449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings/*
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS HEADER.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Copyright (c) 2007 Sun Microsystems Inc. All Rights Reserved
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * The contents of this file are subject to the terms
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * of the Common Development and Distribution License
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * (the License). You may not use this file except in
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * compliance with the License.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * You can obtain a copy of the License at
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * https://opensso.dev.java.net/public/CDDLv1.0.html or
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * opensso/legal/CDDLv1.0.txt
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * See the License for the specific language governing
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * permission and limitations under the License.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * When distributing Covered Code, include this CDDL
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Header Notice in each file and include the License file
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * at opensso/legal/CDDLv1.0.txt.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * If applicable, add the following below the CDDL Header,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * with the fields enclosed by brackets [] replaced by
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * your own identifying information:
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * "Portions Copyrighted [year] [name of copyright owner]"
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * $Id: DiscoveryBootstrap.java,v 1.4 2008/12/05 00:18:31 exu Exp $
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings * Portions Copyrighted 2015 ForgeRock AS.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterpackage com.sun.identity.saml2.profile;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport java.util.ArrayList;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport java.util.Iterator;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport java.util.List;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport java.util.Map;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.federation.common.IFSConstants;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.federation.message.common.AuthnContext;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.federation.message.common.EncryptedNameIdentifier;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.federation.message.common.IDPProvidedNameIdentifier;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.liberty.ws.disco.common.DiscoConstants;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.liberty.ws.disco.common.DiscoServiceManager;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.liberty.ws.disco.common.DiscoUtils;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.liberty.ws.disco.jaxb.ObjectFactory;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.liberty.ws.disco.jaxb.ResourceIDType;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.liberty.ws.disco.jaxb.ResourceOfferingType;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.liberty.ws.disco.jaxb.ServiceInstanceType;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.liberty.ws.disco.plugins.jaxb.DiscoEntryElement;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.liberty.ws.disco.ResourceOffering;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.liberty.ws.interfaces.ResourceIDMapper;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.liberty.ws.security.SessionContext;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.liberty.ws.security.SessionSubject;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.plugin.session.SessionManager;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.plugin.session.SessionException;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml.assertion.Assertion;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml.assertion.NameIdentifier;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml.common.SAMLConstants;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml.common.SAMLException;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.assertion.Advice;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.assertion.AssertionFactory;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.assertion.Attribute;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.assertion.AttributeStatement;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.assertion.NameID;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.assertion.Subject;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.assertion.SubjectConfirmation;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.assertion.SubjectConfirmationData;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.common.SAML2Constants;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.common.SAML2Exception;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.common.SAML2Utils;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.key.EncInfo;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.key.KeyUtil;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.jaxb.metadata.IDPSSODescriptorElement;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.shared.Constants;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.shared.xml.XMLUtils;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster/**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * The class <code>DiscoBootstrap</code> helps in generating the discovery
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * boot strap statement i.e. Discovery Resource Offering as part of the SAML2
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * assertion that is generated during the Single Sign-On. This class checks
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * if there are any credentials that need to be generated for accesing
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * discovery service and do the needful.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterpublic class DiscoveryBootstrap {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster private AttributeStatement bootstrapStatement = null;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster private List assertions = null;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster private Object session = null;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Constructor.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param session session of the user.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param sub SAML2 Subject.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param authnContextClassRef Authentication context class ref
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * that the user is signed-on.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param wscID wsc entity ID.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param realm the realm name.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @exception SAML2Exception if there is any failure.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public DiscoveryBootstrap(Object session, Subject sub,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster String authnContextClassRef, String wscID, String realm)
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster this.session = session;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster try {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster List attributeList = new ArrayList();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster List resourceOfferings = new ArrayList();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster String offering = getResourceOffering(authnContextClassRef,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster sub, wscID, realm);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster resourceOfferings.add(offering);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster Attribute attribute =
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster AssertionFactory.getInstance().createAttribute();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster attribute.setName(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2Constants.DISCOVERY_BOOTSTRAP_ATTRIBUTE_NAME);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster attribute.setNameFormat(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2Constants.DISCOVERY_BOOTSTRAP_ATTRIBUTE_NAME_FORMAT);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster attribute.setAttributeValueString(resourceOfferings);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster attributeList.add(attribute);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster bootstrapStatement =
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster AssertionFactory.getInstance().createAttributeStatement();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster bootstrapStatement.setAttribute(attributeList);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster } catch (Exception ex) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2Utils.debug.error("DiscoveryBootstrap.DiscoveryBootstrap: " +
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "while creating discovery bootstrap statement", ex);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(ex);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Gets the discovery bootstrap resource offering for the user.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return Discovery Resource Offering String
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @exception SAML2Exception if there's any failure.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster private String getResourceOffering(String authnContextClassRef,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster Subject subject, String wscID, String realm) throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (SAML2Utils.debug.messageEnabled()) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2Utils.debug.message(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "DiscoveryBootstrap.getResourceOffering:Init");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster DiscoEntryElement discoEntry =
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster DiscoServiceManager.getBootstrappingDiscoEntry();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (discoEntry == null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2Utils.bundle.getString("missingUnivID"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster String[] values = null;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster try {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster values = SessionManager.getProvider().getProperty(session,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster Constants.UNIVERSAL_IDENTIFIER);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster } catch (SessionException se) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(se);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if ((values == null) || (values.length == 0)) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2Utils.bundle.getString("missingDiscoOffering"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster String univID = values[0];
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster try {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster ResourceOfferingType offering = discoEntry.getResourceOffering();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster ServiceInstanceType serviceInstance = offering.getServiceInstance();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster String providerID = serviceInstance.getProviderID();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (!DiscoServiceManager.useImpliedResource()) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster ResourceIDMapper idMapper =
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster DiscoServiceManager.getResourceIDMapper(providerID);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (idMapper == null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster idMapper = DiscoServiceManager.getDefaultResourceIDMapper();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster ObjectFactory fac = new ObjectFactory();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster ResourceIDType resourceID = fac.createResourceIDType();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster String resourceIDValue = idMapper.getResourceID(providerID,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster univID);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if(SAML2Utils.debug.messageEnabled()) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2Utils.debug.message(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "DiscoveryBootstrap.getResourceOffering: " +
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "ResourceID Value:" + resourceIDValue);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster resourceID.setValue(resourceIDValue);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster offering.setResourceID(resourceID);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster } else {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster ObjectFactory fac =
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster new com.sun.identity.liberty.ws.disco.jaxb.ObjectFactory();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster ResourceIDType resourceID = fac.createResourceIDType();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster resourceID.setValue(DiscoConstants.IMPLIED_RESOURCE);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster offering.setResourceID(resourceID);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster List discoEntryList = new ArrayList();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster discoEntryList.add(discoEntry);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SessionSubject sessionSubject = null;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (DiscoServiceManager.encryptNIinSessionContext()) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster IDPSSODescriptorElement idpSSODesc = SAML2Utils
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster .getSAML2MetaManager().getIDPSSODescriptor(realm,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster providerID);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster EncInfo encInfo = KeyUtil.getEncInfo(idpSSODesc, wscID,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2Constants.IDP_ROLE);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster NameIdentifier ni =
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster EncryptedNameIdentifier.getEncryptedNameIdentifier(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster convertSPNameID(subject.getNameID()), providerID,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster encInfo.getWrappingKey(),
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster encInfo.getDataEncAlgorithm(),
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster encInfo.getDataEncStrength());
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster sessionSubject = new SessionSubject(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster ni,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster convertSC(subject.getSubjectConfirmation()),
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster convertIDPNameID(subject.getNameID()));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster } else {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster sessionSubject = new SessionSubject(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster convertSPNameID(subject.getNameID()),
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster convertSC(subject.getSubjectConfirmation()),
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster convertIDPNameID(subject.getNameID()));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster AuthnContext authnContext = new AuthnContext(authnContextClassRef,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster null);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster authnContext.setMinorVersion(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster IFSConstants.FF_12_PROTOCOL_MINOR_VERSION);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SessionContext invocatorSession = new SessionContext(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster sessionSubject, authnContext, providerID);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster Map map = DiscoUtils.checkPolicyAndHandleDirectives(univID, null,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster discoEntryList, null, invocatorSession, wscID, session);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster List offerings = (List) map.get(DiscoUtils.OFFERINGS);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (offerings.isEmpty()) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (SAML2Utils.debug.messageEnabled()) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2Utils.debug.message(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "DiscoveryBootstrap.getResourceOffering:" +
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "no ResourceOffering");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2Utils.bundle.getString("missingDiscoOffering"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster ResourceOffering resourceOffering =
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster (ResourceOffering) offerings.get(0);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster assertions = (List) map.get(DiscoUtils.CREDENTIALS);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (SAML2Utils.debug.messageEnabled()) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2Utils.debug.message(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "DiscoveryBootstrap.getResourceOffering: "+
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "Resource Offering:" + resourceOffering);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return resourceOffering.toString();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster } catch (Exception ex) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2Utils.debug.error("DiscoveryBootstrap.getResourceOffering:" +
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "Exception while creating resource offering.", ex);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(ex);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Gets the bootstrap attribute statement
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return AttributeStatement ResourceOffering AttributeStatement.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public AttributeStatement getBootstrapStatement() {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return bootstrapStatement;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Gets the credential for discovery boot strap resource offering
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return Advice Credential advice
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public Advice getCredentials() throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster Advice advice = null;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if ((assertions != null) && (assertions.size() != 0)) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster List assertionStrs = new ArrayList();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster for (Iterator iter = assertions.iterator(); iter.hasNext();) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster Assertion assertion = (Assertion)iter.next();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster assertionStrs.add(assertion.toString(true, true));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster advice = AssertionFactory.getInstance().createAdvice();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster advice.setAdditionalInfo(assertionStrs);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return advice;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster private static NameIdentifier convertSPNameID(NameID nameId)
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throws SAMLException {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return new NameIdentifier(nameId.getValue(),
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster nameId.getSPNameQualifier(), nameId.getFormat());
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster private static IDPProvidedNameIdentifier convertIDPNameID(NameID nameId)
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throws SAMLException {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return new IDPProvidedNameIdentifier(nameId.getValue(),
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster nameId.getNameQualifier(), nameId.getFormat());
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster private static com.sun.identity.saml.assertion.SubjectConfirmation
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster convertSC(List subjectConfirmations) throws SAMLException {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if ((subjectConfirmations == null) || subjectConfirmations.isEmpty()) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return null;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SubjectConfirmation subjectConfirmation =
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster (SubjectConfirmation)subjectConfirmations.get(0);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster com.sun.identity.saml.assertion.SubjectConfirmation samlSC =
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster new com.sun.identity.saml.assertion.SubjectConfirmation(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster subjectConfirmation.getMethod());
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SubjectConfirmationData scData =
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster subjectConfirmation.getSubjectConfirmationData();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (scData != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster List content = scData.getContent();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if ((content != null) && (!content.isEmpty())) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster samlSC.setSubjectConfirmationData((String)content.get(0));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return samlSC;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster}