All pastes #3730035 Raw Edit

Shib2 ECP Response

public unlisted xml v1 · immutable
#3730035 ·published 2016-10-18 02:14 UTC
rendered paste body
<?xml version="1.0" encoding="UTF-8"?><soap11:Envelope xmlns:soap11="http://schemas.xmlsoap.org/soap/envelope/">  <soap11:Header>    <ecp:Response xmlns:ecp="urn:oasis:names:tc:SAML:2.0:profiles:SSO:ecp" AssertionConsumerServiceURL="https://login.microsoftonline.com/login.srf" soap11:actor="http://schemas.xmlsoap.org/soap/actor/next" soap11:mustUnderstand="1"/>  </soap11:Header>  <soap11:Body>    <saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="https://login.microsoftonline.com/login.srf" ID="_5029d668b5f2d761264647934d1a75a9" InResponseTo="6778b9fd271570870a78e7bea2a4ea0aa5662373" IssueInstant="2016-10-17T18:14:19.159Z" Version="2.0">      <saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">http://myidp.mydomain.ca</saml2:Issuer>      <saml2p:Status>        <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>      </saml2p:Status>      <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:xs="http://www.w3.org/2001/XMLSchema" ID="_29566785ba64fd6a91af01a9a7a8a999" IssueInstant="2016-10-17T18:14:19.159Z" Version="2.0">        <saml2:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">http://myidp.mydomain.ca</saml2:Issuer>        <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">          <ds:SignedInfo>            <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>            <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>            <ds:Reference URI="#_29566785ba64fd6a91af01a9a7a8a999">              <ds:Transforms>                <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>                <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#">                  <ec:InclusiveNamespaces xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="xs"/>                </ds:Transform>              </ds:Transforms>              <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>              <ds:DigestValue>sPHDLA7/A1hLiTaUqCNRP1zeSwQ=</ds:DigestValue>            </ds:Reference>          </ds:SignedInfo>          <ds:SignatureValue>g9fm5qW18LiBkS0cP5cAuygRQVwXUWYZ+qtMPsc/PoZdqu2NHtnLdpwgwIS5AJ6W4Bn7gQLWRr0maYQLmhiIeQ5gCbo9PdQueE+i/ayZ0TcXjIFXXNL8ByXnU4RAaKTKJ21XwxdpbGzipaNXawbDn1C40wkEAxFV45kA2LqPLylnGWiVkcX1AS7s9pNr8RIUBud93p6foP8be6rgkm3P8GLrNZsgEjGa7Wj2TRVHdo739iIJTk0I3HhleCK25ftL9UFtKqy0xwmht1ABeJ7Y0K3NeYglfmfIME0vL5XWkO8XYpWM+kxkEi89tZWs6Xe979on3mj0OjFJiZoYEx1oaw==</ds:SignatureValue>          <ds:KeyInfo>            <ds:X509Data>              <ds:X509Certificate>[mycert]</ds:X509Certificate>            </ds:X509Data>          </ds:KeyInfo>        </ds:Signature>        <saml2:Subject>          <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" NameQualifier="http://myidp.mydomain.ca" SPNameQualifier="urn:federation:MicrosoftOnline">nAxfpNobRk2vQZWtP4ug0Q==</saml2:NameID>          <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">            <saml2:SubjectConfirmationData Address="10.0.0.5" InResponseTo="6778b9fd271570870a78e7bea2a4ea0aa5662373" NotOnOrAfter="2016-10-17T18:19:19.159Z" Recipient="https://login.microsoftonline.com/login.srf"/>          </saml2:SubjectConfirmation>        </saml2:Subject>        <saml2:Conditions NotBefore="2016-10-17T18:14:19.159Z" NotOnOrAfter="2016-10-17T18:19:19.159Z">          <saml2:AudienceRestriction>            <saml2:Audience>urn:federation:MicrosoftOnline</saml2:Audience>          </saml2:AudienceRestriction>        </saml2:Conditions>        <saml2:AuthnStatement AuthnInstant="2016-10-17T18:14:19.159Z">          <saml2:SubjectLocality Address="10.0.0.5"/>          <saml2:AuthnContext>            <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef>          </saml2:AuthnContext>        </saml2:AuthnStatement>        <saml2:AttributeStatement>          <saml2:Attribute FriendlyName="checkGUIDTEST" Name="checkGUIDTEST" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">            <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">nAxfpNobRk2vQZWtP4ug0Q==</saml2:AttributeValue>          </saml2:Attribute>          <saml2:Attribute FriendlyName="UserId" Name="IDPEmail" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">            <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">myuser@mydomain.ca</saml2:AttributeValue>          </saml2:Attribute>        </saml2:AttributeStatement>      </saml2:Assertion>    </saml2p:Response>  </soap11:Body></soap11:Envelope>