Hi thanks for your response,
it seems you got a point so I checked all the dates and made the a small time shift there just in case. Unfortunately I still get the same error as before. Maybe I am missing something here so here is what I got this time:
Here are all the dates:
ResponseTimestamp ="2012-02-15 08:48:13Z"
wsu:Created ="2012-02-15T08:38:09.601Z"
wsu:Expires ="2012-02-15T09:48:09.601Z"
IssueInstant ="2012-02-15T08:48:09.663Z"
NotBefore ="2012-02-15T08:38:09.601Z"
NotOnOrAfter ="2012-02-15T09:48:09.601Z"
The response with the json error:
ACS_response:
{
"context": "http://localhost:6643/syndesi",
"httpReturnCode": 401,
"identityProvider": null,
"timeStamp": "2012-02-15 08:48:13Z",
"traceId": "ebd11dab-0673-442f-9f34-a51f4815abcb",
"errors": [{"errorCode":"ACS20001","errorMessage":"An error occurred while processing a WS-Federation sign-in response."},
{"errorCode":"ACS50008","errorMessage":"SAML token is invalid."}]
}
The request:
- wa : wsignin1.0
- wctx: pr=wsfederation&rm=http%3a%2f%2flocalhost%3a6643%2f&ry=http%3a%2f%2flocalhost%3a6643%2fsyndesi&cx=http%3a%2f%2flocalhost%3a6643%2fsyndesi
- wresult :
<trust:requestsecuritytokenresponsecollection xmlns:trust="http://docs.oasis-open.org/ws-sx/ws-trust/200512">
<trust:requestsecuritytokenresponse Context="pr=wsfederation&rm=http%3a%2f%2flocalhost%3a6643%2f&ry=http%3a%2f%2flocalhost%3a6643%2fsyndesi&cx=http%3a%2f%2flocalhost%3a6643%2fsyndesi">
<trust:lifetime>
<wsu:created xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">2012-02-15T08:38:09.601Z</wsu:created>
<wsu:expires xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">2012-02-15T09:48:09.601Z</wsu:expires>
</trust:lifetime>
<wsp:appliesto xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy">
<endpointreference xmlns="http://www.w3.org/2005/08/addressing">
https://ecosense.accesscontrol.windows.net/
</endpointreference>
</wsp:appliesto>
<trust:requestedsecuritytoken>
<saml:assertion AssertionID="_c84e5721-...." IssueInstant="2012-02-15T08:48:09.663Z" Issuer="https://login.xo.gr/" MajorVersion="1" MinorVersion="1" xmlns:saml="urn:oasis:names:tc:SAML:1.0:assertion">
<saml:conditions NotBefore="2012-02-15T08:38:09.601Z" NotOnOrAfter="2012-02-15T09:48:09.601Z">
<saml:audiencerestrictioncondition>
<saml:audience>https://ecosense.accesscontrol.windows.net/</saml:audience>
</saml:audiencerestrictioncondition>
</saml:conditions>
<saml:attributestatement>
<saml:subject>
<saml:subjectconfirmation>
<saml:confirmationmethod>urn:oasis:names:tc:SAML:1.0:cm:bearer</saml:confirmationmethod>
</saml:subjectconfirmation>
</saml:subject>
<saml:attribute AttributeName="name" AttributeNamespace="http://schemas.xmlsoap.org/ws/2005/05/identity/claims">
<saml:attributevalue>sso@indice.gr</saml:attributevalue>
</saml:attribute>
<saml:attribute AttributeName="authentication" AttributeNamespace="http://schemas.xmlsoap.org/ws/2005/05/identity/claims">
<saml:attributevalue>Forms</saml:attributevalue>
</saml:attribute>
<saml:attribute AttributeName="role" AttributeNamespace="http://schemas.microsoft.com/ws/2008/06/identity/claims">
<saml:attributevalue>Manager</saml:attributevalue>
</saml:attribute>
</saml:attributestatement>
<ds:signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:signedinfo>
<ds:canonicalizationmethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"></ds:canonicalizationmethod>
<ds:signaturemethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"></ds:signaturemethod>
<ds:reference URI="#_c84e5721-....">
<ds:transforms>
<ds:transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"></ds:transform>
<ds:transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"></ds:transform>
</ds:transforms>
<ds:digestmethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"></ds:digestmethod>
<ds:digestvalue>U970k1....</ds:digestvalue>
</ds:reference>
</ds:signedinfo>
<ds:signaturevalue>fUMa36Fmr....</ds:signaturevalue>
<keyinfo xmlns="http://www.w3.org/2000/09/xmldsig#">
<x509data>
<x509certificate>MIIFdTCCB....</x509certificate>
</x509data>
</keyinfo>
</ds:signature>
</saml:assertion>
</trust:requestedsecuritytoken>
<trust:requestedattachedreference>
<o:securitytokenreference k:TokenType="http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLV1.1" xmlns:k="http://docs.oasis-open.org/wss/oasis-wss-wssecurity-secext-1.1.xsd" xmlns:o="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd">
<o:keyidentifier ValueType="http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.0#SAMLAssertionID">_c84e5721-....</o:keyidentifier>
</o:securitytokenreference>
</trust:requestedattachedreference>
<trust:requestedunattachedreference>
<o:securitytokenreference k:TokenType="http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLV1.1" xmlns:k="http://docs.oasis-open.org/wss/oasis-wss-wssecurity-secext-1.1.xsd" xmlns:o="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd">
<o:keyidentifier ValueType="http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.0#SAMLAssertionID">_c84e5721-....</o:keyidentifier>
</o:securitytokenreference>
</trust:requestedunattachedreference>
<trust:tokentype>urn:oasis:names:tc:SAML:1.0:assertion</trust:tokentype>
<trust:requesttype>http://docs.oasis-open.org/ws-sx/ws-trust/200512/Issue</trust:requesttype>
<trust:keytype>http://docs.oasis-open.org/ws-sx/ws-trust/200512/Bearer</trust:keytype>
</trust:requestsecuritytokenresponse>
</trust:requestsecuritytokenresponsecollection>
Any thoughts?
Thanks,
C.
Constantinos Leftheris. http://www.indice.gr