← Back to plugin index

SAML Assertion Cookie Identity Propagator

Description
Cookie based identity propagator that sets a cookie containing a SAML2 assertion.

The assertion contains the "sender-vouches" subject confirmation method which can be used by the receiver for example for the "Web Services Security SAML Token Profile".

Type name
SamlAssertionCookieIdentityPropagator
Class
com.airlock.iam.saml2.application.configuration.SamlAssertionCookieIdentityPropagator
May be used by
Properties
Cookie Name (cookieName)
Description
The name of the cookie used to transport the SAML2 Assertion.

Note that only one cookie per cookie path and name can exist. Make sure that this cookie name does not clash with other cookie's names. For example, do not use session cookie names such as "JSESSIONID".

Attributes
String
Mandatory
Example
assertionCookie
Example
medusaAuth
Cookie Path (cookiePath)
Description
The path for which the cookie is set. The path determines where the cookie is sent by the reverse proxy (or browser).

If one single assertion cookie is used for all applications, the value "/" can be used. If different tickets are used for different applications, the application's path should be used.

Note that only one cookie per cookie path and name can exist. Make sure that this cookie name does not clash with other cookie's names. For example, do not use session cookie names such as "JSESSIONID".

Make sure the configuration flag Interpret Cookie Domains is set in the Airlock Gateway (WAF) configuration. If not, the cookie path is ignored and cookies in the cookie store are sent to any back-end HTTP request of the same session. This also means that there may be only one cookie per cookie name!
It is best to consult the corresponding documentation of the web entry server or reverse proxy to get more accurate information on cookie handling.

Attributes
String
Optional
Default value
/
Example
/
Example
/appl1
Example
/appl2
Cookie Domain (cookieDomain)
Description
The domain for which the cookie is set. The domain determines where the cookie is sent by the reverse proxy (or browser).

Because of security restrictions in browsers (same origin policy) it is usually not possible to set a cookie for a different domain unless the right-most two domain parts (e.g. "ergon.ch") are equal to that of the application setting the cookie.
It is possible that there are further restrictions regarding this in browsers.

If you are using a HTTP reverse proxy that stores the cookie in its session store (and does not send it to the client), make sure to understand the proxies interpretation of the cookie domain and cookie path.

Make sure the configuration flag Interpret Cookie Domains is set in the Airlock Gateway (WAF) configuration. If not the cookie domain is ignored and cookies in the cookie store are sent to any back-end HTTP request of the same session. The cookie path is also ignored meaning that there may be only one cookie per cookie name!
Airlock also supports the following cookie domain values (if the flag Interpret Cookie Domains is set):

  • The value .* results in cookies being sent to all back-end servers. This is especially useful if one authentication ticket is used for multiple back-ends.
  • The value @<fully-qualified-host> results in the cookie being treated as if it were set by the host specified by "<fully-qualified-host>". If using this value, make sure the corresponding mapping also uses the fully qualified hostname.
It is best to consult the corresponding documentation of the web entry server or reverse proxy to get more accurate information on cookie handling.

If one single assertion cookie is used for all applications, the value "/" can be used. If different cookies are used for different applications, the applications path should be used.

Attributes
String
Optional
Example
@anotherbackend.com
Example
.*
Example
mybackend.com
Cookie Secure Flag (cookieSecureFlag)
Description
If set to TRUE the "secure"-flag of the cookie is set.

If the cookie is marked as secure, the browser (and any HTTP proxy behaving like a browser) should send the cookie only over secure connections.
Caution: If you think that setting this flag makes your application more secure, remember that this flag just "asks" the browser to not transmit the cookie over unencrypted connections.

Attributes
Boolean
Optional
Default value
false
Cookie Encoding Scheme (cookieEncodingScheme)
Description
Assertions must be URL encoded in order to be suitable as cookie values. This optional property defines the URL encoding scheme to be used.
Make sure that the component receiving the ticket uses the same URL encoding scheme.
Attributes
String
Optional
Default value
UTF-8
Allowed values
UTF-8, ISO-8859-1, UTF-16, UTF-16BE, UTF-16LE, US-ASCII, ISO-8859-15
Issuer (issuer)
Description
The Issuer set in the SAML2 Assertion.
Attributes
String
Mandatory
Example
AirlockIAM
Example
AirlockIdp
Subject Template (subjectTemplate)
Description
The template used to insert the user's ID in the Subject element of the Assertion. The string "${userId}" gets replaced by the user's name.
Attributes
String
Optional
Default value
${userId}
Example
${userId}
Example
User_${userId}
Subject Confirmation Method (subjectConfirmationMethod)
Description
The subject confirmation method to use in the assertion.
Attributes
String
Optional
Default value
urn:oasis:names:tc:SAML:2.0:cm:sender-vouches
Suggested values
urn:oasis:names:tc:SAML:2.0:cm:sender-vouches, urn:oasis:names:tc:SAML:2.0:cm:bearer, urn:oasis:names:tc:SAML:2.0:cm:holder-of-key
Name Id Format (nameIdFormat)
Description
The NameID Format to use in the assertion.
Attributes
String
Optional
Default value
urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
Suggested values
urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress, urn:oasis:names:tc:SAML:2.0:nameid-format:persistent, urn:oasis:names:tc:SAML:2.0:nameid-format:transient
Sp Provided Id (spProvidedId)
Description
The SPProvidedId is an attribute of the NameID tag and refers to the actual name that was provided at authentication. If set, this attribute will be added to the assertion. The name of the attribute does not matter. Use @param:PROVIDED_USERNAME as "value" to refer to the username as provided by the user.
Attributes
Plugin-Link
Optional
Assignable plugins
Attributes (attributes)
Description
Defines a list of attributes to be added to the issued assertion. The value of the attribute can either be statically configured or taken from the user.
Attributes
Plugin-List
Optional
Assignable plugins
Assertion Validity Millis (assertionValidityMillis)
Description
The Assertion Validity time in milliseconds. This sets the NotOnOrAfter attribute to the specified instant in the future.
Attributes
Integer
Optional
Default value
30000
Assertion Not Before Skew Millis (assertionNotBeforeSkewMillis)
Description
The maximum number of milliseconds the clocks on the involved parties are allowed to be different. This sets the NotBefore attribute in the SAML assertion to the current time minus the specified number of milliseconds.
Attributes
Integer
Optional
Default value
5000
Xml Signature Algorithm (xmlSignatureAlgorithm)
Description
XML signature algorithm. Used for SAML XML signature generation.
The (deprecated) value "SHA1 (automatic RSA/DSA)" automatically chooses "http://www.w3.org/2000/09/xmldsig#rsa-sha1" or "http://www.w3.org/2000/09/xmldsig#dsa-sha1" depending on the type of the key found in the keystore. However please use a more secure hash instead, as SHA-1 is not considered to be secure.
Attributes
String
Optional
Default value
http://www.w3.org/2001/04/xmldsig-more#rsa-sha256
Allowed values
http://www.w3.org/2001/04/xmldsig-more#rsa-sha512, http://www.w3.org/2001/04/xmldsig-more#rsa-sha384, http://www.w3.org/2001/04/xmldsig-more#rsa-sha256, http://www.w3.org/2000/09/xmldsig#rsa-sha1, http://www.w3.org/2000/09/xmldsig#dsa-sha1, http://www.w3.org/2000/09/xmldsig#hmac-sha1, http://www.w3.org/2001/04/xmldsig-more#rsa-ripemd160, http://www.w3.org/2001/04/xmldsig-more#rsa-md5, http://www.w3.org/2001/04/xmldsig-more#hmac-md5, http://www.w3.org/2001/04/xmldsig-more#hmac-ripemd160, http://www.w3.org/2001/04/xmldsig-more#hmac-sha256, http://www.w3.org/2001/04/xmldsig-more#hmac-sha384, http://www.w3.org/2001/04/xmldsig-more#hmac-sha512, SHA1 (automatic RSA/DSA)
Xml Signature Digest Method (xmlSignatureDigestMethod)
Description
XML signature digest method. Used for SAML XML signature generation and verification.
Attributes
String
Optional
Default value
http://www.w3.org/2001/04/xmlenc#sha256
Allowed values
http://www.w3.org/2001/04/xmlenc#sha512, http://www.w3.org/2001/04/xmlenc#sha256, http://www.w3.org/2000/09/xmldsig#sha1, http://www.w3.org/2001/04/xmlenc#ripemd160
Keystore File (keystoreFile)
Description
JKS Keystore file name containing the certificate and key used to sign the SAML2 Assertion.
Attributes
File/Path
Mandatory
Keystore Password (keystorePassword)
Description
The password used open the keystore.
Attributes
String
Mandatory
Sensitive
Signing Key Alias (signingKeyAlias)
Description
The alias of the key used to sign the Assertion.
Attributes
String
Mandatory
Example
medusaCert
Signing Key Password (signingKeyPassword)
Description
The password used to retrieve the key from the keystore. This password can be the same as the keystore password.
Attributes
String
Mandatory
Sensitive
Audience Restrictions (audienceRestrictions)
Description

If set, adds the given audiences to an AudienceRestriction element. This is usually not required. Each element of this list is included in the AudienceRestriction as a separate Audience.

e.g. If this list contains the Strings: {"https://1.airlock.com","https://2.airlock.com"} the resulting condition contains:
<saml:Conditions ...>
<saml:AudienceRestriction>
<saml:Audience>https://1.airlock.com</saml:Audience>
<saml:Audience>https://2.airlock.com</saml:Audience>
</saml:AudienceRestriction>
</saml:Conditions>
Attributes
String-List
Optional
Enable Subject Confirmation (enableSubjectConfirmation)
Description
If enabled, a SubjectConfirmation element is added to the Assertion. This should only be disabled if the receiver doesn't support this element.
Attributes
Boolean
Optional
Default value
true
Enable Authn Statement (enableAuthnStatement)
Description
If enabled, an AuthnStatement element is added to the Assertion. This should only be disabled if the receiver doesn't support this element.
Attributes
Boolean
Optional
Default value
true
YAML Template (with default values)

type: SamlAssertionCookieIdentityPropagator
id: SamlAssertionCookieIdentityPropagator-xxxxxx
displayName: 
comment: 
properties:
  assertionNotBeforeSkewMillis: 5000
  assertionValidityMillis: 30000
  attributes:
  audienceRestrictions:
  cookieDomain:
  cookieEncodingScheme: UTF-8
  cookieName:
  cookiePath: /
  cookieSecureFlag: false
  enableAuthnStatement: true
  enableSubjectConfirmation: true
  issuer:
  keystoreFile:
  keystorePassword:
  nameIdFormat: urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
  signingKeyAlias:
  signingKeyPassword:
  spProvidedId:
  subjectConfirmationMethod: urn:oasis:names:tc:SAML:2.0:cm:sender-vouches
  subjectTemplate: ${userId}
  xmlSignatureAlgorithm: http://www.w3.org/2001/04/xmldsig-more#rsa-sha256
  xmlSignatureDigestMethod: http://www.w3.org/2001/04/xmlenc#sha256