idpSSOInit.jsp revision 0e107349d3f7763a9c67fb2f32c86c11364c72cf
199767f8919635c4928607450d9e0abb932109ceToomas Soome<%--
199767f8919635c4928607450d9e0abb932109ceToomas Soome DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS HEADER.
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome Copyright (c) 2006 Sun Microsystems Inc. All Rights Reserved
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome The contents of this file are subject to the terms
199767f8919635c4928607450d9e0abb932109ceToomas Soome of the Common Development and Distribution License
199767f8919635c4928607450d9e0abb932109ceToomas Soome (the License). You may not use this file except in
199767f8919635c4928607450d9e0abb932109ceToomas Soome compliance with the License.
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome You can obtain a copy of the License at
199767f8919635c4928607450d9e0abb932109ceToomas Soome https://opensso.dev.java.net/public/CDDLv1.0.html or
199767f8919635c4928607450d9e0abb932109ceToomas Soome opensso/legal/CDDLv1.0.txt
199767f8919635c4928607450d9e0abb932109ceToomas Soome See the License for the specific language governing
199767f8919635c4928607450d9e0abb932109ceToomas Soome permission and limitations under the License.
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome When distributing Covered Code, include this CDDL
199767f8919635c4928607450d9e0abb932109ceToomas Soome Header Notice in each file and include the License file
199767f8919635c4928607450d9e0abb932109ceToomas Soome at opensso/legal/CDDLv1.0.txt.
199767f8919635c4928607450d9e0abb932109ceToomas Soome If applicable, add the following below the CDDL Header,
199767f8919635c4928607450d9e0abb932109ceToomas Soome with the fields enclosed by brackets [] replaced by
199767f8919635c4928607450d9e0abb932109ceToomas Soome your own identifying information:
199767f8919635c4928607450d9e0abb932109ceToomas Soome "Portions Copyrighted [year] [name of copyright owner]"
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome $Id: idpSSOInit.jsp,v 1.9 2009/06/24 23:05:30 mrudulahg Exp $
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome--%>
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome<%--
199767f8919635c4928607450d9e0abb932109ceToomas Soome Portions Copyrighted 2014 ForgeRock AS
199767f8919635c4928607450d9e0abb932109ceToomas Soome--%>
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome<!-- %@ page import="com.iplanet.am.util.Debug" % -->
199767f8919635c4928607450d9e0abb932109ceToomas Soome<%@ page import="com.sun.identity.shared.debug.Debug" %>
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome<%@ page import="com.sun.identity.saml2.common.SAML2Constants" %>
199767f8919635c4928607450d9e0abb932109ceToomas Soome<%@ page import="com.sun.identity.saml2.common.SAML2Exception" %>
199767f8919635c4928607450d9e0abb932109ceToomas Soome<%@ page import="com.sun.identity.saml2.common.SAML2Utils" %>
199767f8919635c4928607450d9e0abb932109ceToomas Soome<%@ page import="com.sun.identity.saml.common.SAMLUtils" %>
199767f8919635c4928607450d9e0abb932109ceToomas Soome<%@ page import="com.sun.identity.saml2.profile.IDPSSOUtil" %>
199767f8919635c4928607450d9e0abb932109ceToomas Soome<%@ page import="java.io.PrintWriter" %>
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome<%--
199767f8919635c4928607450d9e0abb932109ceToomas Soome idpssoinit.jsp initiates Unsolicited SSO at the Identity Provider.
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome Following are the list of supported query parameters :
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome Required parameters to this jsp are :
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome Query Parameter Name Description
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome 1. metaAlias MetaAlias for Identity Provider. The format of
199767f8919635c4928607450d9e0abb932109ceToomas Soome this parameter is /realm_name/IDP name.
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome 2. spEntityID Identifier for Service Provider.
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome Optional Query Parameters :
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome Query Parameter Name Description
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome 3. RelayState Target URL on successful complete of SSO/Federation
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome 4. RelayStateAlias Specify the parameter(s) to use as the RelayState.
199767f8919635c4928607450d9e0abb932109ceToomas Soome e.g. if the request URL has :
199767f8919635c4928607450d9e0abb932109ceToomas Soome ?TARGET=http://server:port/uri&RelayStateAlias=TARGET
199767f8919635c4928607450d9e0abb932109ceToomas Soome then the TARGET query parameter will be interpreted as
199767f8919635c4928607450d9e0abb932109ceToomas Soome RelayState and on successful completion of
199767f8919635c4928607450d9e0abb932109ceToomas Soome SSO/Federation user will be redirected to the TARGET URL.
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome 5. NameIDFormat NameID format Identifier Value.
199767f8919635c4928607450d9e0abb932109ceToomas Soome For example,
199767f8919635c4928607450d9e0abb932109ceToomas Soome urn:oasis:names:tc:SAML:2.0:nameid-format:persistent
199767f8919635c4928607450d9e0abb932109ceToomas Soome urn:oasis:names:tc:SAML:2.0:nameid-format:transient
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome 6. binding URI value that identifies a SAML protocol binding to
199767f8919635c4928607450d9e0abb932109ceToomas Soome used when returning the Response message.
199767f8919635c4928607450d9e0abb932109ceToomas Soome The supported values are :
199767f8919635c4928607450d9e0abb932109ceToomas Soome HTTP-Artifact
199767f8919635c4928607450d9e0abb932109ceToomas Soome HTTP-POST
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome NOTE: There are other SAML defined values for these
199767f8919635c4928607450d9e0abb932109ceToomas Soome which are not supported by FM/AM.
199767f8919635c4928607450d9e0abb932109ceToomas Soome 7. affiliationID affiliation entity ID
199767f8919635c4928607450d9e0abb932109ceToomas Soome--%>
199767f8919635c4928607450d9e0abb932109ceToomas Soome<%
199767f8919635c4928607450d9e0abb932109ceToomas Soome // Retreive the Request Query Parameters
199767f8919635c4928607450d9e0abb932109ceToomas Soome // metaAlias and spEntiyID are the required query parameters
199767f8919635c4928607450d9e0abb932109ceToomas Soome // metaAlias - Identity Provider Entity Id
199767f8919635c4928607450d9e0abb932109ceToomas Soome // spEntityID - Service Provider Identifier
199767f8919635c4928607450d9e0abb932109ceToomas Soome try {
199767f8919635c4928607450d9e0abb932109ceToomas Soome String cachedResID = request.getParameter(SAML2Constants.RES_INFO_ID);
199767f8919635c4928607450d9e0abb932109ceToomas Soome // if this id is set, then this is a redirect from the COT
199767f8919635c4928607450d9e0abb932109ceToomas Soome // cookie writer. There is already an assertion response
199767f8919635c4928607450d9e0abb932109ceToomas Soome // cached in this provider. Send it back directly.
199767f8919635c4928607450d9e0abb932109ceToomas Soome if ((cachedResID != null) && (cachedResID.length() != 0)) {
199767f8919635c4928607450d9e0abb932109ceToomas Soome IDPSSOUtil.sendResponse(request, response, cachedResID);
199767f8919635c4928607450d9e0abb932109ceToomas Soome return;
199767f8919635c4928607450d9e0abb932109ceToomas Soome }
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome String metaAlias = request.getParameter("metaAlias");
199767f8919635c4928607450d9e0abb932109ceToomas Soome if ((metaAlias == null) || (metaAlias.length() == 0)) {
199767f8919635c4928607450d9e0abb932109ceToomas Soome SAMLUtils.sendError(request, response, response.SC_BAD_REQUEST,
199767f8919635c4928607450d9e0abb932109ceToomas Soome "nullIDPEntityID",
199767f8919635c4928607450d9e0abb932109ceToomas Soome SAML2Utils.bundle.getString("nullIDPEntityID"));
199767f8919635c4928607450d9e0abb932109ceToomas Soome return;
199767f8919635c4928607450d9e0abb932109ceToomas Soome }
199767f8919635c4928607450d9e0abb932109ceToomas Soome String spEntityID = request.getParameter("spEntityID");
199767f8919635c4928607450d9e0abb932109ceToomas Soome
199767f8919635c4928607450d9e0abb932109ceToomas Soome if ((spEntityID == null) || (spEntityID.length() == 0)) {
199767f8919635c4928607450d9e0abb932109ceToomas Soome SAMLUtils.sendError(request, response, response.SC_BAD_REQUEST,
199767f8919635c4928607450d9e0abb932109ceToomas Soome "nullSPEntityID",
199767f8919635c4928607450d9e0abb932109ceToomas Soome SAML2Utils.bundle.getString("nullSPEntityID"));
199767f8919635c4928607450d9e0abb932109ceToomas Soome return;
199767f8919635c4928607450d9e0abb932109ceToomas Soome }
199767f8919635c4928607450d9e0abb932109ceToomas Soome // get the nameIDPolicy
199767f8919635c4928607450d9e0abb932109ceToomas Soome String nameIDFormat =
199767f8919635c4928607450d9e0abb932109ceToomas Soome request.getParameter(SAML2Constants.NAMEID_POLICY_FORMAT);
199767f8919635c4928607450d9e0abb932109ceToomas Soome String relayState = SAML2Utils.getRelayState(request);
199767f8919635c4928607450d9e0abb932109ceToomas Soome IDPSSOUtil.doSSOFederate(request,response,new PrintWriter(out, true),null,spEntityID,
199767f8919635c4928607450d9e0abb932109ceToomas Soome metaAlias, nameIDFormat,relayState);
199767f8919635c4928607450d9e0abb932109ceToomas Soome } catch (SAML2Exception sse) {
199767f8919635c4928607450d9e0abb932109ceToomas Soome SAML2Utils.debug.error("Error processing request " , sse);
199767f8919635c4928607450d9e0abb932109ceToomas Soome SAMLUtils.sendError(request, response, response.SC_BAD_REQUEST,
199767f8919635c4928607450d9e0abb932109ceToomas Soome "requestProcessingError",
199767f8919635c4928607450d9e0abb932109ceToomas Soome SAML2Utils.bundle.getString("requestProcessingError") + " " +
199767f8919635c4928607450d9e0abb932109ceToomas Soome sse.getMessage());
199767f8919635c4928607450d9e0abb932109ceToomas Soome return;
199767f8919635c4928607450d9e0abb932109ceToomas Soome } catch (Exception e) {
199767f8919635c4928607450d9e0abb932109ceToomas Soome SAML2Utils.debug.error("Error processing request ",e);
199767f8919635c4928607450d9e0abb932109ceToomas Soome SAMLUtils.sendError(request, response, response.SC_BAD_REQUEST,
199767f8919635c4928607450d9e0abb932109ceToomas Soome "requestProcessingError",
199767f8919635c4928607450d9e0abb932109ceToomas Soome SAML2Utils.bundle.getString("requestProcessingError") + " " +
199767f8919635c4928607450d9e0abb932109ceToomas Soome e.getMessage());
199767f8919635c4928607450d9e0abb932109ceToomas Soome return;
199767f8919635c4928607450d9e0abb932109ceToomas Soome }
199767f8919635c4928607450d9e0abb932109ceToomas Soome%>
199767f8919635c4928607450d9e0abb932109ceToomas Soome