Skip to content

Does mellon protect multiple URL with single metadata file of IdP #49

Description

@kuwars98

Hello,

I have hosted multiple URLs on apache server and help of mellon protect all URLs but earlier I have tested with single URL and working fine.
But 2nd scenarios is that I need to protect all URLs with single metadata file of IdP and getting error such as "Bad Request" for new add URL.
Does mellon module support for multiple URL to protect with single metadata file of IdP ?

Activity

  1. changed the title [-]Does mellon protect multiple URL with single metadata file of IDP[/-] [+]Does mellon protect multiple URL with single metadata file of IdP[/+] on Feb 17, 2021
  2. thijskh commented on Feb 17, 2021

    @thijskh

    Maybe you can describe what exact config you tried and what is logged when you get the Bad Request response.

  3. kuwars98 commented on Feb 17, 2021

    @kuwars98
    Author

    I'm using Apache with Mellon module as a reverse proxy (SP) in front of a web app. Actually we are planning to protect 100+ URLs.
    For test cases:-

    1. We created metadata file and certificate for https://app1-pp.mydomain.com from SP and shared it with IdP(ForgeRock).
      IdP created and configured metadata file and shared it with me. Then, I did configuration at apache level and app1 URL is working fine.

    2. So we had plan to add app2 URL in SAML SSO authentication using previous same entityID and same IdP metadata. I had asked to IdP to add 2nd URL in same previous configuration. Then, I did configuration at apache level. After this is done we're getting "Bad Request" Error..
      While "Bad Request" error did not get any logs at apache.

    Question:- Can we configure and protect multiple URLs with single entityID and IdP metadata ?

    URLs:-
    https://app1-pp.mydomain.com
    https://app2.pp.s3-in.mydomain.com

    Apache Veriosn:- Apache 2.4
    Idp:- ForgeRock

    Mellon Configuration

    <location />
    MellonSPPrivateKeyFile /etc/httpd/mellon/app1.key
    MellonSPCertFile /etc/httpd/mellon/app1.cert
    MellonSPMetadataFile /etc/httpd/mellon/app1.xml
    MellonIdPMetadataFile /etc/httpd/mellon/CGDevsamltestpp1vstd.xml
    MellonEndpointPath /mellon
    MellonEnable "info"
        MellonVariable "cookie"
        #MellonSecureCookie On
        MellonCookiePath /
        MellonUser "NAME_ID"
        MellonSessionDump Off
        MellonSamlResponseDump Off
        MellonEndpointPath "/mellon"
        MellonDefaultLoginPath "/"
        MellonSessionLength 43200
    </Location>
    

    Get Request XML

    <samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
                        xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
                        ID="_72551C09B0AFEA1378FFC214694D2A0F"
                        Version="2.0"
                        IssueInstant="2021-02-17T11:28:10Z"
                        Destination="https://sso.Mydomain.com:443/opensso/SSORedirect/metaAlias/Mydomain/IDPsamltestpp"
                        Consent="urn:oasis:names:tc:SAML:2.0:consent:current-implicit"
                        ForceAuthn="false"
                        IsPassive="false"
                        AssertionConsumerServiceURL="https://app1-pp.mydomain.com/mellon/postResponse"
                        >
        <saml:Issuer>https://app1-pp.mydomain.com/</saml:Issuer>
        <samlp:NameIDPolicy Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"
                            AllowCreate="true"
                            />
    </samlp:AuthnRequest>
    
    

    Response Request XML

    <samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
                    Destination="https://app1-pp.mydomain.com/mellon/postResponse"
                    ID="s2c242212e02cf6423ca6ee4edcb0d2db460347926"
                    InResponseTo="_72551C09B0AFEA1378FFC214694D2A0F"
                    IssueInstant="2021-02-17T11:28:17Z"
                    Version="2.0"
                    >
        <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">CGDevsamltestpp</saml:Issuer>
        <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
            <ds:SignedInfo>
                <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
                <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" />
                <ds:Reference URI="#s2c242212e02cf6423ca6ee4edcb0d2db460347926">
                    <ds:Transforms>
                        <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" />
                        <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
                    </ds:Transforms>
                    <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" />
                    <ds:DigestValue>9QCFx9F0W5XOYj1tMpR4lMljYK6dwjFjsA7Kmzsnik4=</ds:DigestValue>
                </ds:Reference>
    
    
  4. kuwars98 commented on Feb 19, 2021

    @kuwars98
    Author

    Hello Kinkhorst,

    Can you help me if you have any idea about my requirement ?

  5. locked and limited conversation to collaborators on Feb 19, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions