-
Notifications
You must be signed in to change notification settings - Fork 2
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Reorganize the handling of "future" validation rulesets.
The saml2int ruleset is now run everywhere, but the things that we still have exceptions to are now commented out. Those failing tests are now included within the "future" ruleset, which is all that the "check.uk.future" target runs. The "future" rulesets have been broken down into multiple non-overlapping XSLT transforms so that we get to see *all* matches, and none are hidden. One implicit change is that the import transform will now also perform all the saml2int tests (present and future). The intention is that each independent failing part of the saml2int ruleset can now be promoted independently once we have cleaned our own metadata up.
- Loading branch information
Showing
6 changed files
with
243 additions
and
20 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,70 @@ | ||
| <?xml version="1.0" encoding="UTF-8"?> | ||
| <!-- | ||
| check_future_1.xsl | ||
| Checking ruleset containing rules that we don't currently implement, | ||
| but which we may implement in the future. | ||
| Author: Ian A. Young <ian@iay.org.uk> | ||
| --> | ||
| <xsl:stylesheet version="1.0" | ||
| xmlns:xsl="http://www.w3.org/1999/XSL/Transform" | ||
| xmlns:ds="http://www.w3.org/2000/09/xmldsig#" | ||
| xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" | ||
| xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" | ||
| xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" | ||
| xmlns:set="http://exslt.org/sets" | ||
| xmlns:wayf="http://sdss.ac.uk/2006/06/WAYF" | ||
| xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" | ||
| xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" | ||
|
|
||
| xmlns:mdxURL="xalan://uk.ac.sdss.xalan.md.URLchecker" | ||
|
|
||
| xmlns="urn:oasis:names:tc:SAML:2.0:metadata"> | ||
|
|
||
| <!-- | ||
| Common support functions. | ||
| --> | ||
| <xsl:import href="check_framework.xsl"/> | ||
|
|
||
|
|
||
| <!-- | ||
| *************************** | ||
| *** *** | ||
| *** S A M L 2 I N T *** | ||
| *** *** | ||
| *************************** | ||
| --> | ||
|
|
||
| <!-- | ||
| Section 6. | ||
| Check for SAML 2.0 SPs which exclude both transient and persistent SAML 2 name identifier formats. | ||
| --> | ||
| <xsl:template match="md:SPSSODescriptor | ||
| [contains(@protocolSupportEnumeration, 'urn:oasis:names:tc:SAML:2.0:protocol')] | ||
| [md:NameIDFormat] | ||
| [not(md:NameIDFormat[.='urn:oasis:names:tc:SAML:2.0:nameid-format:persistent'])] | ||
| [not(md:NameIDFormat[.='urn:oasis:names:tc:SAML:2.0:nameid-format:transient'])]"> | ||
| <xsl:call-template name="error"> | ||
| <xsl:with-param name="m">saml2int: SP excludes both SAML 2 name identifier formats</xsl:with-param> | ||
| </xsl:call-template> | ||
| </xsl:template> | ||
|
|
||
| <!-- | ||
| Section 6. | ||
| Check for SAML 2.0 IdPs which exclude the transient SAML 2 name identifier format. | ||
| --> | ||
| <xsl:template match="md:IDPSSODescriptor | ||
| [contains(@protocolSupportEnumeration, 'urn:oasis:names:tc:SAML:2.0:protocol')] | ||
| [md:NameIDFormat] | ||
| [not(md:NameIDFormat[.='urn:oasis:names:tc:SAML:2.0:nameid-format:transient'])]"> | ||
| <xsl:call-template name="error"> | ||
| <xsl:with-param name="m">IdP excludes SAML 2 transient name identifier format</xsl:with-param> | ||
| </xsl:call-template> | ||
| </xsl:template> | ||
|
|
||
| </xsl:stylesheet> |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,54 @@ | ||
| <?xml version="1.0" encoding="UTF-8"?> | ||
| <!-- | ||
| check_future_1.xsl | ||
| Checking ruleset containing rules that we don't currently implement, | ||
| but which we may implement in the future. | ||
| Author: Ian A. Young <ian@iay.org.uk> | ||
| --> | ||
| <xsl:stylesheet version="1.0" | ||
| xmlns:xsl="http://www.w3.org/1999/XSL/Transform" | ||
| xmlns:ds="http://www.w3.org/2000/09/xmldsig#" | ||
| xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" | ||
| xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" | ||
| xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" | ||
| xmlns:set="http://exslt.org/sets" | ||
| xmlns:wayf="http://sdss.ac.uk/2006/06/WAYF" | ||
| xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" | ||
| xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" | ||
|
|
||
| xmlns:mdxURL="xalan://uk.ac.sdss.xalan.md.URLchecker" | ||
|
|
||
| xmlns="urn:oasis:names:tc:SAML:2.0:metadata"> | ||
|
|
||
| <!-- | ||
| Common support functions. | ||
| --> | ||
| <xsl:import href="check_framework.xsl"/> | ||
|
|
||
|
|
||
| <!-- | ||
| *************************** | ||
| *** *** | ||
| *** S A M L 2 I N T *** | ||
| *** *** | ||
| *************************** | ||
| --> | ||
|
|
||
| <!-- | ||
| Section 9.1 | ||
| Responses MUST use the HTTP-POST binding, so metadata for that MUST be present. | ||
| --> | ||
| <xsl:template match="md:SPSSODescriptor | ||
| [contains(@protocolSupportEnumeration, 'urn:oasis:names:tc:SAML:2.0:protocol')] | ||
| [not(md:AssertionConsumerService[@Binding = 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST'])]"> | ||
| <xsl:call-template name="error"> | ||
| <xsl:with-param name="m">no HTTP-POST support on SAML 2.0 SP</xsl:with-param> | ||
| </xsl:call-template> | ||
| </xsl:template> | ||
|
|
||
| </xsl:stylesheet> |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters