פתרון בעיות בהטמעה של מדיניות טענות נכוֹנוּת (assertions) של SAML

אתם צופים במסמכי התיעוד של Apigee Edge.
כדאי לעיין במסמכי התיעוד של Apigee X.
מידע

SourceNotConfigured

הודעת השגיאה

Deployment (פריסה) של proxy ל-API דרך ממשק המשתמש של Edge או Edge Management API נכשלת עם הודעת השגיאה הבאה:

Error Deploying Revision revision_number to environment
ValidateSAMLAssertion[policy_name]: Source is not correctly configured.

הודעת שגיאה לדוגמה

Error Deploying Revision 2 to test
ValidateSAMLAssertion[Validate-SAML-Assertion-1]: Source is not correctly configured.

דוגמה לצילום מסך של שגיאה

סיבה

פריסת ה-API Proxy נכשלת עם השגיאה הזו אם אחד או יותר מהרכיבים הבאים של מדיניות Validate SAML Assertion לא מוגדרים או ריקים: <Source>, ‏ <XPath>, ‏ <Namespaces>, ‏ <Namespace>.

לדוגמה, אם לא תכללו את הרכיב <XPath> או אם תשאירו את הרכיב <Source> או את הישויות שלו ריקים, הפריסה של ה-proxy ל-API תיכשל.

אבחון

  1. מזהים את שם המדיניות Validate SAML Assertion (אימות הצהרת SAML) שנכשל מתוך הודעת השגיאה. לדוגמה, בשגיאה הבאה, שם המדיניות Validate SAML Assertion הוא Validate-SAML-Assertion-1.

    ValidateSAMLAssertion[Validate-SAML-Assertion-1]: Source is not correctly configured.
    
  2. בודקים את קובץ ה-XML של המדיניות Validate SAML Assertion שנכשל. צריך לבדוק אם אחד או יותר מהרכיבים הבאים של המדיניות חסרים או ריקים: <Source>, ‏ <XPath>, ‏ <Namespaces>, ‏ <Namespace>. אם כן, יכול להיות שזה הגורם לשגיאה.

    לדוגמה, במדיניות הבאה יש רכיב <Namespaces> ריק מתחת לרכיב <Source>:

    <?xml version="1.0" encoding="UTF-8" standalone="yes"?>
    <ValidateSAMLAssertion name="SAML" ignoreContentType="false">
      <Source name="request">
        <Namespaces></Namespaces>
       </Source>
       <Description/>
     <TrustStore>ref://TrustStoreName</Truststore>
     <RemoveAssertion>false</RemoveAssertion>
    </ValidateSAMLAssertion>
    
  3. בדוגמה שלמעלה, הרכיב <Namespaces> ריק, ולכן מתקבלת השגיאה:

    ValidateSAMLAssertion[Validate-SAML-Assertion-1]: Source is not correctly configured.
    

רזולוציה

מוודאים שהערכים של רכיב <Source> מוגדרים בצורה נכונה באמצעות רכיב <Namespaces> ורכיב הצאצא שלו <Namespace>. צריך גם לוודא שהרכיב <XPath> מוגדר ולא ריק.

כדי לתקן את הדוגמה למדיניות Validate SAML Assertion (אימות טענת נכונות של SAML) שמוצגת למעלה, אפשר להוסיף את הרכיבים <Namespace> וגם את <XPath>:

<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<ValidateSAMLAssertion name="SAML" ignoreContentType="false">
  <Source name="request">
    <Namespaces>
      <Namespace prefix='soap'>http://schemas.xmlsoap.org/soap/envelope/</Namespace>
      <Namespace prefix='wsse'>http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd</Namespace>
      <Namespace prefix='saml'>urn:oasis:names:tc:SAML:2.0:assertion</Namespace>
    </Namespaces>
    <XPath>/soap:Envelope/soap:Header/wsse:Security/saml:Assertion</XPath>
  </Source>
   <Description/>
<TrustStore>ref://TrustStoreName</Truststore>
<RemoveAssertion>false</RemoveAssertion>
</ValidateSAMLAssertion>

TrustStoreNotConfigured

הודעת השגיאה

Deployment (פריסה) של proxy ל-API דרך ממשק המשתמש של Edge או Edge Management API נכשלת עם הודעת השגיאה הבאה:

Error Deploying Revision revision_number to environment
ValidateSAMLAssertion[[Ljava.lang.Object;@object]: Trust store is not correctly configured.

הודעת שגיאה לדוגמה

Error Deploying Revision 2 to test
ValidateSAMLAssertion[[Ljava.lang.Object;@39537262]: Trust store is not correctly configured.

דוגמה לצילום מסך של שגיאה

סיבה

אם הרכיב <TrustStore> ריק או לא מצוין במדיניות ValidateSAMLAssertion, הפריסה של שרת ה-proxy של ה-API תיכשל. חובה להגדיר מאגר מהימן.

אבחון

  1. בודקים את כל כללי המדיניות של Validate SAML Assertion (אימות טענת נכונות ב-SAML) ב-API Proxy הספציפי שבו התרחשה השגיאה. אם יש מדיניות Validate SAML Assertion שבה הרכיב <TrustStore> ריק או לא צוין, זו הסיבה לשגיאה.

    <?xml version="1.0" encoding="UTF-8" standalone="yes"?>
    <ValidateSAMLAssertion name="SAML" ignoreContentType="false">
     <Source name="request">
        <Namespaces>
          <Namespace prefix='soap'>http://schemas.xmlsoap.org/soap/envelope/</Namespace>
          <Namespace prefix='wsse'>http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd</Namespace>
          <Namespace prefix='saml'>urn:oasis:names:tc:SAML:2.0:assertion</Namespace>
        </Namespaces>
        <XPath>/soap:Envelope/soap:Header/wsse:Security/saml:Assertion</XPath>
      </Source>
        <Description/>
        <TrustStore/>
      <RemoveAssertion>false</RemoveAssertion>
    </ValidateSAMLAssertion>
    

רזולוציה

מוודאים שהרכיב <TrustStore> תמיד מצוין ולא ריק במדיניות Validate SAML Assertion. <TrustStore>השם צריך להיות זהה לשם של TrustStore תקין שקיים בכל הסביבות שבהן אתם מנסים לפרוס proxy.

כדי לתקן את הדוגמה שלמעלה, אפשר לציין ערך תקין לרכיב <TrustStore>.

<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<ValidateSAMLAssertion name="SAML" ignoreContentType="false">
  <Source name="request">
    <Namespaces>
      <Namespace prefix='soap'>http://schemas.xmlsoap.org/soap/envelope/</Namespace>
      <Namespace prefix='wsse'>http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd</Namespace>
      <Namespace prefix='saml'>urn:oasis:names:tc:SAML:2.0:assertion</Namespace>
    </Namespaces>
    <XPath>/soap:Envelope/soap:Header/wsse:Security/saml:Assertion</XPath>
  </Source>
  <TrustStore>TrustStoreName</TrustStore>
  <RemoveAssertion>false</RemoveAssertion>
</ValidateSAMLAssertion>

מידע נוסף על השימוש ב-Truststore זמין במאמר Truststores ו-Keystores.

NullKeyStore

הודעת השגיאה

פריסת ה-proxy ל-API דרך ממשק המשתמש של Edge או דרך Edge management API נכשלת עם הודעת השגיאה הבאה:

Error Deploying Revision revision_number to environment
Assertion KeyStore name cannot be null.

הודעת שגיאה לדוגמה

Error Deploying Revision 4 to test
Assertion KeyStore name cannot be null.

דוגמה לצילום מסך של שגיאה

סיבה

אם רכיב הצאצא <Name> ריק או לא צוין ברכיב <Keystore> של מדיניות GenerateSAMLAssertion, פריסת proxy ל-API תיכשל. חובה להזין שם תקין של מאגר מפתחות.

אבחון

  1. בודקים את כל כללי המדיניות של Generate SAML Assertion (יצירת טענת נכונות ב-SAML) בשרת ה-API Proxy הספציפי שבו אירעה הכשל. אם יש מדיניות Generate SAML Assertion שבה אלמנט הצאצא <Name> ריק או לא מצוין באלמנט <Keystore>, זו הסיבה לשגיאה.

    במדיניות הבאה של יצירת טענת נכוֹנוּת (assertion) של SAML יש אלמנט צאצא ריק <Name> באלמנט <Keystore>:

    <?xml version="1.0" encoding="UTF-8" standalone="yes"?>
    <GenerateSAMLAssertion name="SAML" ignoreContentType="false">`
      <CanonicalizationAlgorithm />
      <Issuer ref="reference">Issuer name</Issuer>
      <KeyStore>
        <Name></Name>
        <Alias ref="reference">alias</Alias>
      </KeyStore>
      <OutputVariable>
        <FlowVariable>assertion.content</FlowVariable>
        <Message name="request">
          <Namespaces>
            <Namespace prefix="test">http://www.example.com/test</Namespace>
          </Namespaces>
          <XPath>/envelope/header</XPath>
        </Message>
      </OutputVariable>
      <SignatureAlgorithm />
      <Subject ref="reference">Subject name</Subject>
      <Template ignoreUnresolvedVariables="false">
        <!-- A lot of XML goes here, in CDATA, with {} around
             each variable -->
      </Template>
    </GenerateSAMLAssertion>
    

רזולוציה

מוודאים שאלמנט הצאצא <Name> תמיד מצוין ולא ריק באלמנט <Keystore> של מדיניות Generate SAML Assertion (יצירת טענת SAML).

כדי לתקן את הדוגמה שלמעלה, צריך לציין את רכיב <Name> בצורה נכונה ולוודא שצוין ערך תקין לרכיב <Alias>.

<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<GenerateSAMLAssertion name="SAML" ignoreContentType="false">
  <CanonicalizationAlgorithm />
  <Issuer ref="reference">Issuer name</Issuer>
  <KeyStore>
    <Name ref="reference">keystorename</Name>
    <Alias ref="reference">alias</Alias>
  </KeyStore>
  <OutputVariable>
    <FlowVariable>assertion.content</FlowVariable>
    <Message name="request">
      <Namespaces>
        <Namespace prefix="test">http://www.example.com/test</Namespace>
      </Namespaces>
      <XPath>/envelope/header</XPath>
    </Message>
  </OutputVariable>
  <SignatureAlgorithm />
  <Subject ref="reference">Subject name</Subject>
  <Template ignoreUnresolvedVariables="false">
    <!-- A lot of XML goes here, in CDATA, with {} around
         each variable -->
  </Template>
</GenerateSAMLAssertion>

אפשר לעיין בדוגמאות מתוך דוגמאות קוד במאמר בנושא הפניה למדיניות SAMLAssertion.

NullKeyStoreAlias

הודעת השגיאה

Deployment (פריסה) של proxy ל-API דרך ממשק המשתמש של Edge או Edge Management API נכשלת עם הודעת השגיאה הבאה:

Error Deploying Revision revision_number to environment
Assertion KeyStore alias cannot be null.

הודעת שגיאה לדוגמה

Error Deploying Revision 4 to test
Assertion KeyStore alias cannot be null.

דוגמה לצילום מסך של שגיאה

סיבה

אם רכיב הצאצא <Alias> ריק או לא מצוין ברכיב <Keystore> של מדיניות Generate SAML Assertion, פריסת proxy ל-API תיכשל. חובה לציין כינוי תקין של Keystore.

אבחון

  1. בודקים את כל כללי המדיניות Generate SAML Assertion (יצירת טענת נכונות ב-SAML) בשרת ה-proxy הספציפי של ה-API שבו אירעה הכשל. אם יש מדיניות Generate SAML Assertion שבה אלמנט הצאצא <Alias> ריק או לא מצוין באלמנט <Keystore>, זו הסיבה לשגיאה.

    במדיניות הבאה של יצירת טענת נכוֹנוּת (assertion) של SAML יש אלמנט צאצא ריק <Alias> באלמנט <Keystore>:

    <?xml version="1.0" encoding="UTF-8" standalone="yes"?>
    <GenerateSAMLAssertion name="SAML" ignoreContentType="false">`
      <CanonicalizationAlgorithm />
      <Issuer ref="reference">Issuer name</Issuer>
      <KeyStore>
        <Name ref="reference">keystorename</Name>
        <Alias></Alias>
      </KeyStore>
      <OutputVariable>
        <FlowVariable>assertion.content</FlowVariable>
        <Message name="request">
          <Namespaces>
            <Namespace prefix="test">http://www.example.com/test</Namespace>
          </Namespaces>
          <XPath>/envelope/header</XPath>
        </Message>
      </OutputVariable>
      <SignatureAlgorithm />
      <Subject ref="reference">Subject name</Subject>
      <Template ignoreUnresolvedVariables="false">
        <!-- A lot of XML goes here, in CDATA, with {} around
             each variable -->
      </Template>
    </GenerateSAMLAssertion>
    

רזולוציה

מוודאים שרכיב הצאצא <Name> תמיד מצוין ולא ריק בתוך הרכיב <Keystore> של מדיניות יצירת טענת SAML.

כדי לתקן את הדוגמה שלמעלה, צריך לציין את רכיב <Alias> בצורה נכונה ולוודא שצוין ערך תקין לרכיב <Name>.

<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<GenerateSAMLAssertion name="SAML" ignoreContentType="false">
  <CanonicalizationAlgorithm />
  <Issuer ref="reference">Issuer name</Issuer>
  <KeyStore>
    <Name ref="reference">keystorename</Name>
    <Alias ref="reference">alias</Alias>
  </KeyStore>
  <OutputVariable>
    <FlowVariable>assertion.content</FlowVariable>
    <Message name="request">
      <Namespaces>
        <Namespace prefix="test">http://www.example.com/test</Namespace>
      </Namespaces>
      <XPath>/envelope/header</XPath>
    </Message>
  </OutputVariable>
  <SignatureAlgorithm />
  <Subject ref="reference">Subject name</Subject>
  <Template ignoreUnresolvedVariables="false">
    <!-- A lot of XML goes here, in CDATA, with {} around
         each variable -->
  </Template>
</GenerateSAMLAssertion>

אפשר לעיין בדוגמאות מתוך דוגמאות קוד במאמר בנושא הפניה למדיניות SAMLAssertion.

NullIssuer

הודעת השגיאה

Deployment (פריסה) של proxy ל-API דרך ממשק המשתמש של Edge או Edge Management API נכשלת עם הודעת השגיאה הבאה:

Error Deploying Revision revision_number to environment
Assertion Issuer cannot be null.

הודעת שגיאה לדוגמה

Error Deploying Revision 4 to test
Assertion Issuer cannot be null.

דוגמה לצילום מסך של שגיאה

סיבה

אם הרכיב <Issuer> ריק או לא מצוין במדיניות Generate SAML Assertion, הפריסה של proxy ל-API תיכשל. חובה לציין ערך תקין של <Issuer>.

אבחון

  1. בודקים את כל המדיניות של Generate SAML Assertion בפרוקסי הספציפי של ה-API שבו התרחש הכשל. אם יש מדיניות Generate SAML Assertion שבה הרכיב <Issuer> ריק או לא מצוין, זו הסיבה לשגיאה.

    במדיניות הבאה של יצירת טענת נכונות (assertion) של SAML, הרכיב <Issuer> ריק:

    <?xml version="1.0" encoding="UTF-8" standalone="yes"?>
    <GenerateSAMLAssertion name="SAML" ignoreContentType="false">`
      <CanonicalizationAlgorithm />
      <Issuer></Issuer>
      <KeyStore>
        <Name ref="reference">keystorename</Name>
        <Alias ref="reference">alias</Alias>
      </KeyStore>
      <OutputVariable>
        <FlowVariable>assertion.content</FlowVariable>
        <Message name="request">
          <Namespaces>
            <Namespace prefix="test">http://www.example.com/test</Namespace>
          </Namespaces>
          <XPath>/envelope/header</XPath>
        </Message>
      </OutputVariable>
      <SignatureAlgorithm />
      <Subject ref="reference">Subject name</Subject>
      <Template ignoreUnresolvedVariables="false">
        <!-- A lot of XML goes here, in CDATA, with {} around
             each variable -->
      </Template>
    </GenerateSAMLAssertion>
    

רזולוציה

מוודאים שהרכיב <Issuer> תמיד מצוין ולא ריק במדיניות Generate SAML Assertion.

כדי לתקן את הדוגמה שלמעלה, צריך לציין את רכיב <Issuer> בצורה נכונה:

<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<GenerateSAMLAssertion name="SAML" ignoreContentType="false">
  <CanonicalizationAlgorithm />
  <Issuer ref="reference">Issuer name</Issuer>
  <KeyStore>
    <Name ref="reference">keystorename</Name>
    <Alias ref="reference">alias</Alias>
  </KeyStore>
  <OutputVariable>
    <FlowVariable>assertion.content</FlowVariable>
    <Message name="request">
      <Namespaces>
        <Namespace prefix="test">http://www.example.com/test</Namespace>
      </Namespaces>
      <XPath>/envelope/header</XPath>
    </Message>
  </OutputVariable>
  <SignatureAlgorithm />
  <Subject ref="reference">Subject name</Subject>
  <Template ignoreUnresolvedVariables="false">
    <!-- A lot of XML goes here, in CDATA, with {} around
         each variable -->
  </Template>
</GenerateSAMLAssertion>

אפשר לעיין בדוגמאות מתוך דוגמאות קוד במאמר בנושא הפניה למדיניות SAMLAssertion.