行正确),且Okta配置中使用的SP公钥与该私钥配对。 - 升级依赖版本:旧版本samlify与xmldom可能存在DOM操作兼容性问题,升级samlify到最新稳定版,同步更新
@authenio/xml-encryption和xmldom依赖。 - 排查加密配置一致性:确保Okta和samlify两端的加密配置完全匹配,包括断言加密开关、算法、证书等;可先临时关闭断言加密(两端都设置
isAssertionEncrypted: false),验证基础SAML流程是否正常,再逐步恢复加密配置排查问题。
内容的提问来源于stack exchange,提问作者ambigus9
相关产品推荐
相关产品推荐

