Skip to content

Instantly share code, notes, and snippets.

@enriquemanuel
Last active March 10, 2020 19:42
Show Gist options
  • Save enriquemanuel/1193f27b8110b9a3b0effd5797daec9f to your computer and use it in GitHub Desktop.
Save enriquemanuel/1193f27b8110b9a3b0effd5797daec9f to your computer and use it in GitHub Desktop.
<Response Destination='https://cf.preprod.ds.va.gov/auth/saml_callback' ID='_0b19690b00569905d6b507c46bddf3ac6a1a' InResponseTo='_cb74f510-1990-4c3c-bf37-50cd7962d771' IssueInstant='2020-03-09T19:06:56Z' Version='2.0' xmlns='urn:oasis:names:tc:SAML:2.0:protocol'>
<ns1:Issuer Format='urn:oasis:names:tc:SAML:2.0:nameid-format:entity' xmlns:ns1='urn:oasis:names:tc:SAML:2.0:assertion'>VA_SSOi_IDP</ns1:Issuer><ds:Signature xmlns:ds='http://www.w3.org/2000/09/xmldsig#'>
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm='http://www.w3.org/2001/10/xml-exc-c14n#'/>
<ds:SignatureMethod Algorithm='http://www.w3.org/2001/04/xmldsig-more#rsa-sha256'/>
<ds:Reference URI='#_0b19690b00569905d6b507c46bddf3ac6a1a'>
<ds:Transforms>
<ds:Transform Algorithm='http://www.w3.org/2000/09/xmldsig#enveloped-signature'/>
<ds:Transform Algorithm='http://www.w3.org/2001/10/xml-exc-c14n#'/>
</ds:Transforms>
<ds:DigestMethod Algorithm='http://www.w3.org/2001/04/xmlenc#sha256'/>
<ds:DigestValue>8hvOh5HPjerRPhC69KX9Q8Img9ynkAGoE1sAY/WSG60=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>
yvg0ClM5cP5LZz8DkHVXURrsN+YyPocEurqLTe8G39OzySx4qHhcOSt6ZyHPYDKwUg4kY9GKNSaZ
XSRHAiYhHh15ogxedk20P3/tqbGTbv8pmf8bO20DpRpsDlN63nbYK+MGnb8VteSTG3ka+xSXAraq
CDRjzVSAHWo/oKQFQuzV8/t3Kesc943yxo8IrbJTnP+ZDW+IkNsLrfRSeTg3yBMkhxvcGwTmmXSe
JG1NS6pO2nWZKnBnwpD092Ut9DDHPDYfVIWmK+9SO6g+lAc5YWn/jMcWru2E9oU97dM4bHpctGkJ
IG/CxdZVPhaUBCNkQ1XtNqnWSy5gk/vFtr02uQ==
</ds:SignatureValue>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
MIIFRTCCBC2gAwIBAgIHPQAAACB/ZDANBgkqhkiG9w0BAQsFADBKMRMwEQYKCZImiZPyLGQBGRYD
Z292MRIwEAYKCZImiZPyLGQBGRYCdmExHzAdBgNVBAMTFlZBLUludGVybmFsLVMyLUlDQTEtdjEw
HhcNMTgwNjE4MjExMTQ1WhcNMjEwNjE3MjExMTQ1WjCBsjELMAkGA1UEBhMCVVMxETAPBgNVBAgT
CFZpcmdpbmlhMRAwDgYDVQQHEwdBc2hidXJuMSwwKgYDVQQKEyNVLlMuIERlcGFydG1lbnQgb2Yg
VmV0ZXJhbnMgQWZmYWlyczEMMAoGA1UECxMDSUFNMSEwHwYDVQQDExhsb2dvbi5wcmVwcm9kLmlh
bS52YS5nb3YxHzAdBgkqhkiG9w0BCQEWEGFjc2FkbWluc0B2YS5nb3YwggEiMA0GCSqGSIb3DQEB
AQUAA4IBDwAwggEKAoIBAQDO+en/aiQ5/fs9mQ0LfGi00VCvta0IiXQTSSc7XdKHqsgJLfJ2oaq6
JEkppWvtS0+pa3aZfrTU4Erd2mZ9Ur99IwIM0ZJHCNICGbKB/yA6nbFuu53Xo2P0Y7gLyhmTNlGO
Tdlln85Em6QRrrBGvZvxGVX/hthuCtnTv1u+Mhd5feXc7liWLgI6kpHKTnFPiYIq4BAtu6KKoKrA
QfM0BzKbKCc8+f/r1Ju4Ma+IdFYuP1TG14YH88FK+y/GdZ/EAEbZOPVxKNif8hyVwCa6nwvK8S/g
tEGNDh5tt+hs3SBBmuvBTE7qdbuSnJNNteyBXzhvHbBGD/r3jY3EOJaBXqf1AgMBAAGjggHFMIIB
wTALBgNVHQ8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMCMGA1UdEQQcMBqC
GGxvZ29uLnByZXByb2QuaWFtLnZhLmdvdjAdBgNVHQ4EFgQU7UpWRSA6BzdCpUR/wKN3EMvwSIow
HwYDVR0jBBgwFoAUG23f6z3l4g3vFrHQ3l9YGlbL5OwwSQYDVR0fBEIwQDA+oDygOoY4aHR0cDov
L2NybC5wa2kudmEuZ292L3BraS9jcmwvVkEtSW50ZXJuYWwtUzItSUNBMS12MS5jcmwwewYIKwYB
BQUHAQEEbzBtMEcGCCsGAQUFBzAChjtodHRwOi8vYWlhLnBraS52YS5nb3YvcGtpL2FpYS92YS9W
QS1JbnRlcm5hbC1TMi1JQ0ExLXYxLmNlcjAiBggrBgEFBQcwAYYWaHR0cDovL29jc3AucGtpLnZh
LmdvdjA9BgkrBgEEAYI3FQcEMDAuBiYrBgEEAYI3FQiByMMzgfnwBoGlnw2E4IEIhcKqSwaDgp9g
geCLUgIBZAIBFTAnBgkrBgEEAYI3FQoEGjAYMAoGCCsGAQUFBwMCMAoGCCsGAQUFBwMBMA0GCSqG
SIb3DQEBCwUAA4IBAQAsrFZmAF9OSWsm4YmxTqwAbLW8zppGvh6rhLHWHazGkIh6WlQqar7lu5Ku
JmIkTmH5dbT1XFnjHKTUZFI5PT3afVqpyDEVcg6McY7fxBOfC0tj8GHUrZWDsOKgA4Shr4QlFMYc
awY92Mv0KmAOFuXr+ybF8WGX1zNbF/P3qbywxShLJgSqUa8pP+eE1EO8pm447Ruj6e3odRzL/yi3
qOJJccJWHh5E5McQqrijsnmknbZ/KuavSiHEqHz73i9DrWnYCHtDa0mljsIa3LFOx7RVjNhqVta0
ME5eCoz7XeJ8KoFKPKHAY2XoDfGDg6JwM6pWDLyDazc1DkV+lBZd9s8m
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</ds:Signature>
<Status>
<StatusCode Value='urn:oasis:names:tc:SAML:2.0:status:Success'/>
</Status>
<ns2:Assertion ID='_321a9b0607c3af635a88ba4330eb1cca0406' IssueInstant='2020-03-09T19:06:56Z' Version='2.0' xmlns:ns2='urn:oasis:names:tc:SAML:2.0:assertion'>
<ns2:Issuer Format='urn:oasis:names:tc:SAML:2.0:nameid-format:entity'>VA_SSOi_IDP</ns2:Issuer><ds:Signature xmlns:ds='http://www.w3.org/2000/09/xmldsig#'>
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm='http://www.w3.org/2001/10/xml-exc-c14n#'/>
<ds:SignatureMethod Algorithm='http://www.w3.org/2001/04/xmldsig-more#rsa-sha256'/>
<ds:Reference URI='#_321a9b0607c3af635a88ba4330eb1cca0406'>
<ds:Transforms>
<ds:Transform Algorithm='http://www.w3.org/2000/09/xmldsig#enveloped-signature'/>
<ds:Transform Algorithm='http://www.w3.org/2001/10/xml-exc-c14n#'/>
</ds:Transforms>
<ds:DigestMethod Algorithm='http://www.w3.org/2001/04/xmlenc#sha256'/>
<ds:DigestValue>FxXmCV46iAnxuJezCFpDeA5ios6NDpcMaL8BiX12aFw=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>
smZRAGWRHU8LH0ZZjd117gcqn55ZH3nBs9dQLDYNoG8QwBINTnMuEjEAOnJCbyGVGQ9KkCoK/Mbf
NkHs6FHK24XyY6aAkLIG5UsFNxURb9LpUizPTrse2b7WELXSBGMsH/ex2eSJj7P+Xr/3qX0YJ0Ui
bDJcwJwYoIKUpclkIUSvqPs7ELD/TOjPrRfXG+fywKVV/bmRXVqdhalKcdE9/wEu2jAG+/6P7HIo
+vXNP72VOWuJiW1iXKDPIPXrkZIu6OcBpsnW+DhoXdtspbnGqs1ojX+VBNKtkP3QFeKEOb/MTQTr
M4Fo8XvECxAtnVLpqsE5uiDm8Uu5+1AskLHhKg==
</ds:SignatureValue>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
MIIFRTCCBC2gAwIBAgIHPQAAACB/ZDANBgkqhkiG9w0BAQsFADBKMRMwEQYKCZImiZPyLGQBGRYD
Z292MRIwEAYKCZImiZPyLGQBGRYCdmExHzAdBgNVBAMTFlZBLUludGVybmFsLVMyLUlDQTEtdjEw
HhcNMTgwNjE4MjExMTQ1WhcNMjEwNjE3MjExMTQ1WjCBsjELMAkGA1UEBhMCVVMxETAPBgNVBAgT
CFZpcmdpbmlhMRAwDgYDVQQHEwdBc2hidXJuMSwwKgYDVQQKEyNVLlMuIERlcGFydG1lbnQgb2Yg
VmV0ZXJhbnMgQWZmYWlyczEMMAoGA1UECxMDSUFNMSEwHwYDVQQDExhsb2dvbi5wcmVwcm9kLmlh
bS52YS5nb3YxHzAdBgkqhkiG9w0BCQEWEGFjc2FkbWluc0B2YS5nb3YwggEiMA0GCSqGSIb3DQEB
AQUAA4IBDwAwggEKAoIBAQDO+en/aiQ5/fs9mQ0LfGi00VCvta0IiXQTSSc7XdKHqsgJLfJ2oaq6
JEkppWvtS0+pa3aZfrTU4Erd2mZ9Ur99IwIM0ZJHCNICGbKB/yA6nbFuu53Xo2P0Y7gLyhmTNlGO
Tdlln85Em6QRrrBGvZvxGVX/hthuCtnTv1u+Mhd5feXc7liWLgI6kpHKTnFPiYIq4BAtu6KKoKrA
QfM0BzKbKCc8+f/r1Ju4Ma+IdFYuP1TG14YH88FK+y/GdZ/EAEbZOPVxKNif8hyVwCa6nwvK8S/g
tEGNDh5tt+hs3SBBmuvBTE7qdbuSnJNNteyBXzhvHbBGD/r3jY3EOJaBXqf1AgMBAAGjggHFMIIB
wTALBgNVHQ8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMCMGA1UdEQQcMBqC
GGxvZ29uLnByZXByb2QuaWFtLnZhLmdvdjAdBgNVHQ4EFgQU7UpWRSA6BzdCpUR/wKN3EMvwSIow
HwYDVR0jBBgwFoAUG23f6z3l4g3vFrHQ3l9YGlbL5OwwSQYDVR0fBEIwQDA+oDygOoY4aHR0cDov
L2NybC5wa2kudmEuZ292L3BraS9jcmwvVkEtSW50ZXJuYWwtUzItSUNBMS12MS5jcmwwewYIKwYB
BQUHAQEEbzBtMEcGCCsGAQUFBzAChjtodHRwOi8vYWlhLnBraS52YS5nb3YvcGtpL2FpYS92YS9W
QS1JbnRlcm5hbC1TMi1JQ0ExLXYxLmNlcjAiBggrBgEFBQcwAYYWaHR0cDovL29jc3AucGtpLnZh
LmdvdjA9BgkrBgEEAYI3FQcEMDAuBiYrBgEEAYI3FQiByMMzgfnwBoGlnw2E4IEIhcKqSwaDgp9g
geCLUgIBZAIBFTAnBgkrBgEEAYI3FQoEGjAYMAoGCCsGAQUFBwMCMAoGCCsGAQUFBwMBMA0GCSqG
SIb3DQEBCwUAA4IBAQAsrFZmAF9OSWsm4YmxTqwAbLW8zppGvh6rhLHWHazGkIh6WlQqar7lu5Ku
JmIkTmH5dbT1XFnjHKTUZFI5PT3afVqpyDEVcg6McY7fxBOfC0tj8GHUrZWDsOKgA4Shr4QlFMYc
awY92Mv0KmAOFuXr+ybF8WGX1zNbF/P3qbywxShLJgSqUa8pP+eE1EO8pm447Ruj6e3odRzL/yi3
qOJJccJWHh5E5McQqrijsnmknbZ/KuavSiHEqHz73i9DrWnYCHtDa0mljsIa3LFOx7RVjNhqVta0
ME5eCoz7XeJ8KoFKPKHAY2XoDfGDg6JwM6pWDLyDazc1DkV+lBZd9s8m
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</ds:Signature>
<ns2:Subject>
<ns2:NameID Format='urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress'>Sina.Amiri@va.gov</ns2:NameID>
<ns2:SubjectConfirmation Method='urn:oasis:names:tc:SAML:2.0:cm:bearer'>
<ns2:SubjectConfirmationData InResponseTo='_cb74f510-1990-4c3c-bf37-50cd7962d771' NotOnOrAfter='2020-03-09T19:08:26Z' Recipient='https://cf.preprod.ds.va.gov/auth/saml_callback'/>
</ns2:SubjectConfirmation>
</ns2:Subject>
<ns2:Conditions NotBefore='2020-03-09T19:06:26Z' NotOnOrAfter='2020-03-09T19:08:26Z'>
<ns2:AudienceRestriction>
<ns2:Audience>https://efolder.cf.ds.va.gov</ns2:Audience>
</ns2:AudienceRestriction>
</ns2:Conditions>
<ns2:AuthnStatement AuthnInstant='2020-03-09T19:06:55Z' SessionIndex='CNUDOnJgfhJyCR8+FkFczPyB4KM=S/gxCQ==' SessionNotOnOrAfter='2020-03-09T19:08:26Z'>
<ns2:AuthnContext>
<ns2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:Password</ns2:AuthnContextClassRef>
</ns2:AuthnContext>
</ns2:AuthnStatement>
<ns2:AttributeStatement>
<ns2:Attribute Name='VAUID' NameFormat='urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified'>
<ns2:AttributeValue>1620927</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name='assurLevel' NameFormat='urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified'>
<ns2:AttributeValue>3</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name='adUPN' NameFormat='urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified'>
<ns2:AttributeValue>Sina.Amiri@va.gov</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name='adSamAccountName' NameFormat='urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified'>
<ns2:AttributeValue>VACOAmiriS</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name='adDomain' NameFormat='urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified'>
<ns2:AttributeValue>DVA</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name='authNType' NameFormat='urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified'>
<ns2:AttributeValue>Direct</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name='adEmail' NameFormat='urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified'>
<ns2:AttributeValue>SINA.AMIRI@VA.GOV</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name='LastName' NameFormat='urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified'>
<ns2:AttributeValue>amiri</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name='FirstName' NameFormat='urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified'>
<ns2:AttributeValue>sina</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name='issueInstant' NameFormat='urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified'>
<ns2:AttributeValue>2020-03-09T19:06:55Z</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name='proofingAuth' NameFormat='urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified'>
<ns2:AttributeValue>VA-PIV</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name='transactionId' NameFormat='urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified'>
<ns2:AttributeValue>000080fe000000001f782f69853dc0b4-31b0-5e6693cf-24b0-02321350</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name='sessionScope' NameFormat='urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified'>
<ns2:AttributeValue>B</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name='Role' NameFormat='urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified'>
<ns2:AttributeValue>Role 1</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name='OrganizationID' NameFormat='urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified'>
<ns2:AttributeValue>urn:oid:2.16.840.1.113883.4.349</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name='Organization' NameFormat='urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified'>
<ns2:AttributeValue>Department of Veterans Affairs</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name='SECID' NameFormat='urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified'>
<ns2:AttributeValue>1017317439</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name='VaPIVUserId' NameFormat='urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified'>
<ns2:AttributeValue>1049648194136005</ns2:AttributeValue>
</ns2:Attribute>
<ns2:Attribute Name='PIVCardType' NameFormat='urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified'>
<ns2:AttributeValue>PIV</ns2:AttributeValue>
</ns2:Attribute>
</ns2:AttributeStatement>
</ns2:Assertion></Response>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment