【问题标题】:Spring SAML configuration is breaking other http connectionsSpring SAML 配置正在破坏其他 http 连接
【发布时间】:2016-12-02 11:02:26
【问题描述】:

我正在使用 Spring SAML 在我的应用程序中实现单点登录。从 SSO 的角度来看,Evreything 已集成并正常工作。 我的应用程序的另一个服务也通过 Axis 使用 HTTP 客户端发布开始失败并出现以下错误

{http://xml.apache.org/axis/}stackTrace:javax.net.ssl.SSLPeerUnverifiedException:SSL 对等体的主机名验证失败:null

我已经查看了提供链接的答案 Spring Security SAML + HTTPS to another page 并遵循相同但无济于事。

下面是TLSProtocolSocketFactory的配置

    <bean class="org.springframework.beans.factory.config.MethodInvokingFactoryBean">
    <property name="targetClass" value="org.apache.commons.httpclient.protocol.Protocol"/>
    <property name="targetMethod" value="registerProtocol"/>
    <property name="arguments">
        <list>
            <value>https</value>
            <bean class="org.apache.commons.httpclient.protocol.Protocol">
                <constructor-arg value="https"/>
                <constructor-arg>
                    <bean class="org.springframework.security.saml.trust.httpclient.TLSProtocolSocketFactory">
                        <constructor-arg ref="keyManager"/>
                        <constructor-arg><null/></constructor-arg>
                        <constructor-arg value="allowAll"/>
                    </bean>
                </constructor-arg>
                <constructor-arg value="443"/>
            </bean>
        </list>
    </property>
</bean>

我也在 samlKeystore.jks 中导入了其他服务的证书。

感谢您对问题的任何帮助

【问题讨论】:

    标签: spring-security saml-2.0 spring-saml


    【解决方案1】:

    我想这可能是你要找的东西:Source

    您正在使用 bean TLSProtocolConfigurer 更改 HTTP 客户端中 HTTPS 协议的可信证书和主机名验证。您可以通过删除此 bean 将 HTTP 客户端的行为恢复为默认值。然后,您需要确保您从中加载元数据 (https://idp.ssocircle.com/idp-meta.xml) 的实体使用的证书在您的 cacerts 中受信任,或者使用没有 https (http://idp.ssocircle.com/idp-meta.xml) 的端点。

    或者,您可以通过在 bean TLSProtocolConfigurer 上将属性 sslHostnameVerification 设置为 allowAll 来禁用主机名验证。您还需要确保 https://www.somepage.com(或其 CA)的 HTTPS 证书包含在 samlKeystore.jks 中(请参阅 Spring SAML manual)。

    您可以在Spring SAML manual, chapter HTTP-based metadata provider with SSL 中找到有关TLSProtocolConfigurer bean 的更多详细信息。

    【讨论】:

    • 谢谢@blur0224。我在上面的问题中发布了相同的链接并按照说明进行操作。即使在删除上述 bean 之后,我也收到异常 code faultDetail: {xml.apache.org/axis}stackTrace:javax.net.ssl.SSLException: Error in hostname verification at org.opensaml.ws.soap.client.http.TLSProtocolSocketFactory .verifyHostname(TLSProtocolSocketFactory.java:153) at org.opensaml.ws.soap.client.http.TLSProtocolSocketFactory.createSocket(TLSProtocolSocketFactory.java:118)
    • 如果您尝试使用具有自签名证书的 java 连接到 Web 服务,也会出现此错误。 Java 需要通过将证书添加到 JKS 来显式信任证书。您是否有可能在大约同一时间切换到不同的 JDK 或更新到可能没有加载该 CA 的新 JDK?
    • 我在 samkeystore.jks 和 jre cacerts 中都加载了站点 CA。我看到的一个观察结果是,当我使用 Spring TLSSocketProtocolFcatory 而不是 Opensaml TLSProtocolFactory 的 verifyHostname 函数时,从 sslsesion.getPeerHost() 检索主机时,主机总是为空...
    • 有人得到解决方案吗?请帮忙。
    【解决方案2】:

    问题出在PKIXX509CredentialTrustEngine 的checkNames() 函数中,我们只检查trustedNames 集合的null 而不是"null or Empty"。

    即使我们传递了 trustedNames as null 在TLSProtocolSocketFactory 的getPKIXResolver() 方法中创建StaticPKIXValidationInformatonResolver,该类的构造函数将trustedNames 集合重新初始化为空集合。
    将线路从
    if(trustedNames == null) 更改为

    if(trustedNames == null || trustedNames.isEmpty())
    为我解决了问题。

    【讨论】:

      猜你喜欢
      • 2020-05-29
      • 2015-03-08
      • 1970-01-01
      • 2013-08-06
      • 2012-06-26
      • 2017-02-20
      • 2020-07-02
      • 1970-01-01
      • 2020-12-02
      相关资源
      最近更新 更多