Skip to content

AssertionConsumerServiceURL mismatch between Request and configured metadata is handled too gracefully #2653

Description

@restena-sw

Specifics of your environment

  1. simpleSAMLphp is an IdP
  2. SimpleSAMLphp version is 2.5.2
  3. PHP is version 8.3
  4. Platform is Linux
  5. Webserver is an nginx frontend with FPM backend

Describe the bug
If a SAML SP sends an AuthNRequest with the optional parameter AssertionConsumerServiceURL, and that URL is not contained in the SP configured metadata, and the request is not signed, then authentication succeeds and SSP sends the assertion back to one of the URLs from metadata.

However, the SAML spec states

AssertionConsumerServiceURL [Optional]
Specifies by value the location to which the message MUST be returned to the
requester. The responder MUST ensure by some means that the value specified is in fact associated
with the requester.

One way is signed requests - in this case it is okay to continue the authentication and take the received AssertionConsumerServiceURL at face value.

Another way is pre-configured metadata. In that case, a mismatch is a problem.

Expected behavior
In the given situation (unsigned request, stored metadata with different ACS URLs), it is impossible to satisfy both MUST conditions simultaneously; one of the two is always violated. A protocol violation should not lead to successful auth, but raise a fatal protocol error instead.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions