|
| 1 | +<?xml version="1.0"?> |
| 2 | +<samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" ID="pfx0a3cfa31-f178-71f2-9b94-ad4047591acc" Version="2.0" IssueInstant="2012-04-04T07:33:10.921Z" Destination="https://example.com/endpoint"> |
| 3 | + <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">idp.example.com</saml:Issuer> |
| 4 | + <samlp:Status> |
| 5 | + <samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/> |
| 6 | + </samlp:Status> |
| 7 | + <saml:Assertion xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Version="2.0" IssueInstant="2012-04-04T07:33:10.923Z" ID="unsigned-assertion"> |
| 8 | + <saml:Issuer>idp.myexample.org</saml:Issuer><ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> |
| 9 | + <ds:SignedInfo><ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/> |
| 10 | + <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/> |
| 11 | + <ds:Reference URI="#pfx7fca52d6-8991-5d99-3147-4f9d7c278d78"><ds:Transforms><ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/><ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/></ds:Transforms><ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/><ds:DigestValue>FA0AbR4w9oYdx7MFjERARVJAHps=</ds:DigestValue></ds:Reference></ds:SignedInfo><ds:SignatureValue>GDH5jhCNX9PFxW+71SOJPyusAOwzECwmd57NDhvA/VKWHnV3PpvpNkOLyamoBNdZ4qxponnobg2zneLESrFnLJdJ1cgs51YvtBJTxKoA7oZMMNKReZFST8g7pDdrBC82n5rTdzxclaJkpwz1yjcho3K3TjxK+gU1svVrEKMUwyo=</ds:SignatureValue> |
| 12 | +<ds:KeyInfo><ds:X509Data><ds:X509Certificate>MIICGzCCAYQCCQCNNcQXom32VDANBgkqhkiG9w0BAQUFADBSMQswCQYDVQQGEwJVUzELMAkGA1UECBMCSU4xFTATBgNVBAcTDEluZGlhbmFwb2xpczERMA8GA1UEChMIT25lTG9naW4xDDAKBgNVBAsTA0VuZzAeFw0xNDA0MjMxODQxMDFaFw0xNTA0MjMxODQxMDFaMFIxCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJJTjEVMBMGA1UEBxMMSW5kaWFuYXBvbGlzMREwDwYDVQQKEwhPbmVMb2dpbjEMMAoGA1UECxMDRW5nMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDo6m+QZvYQ/xL0ElLgupK1QDcYL4f5PckwsNgS9pUvV7fzTqCHk8ThLxTk42MQ2McJsOeUJVP728KhymjFCqxgP4VuwRk9rpAl0+mhy6MPdyjyA6G14jrDWS65ysLchK4t/vwpEDz0SQlEoG1kMzllSm7zZS3XregA7DjNaUYQqwIDAQABMA0GCSqGSIb3DQEBBQUAA4GBALM2vGCiQ/vm+a6v40+VX2zdqHA2Q/1vF1ibQzJ54MJCOVWvs+vQXfZFhdm0OPM2IrDU7oqvKPqP6xOAeJK6H0yP7M4YL3fatSvIYmmfyXC9kt3Svz/NyrHzPhUnJ0ye/sUSXxnzQxwcm/9PwAqrQaA3QpQkH57ybF/OoryPe+2h</ds:X509Certificate></ds:X509Data></ds:KeyInfo></ds:Signature> |
| 13 | + <saml:Subject> |
| 14 | + < saml:NameID NameQualifier= "idp.example.com" Format= "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"> [email protected]</ saml:NameID> |
| 15 | + <saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"> |
| 16 | + <saml:SubjectConfirmationData Recipient="https://example.com/endpoint" InResponseTo="_f7201940-6055-012f-3bc1-782bcb13c426"/> |
| 17 | + </saml:SubjectConfirmation> |
| 18 | + </saml:Subject> |
| 19 | + <saml:Conditions NotBefore="2012-04-04T07:28:11.442Z" NotOnOrAfter="2012-04-04T07:38:11.442Z"> |
| 20 | + <saml:AudienceRestriction> |
| 21 | + <saml:Audience>example.com</saml:Audience> |
| 22 | + </saml:AudienceRestriction> |
| 23 | + </saml:Conditions> |
| 24 | + <saml:AuthnStatement AuthnInstant="2012-04-04T07:33:11.442Z"> |
| 25 | + <saml:AuthnContext> |
| 26 | + <saml:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml:AuthnContextClassRef> |
| 27 | + </saml:AuthnContext> |
| 28 | + </saml:AuthnStatement> |
| 29 | + </saml:Assertion> |
| 30 | + <foo> |
| 31 | + <saml:Assertion xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Version="2.0" IssueInstant="2012-04-04T07:33:10.923Z" ID="pfx7fca52d6-8991-5d99-3147-4f9d7c278d78"> |
| 32 | + <saml:Issuer>idp.myexample.org</saml:Issuer> |
| 33 | + <saml:Subject> |
| 34 | + < saml:NameID NameQualifier= "idp.example.com" Format= "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"> [email protected]</ saml:NameID> |
| 35 | + <saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"> |
| 36 | + <saml:SubjectConfirmationData Recipient="https://example.com/endpoint" InResponseTo="_f7201940-6055-012f-3bc1-782bcb13c426"/> |
| 37 | + </saml:SubjectConfirmation> |
| 38 | + </saml:Subject> |
| 39 | + <saml:Conditions NotBefore="2012-04-04T07:28:11.442Z" NotOnOrAfter="2012-04-04T07:38:11.442Z"> |
| 40 | + <saml:AudienceRestriction> |
| 41 | + <saml:Audience>example.com</saml:Audience> |
| 42 | + </saml:AudienceRestriction> |
| 43 | + </saml:Conditions> |
| 44 | + <saml:AuthnStatement AuthnInstant="2012-04-04T07:33:11.442Z"> |
| 45 | + <saml:AuthnContext> |
| 46 | + <saml:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml:AuthnContextClassRef> |
| 47 | + </saml:AuthnContext> |
| 48 | + </saml:AuthnStatement> |
| 49 | + </saml:Assertion> |
| 50 | + </foo> |
| 51 | +</samlp:Response> |
0 commit comments