void testSAML2POST() {
try {
QName idprole(samlconstants::SAML20MD_NS, IDPSSODescriptor::LOCAL_NAME);
- SecurityPolicy policy(m_rules2, m_metadata, &idprole, m_trust);
+ SecurityPolicy policy(m_rules2, m_metadata, &idprole, m_trust, false);
// Read message to use from file.
string path = data_path + "saml2/binding/SAML2Response.xml";
);
janitor.release();
+ CredentialCriteria cc;\r
+ cc.setUsage(CredentialCriteria::SIGNING_CREDENTIAL);\r
+ Locker clocker(m_creds);\r
+ const Credential* cred = m_creds->resolve(&cc);\r
+ TSM_ASSERT("Retrieved credential was null", cred!=NULL);\r
+
// Freshen timestamp and ID.
toSend->setIssueInstant(time(NULL));
toSend->setID(NULL);
samlconstants::SAML20_BINDING_HTTP_POST, encoder_config->getDocumentElement()
)
);
- encoder->encode(*this,toSend.get(),"https://sp.example.org/SAML/SSO","https://sp.example.org/","state",m_creds);
+ encoder->encode(*this,toSend.get(),"https://sp.example.org/SAML/SSO","https://sp.example.org/","state",cred);
toSend.release();
// Decode message.
// Test the results.
TSM_ASSERT_EQUALS("RelayState was not the expected result.", relayState, "state");
TSM_ASSERT("SAML Response not decoded successfully.", response.get());
- TSM_ASSERT("Message was not verified.", policy.isSecure());\r
+ TSM_ASSERT("Message was not verified.", policy.isSecure());
auto_ptr_char entityID(policy.getIssuer()->getName());
TSM_ASSERT("Issuer was not expected.", !strcmp(entityID.get(),"https://idp.example.org/"));
TSM_ASSERT_EQUALS("Assertion count was not correct.", response->getAssertions().size(), 1);
// Trigger a replay.
policy.reset();
- TSM_ASSERT_THROWS("Did not catch the replay.", decoder->decode(relayState,*this,policy), BindingException);
+ TSM_ASSERT_THROWS("Did not catch the replay.", decoder->decode(relayState,*this,policy), SecurityPolicyException);
}
catch (XMLToolingException& ex) {
TS_TRACE(ex.what());
void testSAML2POSTSimpleSign() {
try {
QName idprole(samlconstants::SAML20MD_NS, IDPSSODescriptor::LOCAL_NAME);
- SecurityPolicy policy(m_rules2, m_metadata, &idprole, m_trust);
+ SecurityPolicy policy(m_rules2, m_metadata, &idprole, m_trust, false);
// Read message to use from file.
string path = data_path + "saml2/binding/SAML2Response.xml";
);
janitor.release();
+ CredentialCriteria cc;\r
+ cc.setUsage(CredentialCriteria::SIGNING_CREDENTIAL);\r
+ Locker clocker(m_creds);\r
+ const Credential* cred = m_creds->resolve(&cc);\r
+ TSM_ASSERT("Retrieved credential was null", cred!=NULL);\r
+
// Freshen timestamp and ID.
toSend->setIssueInstant(time(NULL));
toSend->setID(NULL);
samlconstants::SAML20_BINDING_HTTP_POST_SIMPLESIGN, encoder_config->getDocumentElement()
)
);
- encoder->encode(*this,toSend.get(),"https://sp.example.org/SAML/SSO","https://sp.example.org/","state",m_creds);
+ encoder->encode(*this,toSend.get(),"https://sp.example.org/SAML/SSO","https://sp.example.org/","state",cred);
toSend.release();
// Decode message.
// Test the results.
TSM_ASSERT_EQUALS("RelayState was not the expected result.", relayState, "state");
TSM_ASSERT("SAML Response not decoded successfully.", response.get());
- TSM_ASSERT("Message was not verified.", policy.isSecure());\r
+ TSM_ASSERT("Message was not verified.", policy.isSecure());
auto_ptr_char entityID(policy.getIssuer()->getName());
TSM_ASSERT("Issuer was not expected.", !strcmp(entityID.get(),"https://idp.example.org/"));
TSM_ASSERT_EQUALS("Assertion count was not correct.", response->getAssertions().size(), 1);
// Trigger a replay.
policy.reset();
- TSM_ASSERT_THROWS("Did not catch the replay.", decoder->decode(relayState,*this,policy), BindingException);
+ TSM_ASSERT_THROWS("Did not catch the replay.", decoder->decode(relayState,*this,policy), SecurityPolicyException);
}
catch (XMLToolingException& ex) {
TS_TRACE(ex.what());