Skip to content

Instantly share code, notes, and snippets.

@pkarneliuk
Created June 5, 2017 07:25
Show Gist options
  • Save pkarneliuk/17d026a910c093cae83a3c290ce05ec2 to your computer and use it in GitHub Desktop.
Save pkarneliuk/17d026a910c093cae83a3c290ce05ec2 to your computer and use it in GitHub Desktop.
Это образец запроса к PingFederate от WIF, котрый был отклонён с сообщением "Unexpected problem evaluating Token"
2017-05-11 12:33:51,133|STS| | 10.6.84.29 | | wst| WSTrust| EPBYMINW1763T56.cluster.dom| IdP| failure| | Unexpected problem evaluating Token| 16 |<s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:a="http://www.w3.org/2005/08/addressing" xmlns:u="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">
<s:Header>
<a:Action s:mustUnderstand="1">http://docs.oasis-open.org/ws-sx/ws-trust/200512/RST/Issue</a:Action>
<a:MessageID>urn:uuid:d70d3f7f-d6f5-46bc-99ec-35ac135ef25e</a:MessageID>
<a:ReplyTo>
<a:Address>http://www.w3.org/2005/08/addressing/anonymous</a:Address>
</a:ReplyTo>
<a:To s:mustUnderstand="1">https://epbyminw1763t56.cluster.dom:9031/idp/sts.wst?TokenProcessorId=Kerberos</a:To>
<o:Security s:mustUnderstand="1" xmlns:o="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd">
<u:Timestamp u:Id="_0">
<u:Created>2017-05-11T09:32:38.396Z</u:Created>
<u:Expires>2017-05-11T09:37:38.396Z</u:Expires>
</u:Timestamp>
<o:BinarySecurityToken u:Id="uuid-825377e4-4b4e-4771-a9f4-7655090c28ea-16" ValueType="http://docs.oasis-open.org/wss/oasis-wss-kerberos-token-profile-1.1#GSS_Kerberosv5_AP_REQ" EncodingType="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Base64Binary">YIIGXwYJKoZIhvcSAQICAQBuggZOMIIGSqADAgEFoQMCAQ6iBwMFAAAAAACjggTeYYIE2jCCBNagAwIBBaENGwtDTFVTVEVSLkRPTaIuMCygAwIBAqElMCMbBGhvc3QbG2VwYnltaW53MTc2M3Q1Ni5jbHVzdGVyLmRvbaOCBI4wggSKoAMCARKhAwIBBaKCBHwEggR4O3Nm+YEf8STsbvHARfVWl0nropPi1+8Vt/XVo5fdbXRTSYYPTb5XJ+CWzC0ocy7SIj1uKwqCiC41lSmPsEEQTTGMuPc5wgc+8KT0xUy4R0jvPF1iP0nSXh9jNVGX8JNtZ3o8DN91ds69j5rfKVrU0ldqBY8gtBjCJXdHmMb5U5QdU4pGjYI33zayxSG/xbSqADul/a3TO39Xl0nVFzCW8X3UAmVkSMVZMsY/Paxa6XtjNSEz2/YuAhIHgrFHRl/LIAx+rgfEr40zG+L1s6mEykthPqc+RhULDBegOhmkTBAi5CAJaWpOmnMfTffpMv7aB9JaJ876MrVJ8Wo41bwwGiTsll/8tX3/wDP1sIeOn0KdnMeIftL8HQb5WqjhPBBkxTFtP5LVotz0dU39H8xn8BVBNIAXqj7WH9Ctl1dx2exYgMWsbXeqPV4SmQ08XohKJ5xwFykDvjkp2Xd62oxn41RuStXPLvJs1FtR6J0QPrYH8ay+vHyMO9gZkuoX5VYQbnevNJkXbp+RTmhh/WWCNaVZjBxlhnAdFN8FHzP5gs6vfBvsU8xE/OtufVJ0iDgWjVvB36pde+IpebCXaALAJX9wgLIq+hoW4OUyf1WEKIEszK05DeJrs3wl8fX9svatUyH6ipi/JkUPXMPYtGo0QWXiqrs8z3yVgAafBqCgNFrjgb1aPpdHeGzdfSgNto6LTseNpMUCW0I7c0CvkUE3vaTZxufmO+YW73E/nnI8CDpad+qXnErAsRwatbr5lJb+BC9I/9Zf/Dtdke804R5oxVsPgpD5wbyAqHn8pzs9n9vua6WqgM48VQMM7iaozPC9DyB45yZUiO4tGYZ4KAIoSvYEjzc7jN+cElDxnmgG1hMpV8kTJsBCUGArayFURP4skfiM6cb8TxSNPaM9jzY2QjQODL7lcoJYTYePbGRsWhEdrHsMG0AdJuG/BfbT+Ohd3x3rKzTlEr6FH/7wLiyGcX2jme/YyJxIC3SraKNRdEMtjm/HUqqAoHo11337GHB8RfsXTojTHMvb11B0JvIL0+rghHv5VsKohmAR+0nAl9qDzZfLhqT6WaM+rfRnQeHIR9wdQFTNnWaeYi4KlURdgs95bsHuVsavADzN8jtnFmCEVGNK3RbTr8Dnnkk+cHfBHkgY4CXtfxn7Cw6sC2kn+U58Rj4oXVRAW+Y8NslFhkH345fxG3ruhL5SdqnGa3ekYWzpb+re6oDne2QAqgEweB+aHUbc6vWYEsku80Uegh0mbxQYHTwpBC+kONr1nUqnjVIZFJIIRJ6UKdT3WmEAZY2J0ioO3iOciWpiyuA0hdy5hcZnMmX3FOQwzYPKSM5PXKYv3pZg6pZ2vqBA8mIpX/vEI+Zt6vUSjCmTt17PaG/fi1G/LTFKyQnmwaS+H2qd5MSxuDibDIJsZNCpM048sRGJkKn/N78EakvWCHzoNjHYYTbOHQL3E+WI1NlbpRIR7hvxND/rUi8uAfkzQO6arXpXQu0hqagEy9lvlvsD5Ix4IxqBuM2poqSCAVEwggFNoAMCARKiggFEBIIBQLSw6vI2swVqrzhtKO6HOokfRU16iQfRoRzpIe9/P7QjENkdHGb3foFMoAui9XjW+DRIp5w5HznurNLzUYKbQapKk7QXQClonPwMddRsw0zYUvOGqTkWNxNFqtE1jIeke+/beHOgtqqmpdfym9oywCCd+q+3++iMvc7lY6ggWRRNTXugc8XGdHbeljXPpzy1XgOkxeF84wqLEghEjp8vL3CkDW7zaUpNIrEbYQ3Kd+N0jeWdzypnzyZT/p3WFgl84z9lcXVGvIpI1raTgXd+It9vROWVgyT1yc5VamjXF4/d6R9BKnoKNFYa8fupFUJ8txoTKfK27t8G0mebfLi67PIVoLNkCehcLh1eV72vf1M098sfu3UtaIMsz3oRvx6lBe+d0IMQb8SRtY19Wnod/P+MJFKSs2LrwAC/lQdiabR3</o:BinarySecurityToken>
<Signature xmlns="http://www.w3.org/2000/09/xmldsig#">
<SignedInfo>
<CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
<SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#hmac-sha1"/>
<Reference URI="#_0">
<Transforms>
<Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
</Transforms>
<DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
<DigestValue>fT6uHDi5qo/RzCJ62irUxZE7T9s=</DigestValue>
</Reference>
</SignedInfo>
<SignatureValue>66bMB0wgnm760UEMlS5RHMy8UrM=</SignatureValue>
<KeyInfo>
<o:SecurityTokenReference>
<o:Reference URI="#uuid-825377e4-4b4e-4771-a9f4-7655090c28ea-16"/>
</o:SecurityTokenReference>
</KeyInfo>
</Signature>
</o:Security>
</s:Header>
<s:Body>
<trust:RequestSecurityToken xmlns:trust="http://docs.oasis-open.org/ws-sx/ws-trust/200512">
<wsp:AppliesTo xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy">
<wsa:EndpointReference xmlns:wsa="http://www.w3.org/2005/08/addressing">
<wsa:Address>https://epbyminw1035t1/</wsa:Address>
</wsa:EndpointReference>
</wsp:AppliesTo>
<trust:KeyType>http://docs.oasis-open.org/ws-sx/ws-trust/200512/Bearer</trust:KeyType>
<trust:RequestType>http://docs.oasis-open.org/ws-sx/ws-trust/200512/Issue</trust:RequestType>
<trust:TokenType>urn:oasis:names:tc:SAML:2.0:assertion</trust:TokenType>
</trust:RequestSecurityToken>
</s:Body>
</s:Envelope> | |
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment