Skip to content

Instantly share code, notes, and snippets.

@tecsyscom
Created April 12, 2017 14:01
Show Gist options
  • Save tecsyscom/f0b5cce84821ad715d89532865376074 to your computer and use it in GitHub Desktop.
Save tecsyscom/f0b5cce84821ad715d89532865376074 to your computer and use it in GitHub Desktop.
sample SAML request from keyCloak
<samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Destination="https://signin.aws.amazon.com/saml" ID="ID_15d519a5-88ac-4d2d-8206-409e570a0987" IssueInstant="2017-04-12T09:36:17.883Z" Version="2.0"><saml:Issuer>http://127.0.0.1:8080/auth/realms/aws</saml:Issuer><dsig:Signature xmlns:dsig="http://www.w3.org/2000/09/xmldsig#"><dsig:SignedInfo><dsig:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/><dsig:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/><dsig:Reference URI="#ID_15d519a5-88ac-4d2d-8206-409e570a0987"><dsig:Transforms><dsig:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/><dsig:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/></dsig:Transforms><dsig:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/><dsig:DigestValue>3cCxC7wj/4NIZAvVdU1xdlbfihU7q5OllDCLJ1TdbUw=</dsig:DigestValue></dsig:Reference></dsig:SignedInfo><dsig:SignatureValue>JGx82KgE3/AlFnqSKsNpbZgvF7+7XDrilC06oOneQ5rKlW8LPYSgzDXE02Sp0jlHuhekfnf9mNQDdfxTPXLxf3CwpOBjHQ+bPQA2xg2Oq6+DLS6VIAPLao40RWjqxCDDKv34xMBddzfAcIcL0bv45aa4+ZD8Q6eFbUmRtXZt9coOTF161GOyAOcsr/aO2tupRuYD4PB60s3c+cwHxPY3QBpPLys3mXyIAvCFS7r/Q2B2mUYIVhlZsb+gBmDWIABdHtlZ2OXA+37Emfw8NQ6D7kv78CxO6OWHZn707kQXS1D4tlvVXPPePbjPtJ+7Guu+DQxZYYqcgZpF3CfiwApYxQ==</dsig:SignatureValue><dsig:KeyInfo><dsig:X509Data><dsig:X509Certificate>MIIClTCCAX0CBgFbYQaf6zANBgkqhkiG9w0BAQsFADAOMQwwCgYDVQQDDANhd3MwHhcNMTcwNDEyMDcxNjE1WhcNMjcwNDEyMDcxNzU1WjAOMQwwCgYDVQQDDANhd3MwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCgfyPfhCt3JSR0kYFPm/ADdtnAS48CnZkvyrB4yNcsSNImA9VxChbJqrWQnvDMrq+AK95ufgQvSIWq+h8dnRrojXlCQS0d+X6qj76XcUqRaO7u/cMr/MyaKt09QUAllj4Xsn/OKalYUhZ1CZ5X/iWCDk5cEeXoMsBsWa0zDRny16erTdaDqOgzeRF3Rn7Wllrja98Gs+pwpSbzhd23aTHVqzVzUY67LlfRWvHNr9QhBnDWV8z29C/C9csO7li3QSxv43wBfl2SE7Vd6NNITCK6M/nhSZqv3KbIIvUOTf8juc103p2RvLUOomMVob/4bQTARf0L0z68QYijw67io8CTAgMBAAEwDQYJKoZIhvcNAQELBQADggEBAAckPF92aPx9dx3EUpvPeIIoLM/lItDf1B1srU3F5YsJrZ2FiWRxxNt/wJkD4Lq/jrMs6xwECFEnicp3ph+vFyFTRHB9hAAiLTnnBjalrjBgbtH5n+EuJaTQA/86OdNwAMVcH+QOtCgy5XoICVxbTON1RY91p4hZAPvm28cQr8ihix5wa/MDBJODDV7Pr+qOV/WZEoRfS9gJMkxu3NfT/q7DB0pMV5dSBy6CIGcAUeaUh+IbV+mJcx2qy4xWw1HArkym7GsR6NEDvWjHCkN+Car8evktOed5KO1VnNX6cXa1ovQqFEV4URixkq0yjMbYZ95nZK48hUUn4gdyDv2FdI0=</dsig:X509Certificate></dsig:X509Data><dsig:KeyValue><dsig:RSAKeyValue><dsig:Modulus>oH8j34QrdyUkdJGBT5vwA3bZwEuPAp2ZL8qweMjXLEjSJgPVcQoWyaq1kJ7wzK6vgCvebn4EL0iFqvofHZ0a6I15QkEtHfl+qo++l3FKkWju7v3DK/zMmirdPUFAJZY+F7J/zimpWFIWdQmeV/4lgg5OXBHl6DLAbFmtMw0Z8tenq03Wg6joM3kRd0Z+1pZa42vfBrPqcKUm84Xdt2kx1as1c1GOuy5X0Vrxza/UIQZw1lfM9vQvwvXLDu5Yt0Esb+N8AX5dkhO1XejTSEwiujP54Umar9ymyCL1Dk3/I7nNdN6dkby1DqJjFaG/+G0EwEX9C9M+vEGIo8Ou4qPAkw==</dsig:Modulus><dsig:Exponent>AQAB</dsig:Exponent></dsig:RSAKeyValue></dsig:KeyValue></dsig:KeyInfo></dsig:Signature><samlp:Status><samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/></samlp:Status><saml:Assertion xmlns="urn:oasis:names:tc:SAML:2.0:assertion" ID="ID_a6ebc383-7271-41e6-9f45-a0be66e958ce" IssueInstant="2017-04-12T09:36:17.882Z" Version="2.0"><saml:Issuer>http://127.0.0.1:8080/auth/realms/aws</saml:Issuer><dsig:Signature xmlns:dsig="http://www.w3.org/2000/09/xmldsig#"><dsig:SignedInfo><dsig:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/><dsig:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/><dsig:Reference URI="#ID_a6ebc383-7271-41e6-9f45-a0be66e958ce"><dsig:Transforms><dsig:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/><dsig:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/></dsig:Transforms><dsig:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/><dsig:DigestValue>gZk6dDepQMSeQrCzNo2s1+o5KKsFdUBIvjrVjW+Wqbg=</dsig:DigestValue></dsig:Reference></dsig:SignedInfo><dsig:SignatureValue>O2g3s/9qoJ8BjxxnPMAPTLo6Mb5LzYfO0puKHQU2uSpnK/aOOqsv/k2zCZOnAQJNa8SzAfo3wlFyXK1MiMzQ9Ilcsb7gREVCe0Ow/MWQ7AVDZ5O2OClCOvz8wHgQ1FWM3rL1Y1Z+n7fsN/nMEk8ussRYUAR4f0GBOd8k+EfjgzneV9//SD34aqEzEn4j/QI1fld1AtxNiWsrzG/cqs0MZAyYH1KVTpvMMmX8yBZJT5kskXGk8jBhgMKysXjNWiFR2tB/wSg3QQU2TtrkDh96YIRvtyNw2ac3COXS7ri3JcruebUV8CGhOyV5o4sycdy3HJ0898mPMkU+qZia5Ci21Q==</dsig:SignatureValue><dsig:KeyInfo><dsig:X509Data><dsig:X509Certificate>MIIClTCCAX0CBgFbYQaf6zANBgkqhkiG9w0BAQsFADAOMQwwCgYDVQQDDANhd3MwHhcNMTcwNDEyMDcxNjE1WhcNMjcwNDEyMDcxNzU1WjAOMQwwCgYDVQQDDANhd3MwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCgfyPfhCt3JSR0kYFPm/ADdtnAS48CnZkvyrB4yNcsSNImA9VxChbJqrWQnvDMrq+AK95ufgQvSIWq+h8dnRrojXlCQS0d+X6qj76XcUqRaO7u/cMr/MyaKt09QUAllj4Xsn/OKalYUhZ1CZ5X/iWCDk5cEeXoMsBsWa0zDRny16erTdaDqOgzeRF3Rn7Wllrja98Gs+pwpSbzhd23aTHVqzVzUY67LlfRWvHNr9QhBnDWV8z29C/C9csO7li3QSxv43wBfl2SE7Vd6NNITCK6M/nhSZqv3KbIIvUOTf8juc103p2RvLUOomMVob/4bQTARf0L0z68QYijw67io8CTAgMBAAEwDQYJKoZIhvcNAQELBQADggEBAAckPF92aPx9dx3EUpvPeIIoLM/lItDf1B1srU3F5YsJrZ2FiWRxxNt/wJkD4Lq/jrMs6xwECFEnicp3ph+vFyFTRHB9hAAiLTnnBjalrjBgbtH5n+EuJaTQA/86OdNwAMVcH+QOtCgy5XoICVxbTON1RY91p4hZAPvm28cQr8ihix5wa/MDBJODDV7Pr+qOV/WZEoRfS9gJMkxu3NfT/q7DB0pMV5dSBy6CIGcAUeaUh+IbV+mJcx2qy4xWw1HArkym7GsR6NEDvWjHCkN+Car8evktOed5KO1VnNX6cXa1ovQqFEV4URixkq0yjMbYZ95nZK48hUUn4gdyDv2FdI0=</dsig:X509Certificate></dsig:X509Data><dsig:KeyValue><dsig:RSAKeyValue><dsig:Modulus>oH8j34QrdyUkdJGBT5vwA3bZwEuPAp2ZL8qweMjXLEjSJgPVcQoWyaq1kJ7wzK6vgCvebn4EL0iFqvofHZ0a6I15QkEtHfl+qo++l3FKkWju7v3DK/zMmirdPUFAJZY+F7J/zimpWFIWdQmeV/4lgg5OXBHl6DLAbFmtMw0Z8tenq03Wg6joM3kRd0Z+1pZa42vfBrPqcKUm84Xdt2kx1as1c1GOuy5X0Vrxza/UIQZw1lfM9vQvwvXLDu5Yt0Esb+N8AX5dkhO1XejTSEwiujP54Umar9ymyCL1Dk3/I7nNdN6dkby1DqJjFaG/+G0EwEX9C9M+vEGIo8Ou4qPAkw==</dsig:Modulus><dsig:Exponent>AQAB</dsig:Exponent></dsig:RSAKeyValue></dsig:KeyValue></dsig:KeyInfo></dsig:Signature><saml:Subject><saml:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient">G-347053b3-2e93-4f91-9f95-717d507c41e6</saml:NameID><saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><saml:SubjectConfirmationData NotOnOrAfter="2017-04-12T09:41:15.882Z" Recipient="https://signin.aws.amazon.com/saml"/></saml:SubjectConfirmation></saml:Subject><saml:Conditions NotBefore="2017-04-12T09:36:15.882Z" NotOnOrAfter="2017-04-12T09:37:15.882Z"><saml:AudienceRestriction><saml:Audience>urn:amazon:webservices</saml:Audience></saml:AudienceRestriction></saml:Conditions><saml:AuthnStatement AuthnInstant="2017-04-12T09:36:17.884Z" SessionIndex="bce62ede-2786-48e1-a27c-728ddf7bd7d2"><saml:AuthnContext><saml:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified</saml:AuthnContextClassRef></saml:AuthnContext></saml:AuthnStatement><saml:AttributeStatement><saml:Attribute FriendlyName="Session Name" Name="https://aws.amazon.com/SAML/Attributes/RoleSessionName" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"><saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">mingderwang</saml:AttributeValue></saml:Attribute><saml:Attribute FriendlyName="Session Duration" Name="https://aws.amazon.com/SAML/Attributes/SessionDuration" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"><saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">7220</saml:AttributeValue></saml:Attribute><saml:Attribute FriendlyName="Session Role" Name="https://aws.amazon.com/SAML/Attributes/Role" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"><saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">arn:aws:iam::397676937498:role/mykeyCloak</saml:AttributeValue><saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">uma_authorization</saml:AttributeValue></saml:Attribute></saml:AttributeStatement></saml:Assertion></samlp:Response>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment