Xavier Guimard
c80795805a
#28 in progress
2010-09-18 06:23:34 +00:00
Xavier Guimard
305113c53f
#28 in progress :
...
- Extension to Net::OpenID::Server to manage extensions (and sign them)
2010-09-17 15:32:43 +00:00
Xavier Guimard
09b6f037df
_SOAP.pm and Menu.pm provide both _compileRules => moved to _LibAccess.pm
2010-09-17 10:23:49 +00:00
Clément Oudot
d7fb73b2e2
Rewrite Menu module, to integrate it in Portal ( #29 )
2010-09-16 15:10:00 +00:00
Clément Oudot
b658c3df43
SAFEWRAP test was not good
2010-09-16 08:44:56 +00:00
Clément Oudot
dda83a3e67
Store authChoice in session, and load it for existing sessions
2010-09-13 15:14:19 +00:00
Clément Oudot
07c1c59d0e
Load IDPs in SAML userDBInit to manage SLO in SAML proxy mode
2010-09-13 15:10:39 +00:00
Clément Oudot
657c39d563
Use subProcess to change password in Menu
2010-09-13 15:08:29 +00:00
Clément Oudot
3304885bf0
Register dn in session even if no UserDBLDAP selected
2010-09-13 14:09:07 +00:00
Clément Oudot
c004e6363d
Load correct authentication module on issuer logout process
2010-09-10 20:27:14 +00:00
Clément Oudot
0fb130e29e
Correct UserDBSAML init test
2010-09-10 20:17:08 +00:00
Clément Oudot
17b3c15466
Code authentication choice like multiple authentication ( #19 )
2010-09-10 19:52:44 +00:00
Clément Oudot
61a73e59dd
Work on authentication choice ( #19 )
2010-09-08 20:16:32 +00:00
Clément Oudot
1f4a6e6450
#19 :
...
* Dedicated AuthChoice.pm
* Authentication choice parameters in Manager
2010-09-06 15:05:54 +00:00
Clément Oudot
d2549c2fbe
Always display authentication choices if any ( #19 )
2010-09-06 09:35:05 +00:00
Xavier Guimard
c8a2b8c5e0
"_safe" instead of "safe" in Menu
2010-09-06 09:23:23 +00:00
Xavier Guimard
29640f3829
test wrapper for Safe
2010-09-04 11:49:03 +00:00
Clément Oudot
09b06fecbf
Add SSL and Apache in authentication choices ( #19 )
2010-09-03 16:02:10 +00:00
Xavier Guimard
d00f68a54b
Try to close LEMONLDAP-117
2010-09-03 15:58:57 +00:00
Clément Oudot
82b4ea080e
Load correct authentication module for authLogout (#LEMONDLAP-19)
2010-09-03 15:23:08 +00:00
Clément Oudot
615f0ba259
Transport authChoice in OpenID workflow
2010-09-03 14:58:25 +00:00
Clément Oudot
a8cc940774
Manage authChoice in CAS proxy callback
2010-09-03 14:53:31 +00:00
Clément Oudot
9e38c5ea2a
Transport authChoice in CAS authentication
2010-09-03 14:24:19 +00:00
Clément Oudot
41151228ff
Typo in checkXSSAttack call
2010-09-03 14:23:54 +00:00
Clément Oudot
ec8eb57b1f
* Common XSS attack check method
...
* Check XSS attack on authChoice parameter
2010-09-03 14:15:44 +00:00
Xavier Guimard
eacdc8e2dd
Typo
2010-09-03 13:37:49 +00:00
Xavier Guimard
47cb5c1a59
OpenID consumer now supports "OpenID Simple Registration Extension"
2010-09-03 13:34:35 +00:00
Clément Oudot
c10f1a96db
Authentication choice in progress ( #19 )
2010-09-03 13:21:03 +00:00
Clément Oudot
0f4212abc2
URL param to choose authentication module (#LEMONLDAP19)
2010-09-02 15:32:40 +00:00
Xavier Guimard
0e1f5f4217
According to OpenID-2.0 specs, HTML field should be called "openid_identifier"
2010-09-02 10:38:28 +00:00
Clément Oudot
9992c56f43
Configure mapping between SAML authentication contexts and authentication levels ( #152 )
2010-09-02 09:09:10 +00:00
Clément Oudot
8d6899c2b2
Configuration keys for authentication levels ( #152 )
2010-09-01 16:06:01 +00:00
Xavier Guimard
06beaa6ff4
« make tidy »
2010-09-01 12:56:15 +00:00
Xavier Guimard
dd597a7cce
OpenID federation message
2010-09-01 12:52:56 +00:00
Clément Oudot
a5ac6ee02b
Recreate an ARRAY ref for ldapGroupAttributeNameSearch ( #1 )
2010-09-01 10:59:11 +00:00
Clément Oudot
0f973b7b87
Set external authenticationLevel to 1
2010-09-01 09:53:55 +00:00
Xavier Guimard
7770f58ab2
Error using Lemonldap::NG::Common::Crypt
2010-09-01 09:16:02 +00:00
Clément Oudot
e5bbac08de
Add authFinish, authLogout and authForce in authentication modules ( #149 )
2010-09-01 08:59:39 +00:00
Xavier Guimard
f6f09f635c
IssuerOpenID in progress
2010-08-31 15:36:32 +00:00
Clément Oudot
038f57d7b5
SAML Issuer: redirect on logout page after logout process initiated by IDP
2010-08-31 15:21:17 +00:00
Clément Oudot
0d5faacc0a
Manage // in path when checking IssuerDB path
2010-08-31 15:14:44 +00:00
Clément Oudot
88272cce87
Use _saml_id key in SAML sessions to rattach them to main SSO session_id ( #148 )
2010-08-31 14:36:45 +00:00
Clément Oudot
35935c5b7f
Little bug in controlExistingSession
2010-08-31 12:23:11 +00:00
Clément Oudot
1e1f9bf5ea
Modify binmode to bytes for SOAP responses ( closes #144 )
2010-08-31 10:34:28 +00:00
Clément Oudot
a73968cd84
AuthCAS: use logoutServices to register CAS logout URL
2010-08-30 16:01:25 +00:00
Clément Oudot
92352246ee
Support from logout services: they are deconnected with a GET request after portal logout ( #121 )
2010-08-30 15:46:26 +00:00
Clément Oudot
611d252ebc
AuthCAS: renew and gateway flags can now been configured
2010-08-30 13:41:45 +00:00
Clément Oudot
9a4df749fe
CAS: Manage renew flag in VALIDATE and SERVICE VALIDATE URL ( #101 )
2010-08-30 09:24:04 +00:00
Clément Oudot
d3aefd81b8
AuthCAS: declare authForce method
2010-08-30 09:01:15 +00:00
Clément Oudot
60296f0143
CAS: Manage renew flag in LOGIN URL ( #101 )
2010-08-30 08:56:16 +00:00
Clément Oudot
8e7c112181
AuthCAS: declare authLogout and authFinish methods
2010-08-30 08:38:53 +00:00
Clément Oudot
e3010de6e5
CAS Issuer ( #101 ):
...
* Manage gateway parameter (refused unauthenticated user)
* Display CAS logout URL message
* Do not check base64 encoded URL for CAS (mandatory for logout URL management)
2010-08-27 16:07:19 +00:00
Xavier Guimard
7eb813fbca
Little TODO
2010-08-27 15:35:53 +00:00
Xavier Guimard
cd00bf3b62
OpenID server in progress
2010-08-27 15:34:03 +00:00
Clément Oudot
6045909d1f
AuthCAS: collect PT for each registered CAS proxied service ( #146 )
2010-08-27 14:42:07 +00:00
Clément Oudot
832f7050eb
Add activation parameter for each IssuerDB module ( #147 )
2010-08-27 13:01:54 +00:00
Clément Oudot
ac47c65adb
AuthCAS: remove unused parameters and add debug information ( #146 )
2010-08-27 08:50:09 +00:00
Clément Oudot
f4514c41e7
Manage all proxy workflow for CAS ( #101 )
2010-08-26 16:16:13 +00:00
Clément Oudot
b4f5adde99
Manage proxy granting ticket for CAS service validate URL ( #101 )
2010-08-26 14:43:32 +00:00
Clément Oudot
b721763e23
Manage CAS service validate URL ( #101 )
2010-08-26 12:24:38 +00:00
Clément Oudot
cf282a3c25
Add sample CAS client script ( #101 )
2010-08-26 10:25:58 +00:00
Clément Oudot
a19067e5a2
Delete CAS secondary sessions on logout ( #101 )
2010-08-26 08:42:28 +00:00
Clément Oudot
04ede0a918
CAS:
...
* Check the ticket is a service ticket
* Add _utime in CAS service sessions
* Add some debug messages
2010-08-25 15:57:21 +00:00
Clément Oudot
2b1e09d09c
Manage CAS logout and validate URL ( #101 )
2010-08-25 15:33:33 +00:00
Clément Oudot
a6acf86f4e
Generate CAS Service Ticket ( #101 )
2010-08-25 14:23:45 +00:00
Clément Oudot
c6c8024326
Manage CAS URLs ( #101 )
2010-08-23 16:41:38 +00:00
Clément Oudot
5877fa95d6
CAS IssuerDB skeleton ( #101 )
2010-08-23 15:47:53 +00:00
Clément Oudot
dca8b923ac
* Add setUserDBValue method for LDAP and DBI userDB
...
* Add samlUserDBIdentityKey
* IssuerDBSAML now try to store Lasso identity in UserDB
* References #123
2010-08-23 14:52:53 +00:00
Clément Oudot
240c2b56eb
SAML:
...
* Use request path to choose IssuerDB module to load
* Store all used IssuerDB module in user session
* Launch issuerLogout method for all used IssuerDB module
* References #102
2010-08-23 13:27:16 +00:00
Clément Oudot
4fa2f6318e
Build removeOther link with javascript, to get the final redirection URL and method ( #125 )
2010-08-20 15:07:55 +00:00
Clément Oudot
a9a2106e89
Add a back URL in removeOther link ( #125 )
2010-08-20 13:48:09 +00:00
Clément Oudot
a85958f90f
Always clear previous hidden form value when PE_INFO is returned by autoRedirect and autoPost ( #125 )
2010-08-20 10:52:52 +00:00
Clément Oudot
5e6efebab1
Manage info form hidden fields for autoRedirect and autoPost ( #125 )
2010-08-20 10:31:20 +00:00
Clément Oudot
ead9413dd8
Possibility to control form method of info and confirm screen (references #125 )
2010-08-19 16:19:30 +00:00
Clément Oudot
f0af83546a
Correct bug for artifact resolution on IDP side ( #143 )
2010-08-19 14:17:25 +00:00
Clément Oudot
e29a65e92b
Disable timer on IDP list ( #141 )
2010-08-18 15:10:30 +00:00
Clément Oudot
6781054397
Return error when SAML authentication is refused by user ( #132 )
2010-08-18 14:26:18 +00:00
Clément Oudot
33403f3396
Display a link to go back to SP on IDP login page ( #140 )
2010-08-18 13:39:15 +00:00
Xavier Guimard
45aaa41cee
Split extractFormInfo => create getIDP()
2010-08-18 10:07:42 +00:00
Clément Oudot
6c534022f4
Use #PORTAL# macro in SAML URL to ease SAML configuration ( #139 )
2010-08-18 09:49:55 +00:00
Clément Oudot
1dc1f926e4
Add timeout, version and binary attributes options for LDAP configuration ( closes #129 )
2010-07-28 10:00:30 +00:00
Clément Oudot
5cc3a3057a
Update MailReset doxygen documentation ( #7 )
2010-07-22 09:06:50 +00:00
Clément Oudot
a32502b8f7
Do use st when browsing backends (authentication, userDB, ...) to prevent from a bug in Perl-LDAP 0.40 ( #128 )
2010-07-21 12:13:12 +00:00
Clément Oudot
6792a1350c
Store replay protection for SAML SLO request sent by IDP
2010-07-05 21:24:34 +00:00
Clément Oudot
192dd9c8e1
Preparation for 1.0rc2 release
2010-07-05 16:20:17 +00:00
Clément Oudot
15cb8f6e29
SAML error codes for IDP and UserDBSAML ( #40 )
2010-07-05 15:58:03 +00:00
Clément Oudot
abfc445f38
SAML Error codes for SP ( #40 )
2010-07-05 15:38:02 +00:00
Clément Oudot
6fb21c669b
Use private key passwords ( #97 )
2010-07-05 11:50:12 +00:00
Clément Oudot
3ed02a09b8
* Set noInfo flag when updating session
...
* Get sessionIndex from SLO request before validating the request
* Use NameID dump in debug message
2010-07-05 09:36:52 +00:00
Clément Oudot
1c4d8535f7
SAML: Issuer can send SLO requests to SP and IDP when in proxy mode ( #31 )
2010-07-03 14:38:46 +00:00
Clément Oudot
c0548bab70
Modify XML namespace for Lasso Session empty object
2010-07-03 13:55:43 +00:00
Clément Oudot
0dac2f1374
* authInit should be called before issuerForAuthUser when we catch SLO URL in IDP proxy mode
...
* do not 'return' sendSLOErrorMessage
2010-07-02 15:42:22 +00:00
Clément Oudot
b635d87761
* authInit should be called before issuerForAuthUser when we catch SLO URL in IDP proxy mode
...
* do not 'return' sendSLOErrorMessage
2010-07-02 15:14:54 +00:00
Clément Oudot
f193d0b66d
Really exit if sendSLOErrorMessage fail
2010-07-02 14:17:01 +00:00
Clément Oudot
a6c60ec1a7
Keep and restore SAML request for IDP proxy ( #31 )
2010-07-02 11:29:00 +00:00
Clément Oudot
e0bbb1c9d0
Delete SAML sessions on local logout ( #122 )
2010-07-02 09:05:46 +00:00
Clément Oudot
1f28b97cd8
Wrong error level in debug message
2010-07-02 08:54:54 +00:00
Clément Oudot
e359e1a7d1
SAML: use correct method to build artifact message ( #32 )
2010-07-02 08:14:26 +00:00
Clément Oudot
5754d86ff5
* Add a troolean type in Manager
...
* Sign SAML Message options can accept the default value (#88 )
2010-07-01 16:05:57 +00:00
Clément Oudot
2ce4e19a0d
SAML: catch SSO artifact URL in IssuerDBSAML ( #32 )
2010-07-01 11:31:24 +00:00
Clément Oudot
f46c3b4224
SAML: artifact for sending authn request, work in progress ( #32 )
2010-07-01 09:48:50 +00:00
Clément Oudot
edb345f23c
SAML:
...
* Correct a SLO bug when only one SP in session
* Check NotOnOrAfter in SLO request (#36 )
2010-06-30 08:05:20 +00:00
Clément Oudot
b2381101d7
SAML: use getSamlSession whenever it's possible
2010-06-28 16:22:07 +00:00
Clément Oudot
758c133f81
SAML: encode metadata flag was not honored for attribute authority
2010-06-28 15:04:40 +00:00
Clément Oudot
d07eaab83f
SAML: keep SAML request in memory for IDP Proxy management ( #31 )
2010-06-28 15:00:14 +00:00
Clément Oudot
3ee1e9b393
Add an option to encode Metadata in UTF-8 ( #119 )
2010-06-28 09:11:59 +00:00
Clément Oudot
f5367d4dc9
* Create sendSLOErrorResponse subroutine
...
* Send SLO error if REDIRECT or POST SLO request on a closed session (#107 )
* Send SLO error instead of empty SOAP message, or local error page
2010-06-28 08:34:15 +00:00
Clément Oudot
dee65a4d00
SAML: cache Lasso::Server object to increase performances ( #86 )
2010-06-25 15:38:14 +00:00
Clément Oudot
d114827e70
Store metadata in raw format ( #104 )
2010-06-25 13:51:09 +00:00
Clément Oudot
b32d4e8f52
Remove HttpRedirect and HttpDisableSubmit options in info.tpl, and use hidden fields to store URL parameters, for form GET to work ( #115 )
2010-06-23 14:03:18 +00:00
Clément Oudot
07f648cd7e
SLO termination complete ( #111 )
2010-06-23 09:58:14 +00:00
Xavier Guimard
0e082b1d8f
Closes : #114 : Bad usage of Apache::Session::searchOn() on portal
2010-06-22 16:30:38 +00:00
Clément Oudot
33699a6d40
SAML: build a SLO termination state ( #111 )
2010-06-21 16:24:50 +00:00
Clément Oudot
174026f44c
SAML: validate SLO request before building other SP SLO request ( #111 )
2010-06-21 15:44:18 +00:00
Xavier Guimard
aa190c7f35
make tidy
2010-06-21 15:29:59 +00:00
Xavier Guimard
8139248c15
Closes : #113 : Lemonldap::NG is not compatible with the use of a LDAP server using a different encoding than UTF-8 for storing passwords
2010-06-21 14:47:27 +00:00
Clément Oudot
8b23a63fb3
SAML: use a SLO status session to store SLO status on IDP side ( #111 )
2010-06-21 14:28:42 +00:00
Clément Oudot
3b6e0567ee
SAML: store SAML Token in session ( #110 )
2010-06-18 13:07:20 +00:00
Clément Oudot
11761807f4
SAML: do not send empty Attribute Statement ( #109 )
2010-06-18 07:50:37 +00:00
Clément Oudot
af0f4ef88e
SAML: force NameID format if requested format is unspecified ( #108 )
2010-06-17 13:29:53 +00:00
Clément Oudot
e33f7c2efc
SAML:
...
* Use table instead of list for SP SLO status
* Catch SLO response and display status logo (#106 )
2010-06-16 16:17:05 +00:00
Clément Oudot
885966f04b
SAML: error in SAML POST field name ( #56 )
2010-06-16 13:08:18 +00:00
Clément Oudot
1aec1902f5
SAML: create POST relay mechanism to send POST SLO requests ( #56 )
2010-06-16 10:32:43 +00:00
Clément Oudot
8ffd3e6244
Display status of SLO request in debug level ( #78 )
2010-06-14 15:42:32 +00:00
Clément Oudot
d1d0accae6
Rebuild logout object before sending SLO response ( #78 )
2010-06-14 15:29:37 +00:00
Clément Oudot
ebc421d335
Return directly if no local session ( #105 )
2010-06-14 14:52:52 +00:00
Clément Oudot
021f89d918
Check session before closing it ( #105 )
2010-06-14 14:18:27 +00:00
Xavier Guimard
22387615fb
Permit direct OpenID server side direct authentication
2010-06-14 06:19:34 +00:00
Clément Oudot
6bc5246690
Send SOAP SLO request to other entities when receiving a SOAP SLO request on IDP ( #78 )
2010-06-11 14:50:28 +00:00
Clément Oudot
98a9b6ef40
SAML: delete secondary SAML sessions ( #100 )
2010-06-11 14:13:26 +00:00
Clément Oudot
a570447179
SAML: use another method to set NameID in Attribute request ( #83 )
2010-06-11 13:49:33 +00:00
Clément Oudot
a62484dc91
SAML: manage SOAP SLO request - work in progress ( #78 )
2010-06-11 10:17:43 +00:00
Clément Oudot
2b7cbd4d83
SAML:
...
* IDP Option to check conditions (#98 )
* Extend SAML date format (add milliseconds)
2010-06-10 15:01:05 +00:00
Thomas CHEMINEAU
3fb6a0ccd1
SAML #89 - Now use a different private key for encryption when creation Lasso::Server object
2010-06-09 08:42:30 +00:00
Clément Oudot
2ab40fea15
Soap is not required for SAML ( #91 )
2010-06-08 13:19:00 +00:00
Xavier Guimard
11dd597a41
Some Lintian tips
2010-06-08 10:39:34 +00:00
Clément Oudot
7e031e199a
SAML: minor corrections for forceAuthn flag management ( #34 )
2010-06-07 15:36:45 +00:00
Clément Oudot
783d88eabb
SAML: manage ForceAuthn flag from SP ( #34 )
2010-06-07 14:48:59 +00:00
Clément Oudot
05637bf0c4
SAML: set encryption mode on providers (none, nameid or assertion) ( #49 )
2010-06-04 15:54:52 +00:00
Clément Oudot
dd615d0678
SAML:
...
* Check values of requested attributes (#85 )
* Refactor some code in _SAML (createAttribute and createAttributeValue)
2010-06-04 14:23:41 +00:00
Xavier Guimard
208a4f34d2
Closes #82 : CDA always use secured cookie even if requested site is a http one
2010-06-04 08:43:42 +00:00
Xavier Guimard
47d38c7e3f
New debconf translation ( Closes : #584453 / bugs.debian.org)
2010-06-04 08:35:53 +00:00
Thomas CHEMINEAU
160c5f670a
fix #35 - include more checks to test contents on identity dump
2010-06-03 14:02:15 +00:00
Clément Oudot
cc1eb344a7
SAML: get attributes in attribute response
2010-06-02 15:21:39 +00:00
Clément Oudot
101442179d
Check format and friendly name from attribute ( #84 )
2010-06-02 14:51:39 +00:00
Clément Oudot
e928b770f7
SAML: browse SP authorized attributes and build attribute response ( #2 )
2010-06-02 13:45:37 +00:00
Clément Oudot
5ded22db86
Do not return errors in POST or SOAP response process, just quit if something is wrong
2010-06-02 09:12:35 +00:00
Clément Oudot
82b350a397
SAML: check NameID before extracting content
2010-06-02 09:08:33 +00:00
Clément Oudot
5444a9d3b4
SAML:
...
* Grab NameID from attribute request and find corresponding session (#2 )
* create a getSamlSession subroutine
2010-06-02 09:04:07 +00:00
Clément Oudot
a27464e277
SAML: process and validate attribute request ( #2 )
2010-06-02 08:09:59 +00:00