Difference between revisions of "I3:XR1-Oracle RP-x-WSO2 IdP"

From OSIS Open Source Identity Systems
Jump to: navigation, search
(XR1-Oracle RP-x-WSO2 IdP)
 
Line 6: Line 6:
 
   |testdate        = 31 March 2008
 
   |testdate        = 31 March 2008
 
   |outcome        = Issues
 
   |outcome        = Issues
   |testedby        = [[User:66.249.72.180|66.249.72.180]] 01:10, 15 February 2008 (PST)
+
   |testedby        = [[User:[[User:Ramana Turlapati|Ramana Turlapati]] 13:44, 1 April 2008 (PDT)]] 01:10, 15 February 2008 (PST)
 
   |testedsolution1 = Oracle RP
 
   |testedsolution1 = Oracle RP
 
   |testedsolution2 = WSO2 IdP
 
   |testedsolution2 = WSO2 IdP
Line 26: Line 26:
  
 
Card selector could not retrieve token from IdP. http://identity.wso2.org/ is unreachable
 
Card selector could not retrieve token from IdP. http://identity.wso2.org/ is unreachable
 +
===========================================================================================
 +
Test performed on April 1, 2008 1:32pm PDT. Oracle RP still fails to work with WSO2 Idp. The reason is that the encrypted token recieved from WSO2 does not define the <DigestMethod/> for key wrap algorithm RSAOAEP. <EncryptionMethod/> element of <EncryptedKey/> is missing the <DigestMethod/> subelement. Oracle XML Encryption impl requires <DigestMethod/> to be specified.
 +
couple of options:
 +
WSO2 by default provides auditable cards - this is forcing encryption to happen at WSO2 provider side. If instead they provide for non-auditable cards, then the encryption would happen at card agent which seems to be doing things as per XMLEncryption spec.
 +
 +
Oracle fixes to be tolerant of missing <DigestMethod/>
 
}}
 
}}
 
<includeonly>[[Category:I3 XResult]]</includeonly>
 
<includeonly>[[Category:I3 XResult]]</includeonly>

Latest revision as of 13:44, 1 April 2008

{{#vardefine:DtArticleSortKey|}}

XR1-Oracle RP-x-WSO2 IdP

{{#vardefine:page|{{#if:{{#var:page}}|{{#var:page}}|XR1-Oracle RP-x-WSO2 IdP}}}}{{#vardefine:nr|{{#if:{{#var:nr}}|{{#expr:{{#var:nr}}+1}}|1}}}}{{#vardefine:url|{{#replace:{{#var:page}}| |_}}}}{{#if:XR1-Oracle RP-x-WSO2 IdP|{{#if:{{#var:DtArticleSortKey}}||}}}}{{#ifeq:{{#var:header}}|no||

{{#ifeq:no|no||
{{#if:{{#var:refs}}|[[{{#var:page}}|no_ref's]]|[[Special:Call/DT Article show Refs,page={{#var:page}},refs=yes|ref's]]}}}} {{#if:{{#var:DtArticleSortKey}}|({{#var:DtArticleSortKey}})}}    list help  [[Special:Call/DT Article copy,cat=XResult,from={{#var:page}},namespace=I3|copy]]  [[Special:Call/DT Articles list XML,type=XResult,title={{#var:page}},namespace=I3|as XML]]  edit
}}
{{#if:|Cross Solution Result |Cross Solution Result }}   XR1-Oracle RP-x-WSO2 IdP
Identifier   bgcolor={{{color}}}}}|XR1
Date Tested   bgcolor={{{color}}}}}|31 March 2008
Outcome (Must be one of:)
* Works
* Issues
* Failed
* N/A
* Not Tested
 
bgcolor={{{color}}}}}|Issues
Tested By   bgcolor={{{color}}}}}|[[User:Ramana Turlapati 13:44, 1 April 2008 (PDT)]] 01:10, 15 February 2008 (PST)
Solutions Involved   bgcolor={{{color}}}}}|{{#if: Oracle RP | I3:Oracle RP |   }}
  bgcolor={{{color}}}}}|{{#if: WSO2 IdP | I3:WSO2 IdP |   }}
Other Solutions Involved   bgcolor={{{color}}}}}|.
Operating System   bgcolor={{{color}}}}}|Windows XP
Browser   bgcolor={{{color}}}}}|IE 7
Notes   bgcolor={{{color}}}}}|Update by Prabath : 31/03/2008

Correct end point is https://is.test.wso2.org

Identity Selector retreives the card correctly but resulted the following error once logged in.

Login Error!

Card Login Failed

================================================================================

Card selector could not retrieve token from IdP. http://identity.wso2.org/ is unreachable

===============================================================================

Test performed on April 1, 2008 1:32pm PDT. Oracle RP still fails to work with WSO2 Idp. The reason is that the encrypted token recieved from WSO2 does not define the <DigestMethod/> for key wrap algorithm RSAOAEP. <EncryptionMethod/> element of <EncryptedKey/> is missing the <DigestMethod/> subelement. Oracle XML Encryption impl requires <DigestMethod/> to be specified. couple of options: WSO2 by default provides auditable cards - this is forcing encryption to happen at WSO2 provider side. If instead they provide for non-auditable cards, then the encryption would happen at card agent which seems to be doing things as per XMLEncryption spec.

Oracle fixes to be tolerant of missing <DigestMethod/>

Click here for help populating this chart.

Back To

{{#dpl: namespace = I3 | linksto = I3:XR1-Oracle RP-x-WSO2 IdP }}