diff options
5 files changed, 148 insertions, 19 deletions
| diff --git a/id/server/doc/handbook/protocol/protocol.html b/id/server/doc/handbook/protocol/protocol.html index ff7921ad5..6713bd7a3 100644 --- a/id/server/doc/handbook/protocol/protocol.html +++ b/id/server/doc/handbook/protocol/protocol.html @@ -271,6 +271,13 @@ Redirect Binding</td>        <p><strong>Hinweis:</strong> Im Falle einer privatwirtschaftlichen Applikation ist die Stammzahl durch die wbPK ersetzt.</p></td>      </tr>      <tr> +      <td height="23">urn:oid:1.2.40.0.10.2.1.1.261.106</td> +      <td>MANDATE-TYPE-OID</td> +      <td align="center">mandate</td> +      <td> </td> +      <td>Bezeichnung als OID des verwendeten Vollmachten-Profils</td> +    </tr> +    <tr>        <td height="23">urn:oid:1.2.40.0.10.2.1.1.261.68</td>        <td>MANDATE-TYPE</td>        <td align="center">mandate</td> @@ -646,6 +653,45 @@ Redirect Binding</td>      <td>Der geforderte QAA Level ist höher als der QAA Level der gewählten Authentifizierungsmethode</td>    </tr>  </table> +<h5><a name="statuscodes_13xx" id="allgemeines_zugangspunkte26"></a>1.3.1.4 eIDAS (13xxx)</h5> +<table class="configtable"> +  <tr> +    <th width="13%">Statuscode</th> +    <th width="87%">Beschreibung</th> +  </tr> +  <tr> +    <td>1300</td> +    <td>Fehler beim Erstellen des eIDAS Authentifizierungsrequests</td> +  </tr> +  <tr> +    <td>1301</td> +    <td>Fehler beim Validieren der eIDAS Authentifizierungsresponse</td> +  </tr> +  <tr> +    <td>1302</td> +    <td>Response vom eIDAS Node enthält einen Fehler</td> +  </tr> +  <tr> +    <td>1303</td> +    <td>eIDAS Response beinhaltet nicht alle minimal erforderlichen Attribute</td> +  </tr> +  <tr> +    <td>1304</td> +    <td>Der ausgewählte eIDAS Node existiert nicht oder ist nicht konfiguriert</td> +  </tr> +  <tr> +    <td>1305</td> +    <td>eIDAS Request konnte nicht gültig verarbeitet werden</td> +  </tr> +  <tr> +    <td>1306</td> +    <td>Generierung dereIDAS Metadaten fehlgeschlagen</td> +  </tr> +  <tr> +    <td>1399</td> +    <td>Interner Fehler in der eIDAS SAML-Engine</td> +  </tr> +</table>  <h4><a name="statuscodes_4xxxx" id="allgemeines_zugangspunkte8"></a>1.3.2 Statuscodes 4xxxx</h4>  <p>Alles Statuscodes beginnend mit der Zahl vier beschreiben Fehler die während der Kommunikation mit externen Services aufgetreten sind.</p>  <h5><a name="statuscodes_40xxx" id="allgemeines_zugangspunkte19"></a>1.3.2.1 BKU (40xxxx)</h5> diff --git a/id/server/idserverlib/src/main/resources/resources/properties/id_messages_de.properties b/id/server/idserverlib/src/main/resources/resources/properties/id_messages_de.properties index 6b48750d2..400b0bc25 100644 --- a/id/server/idserverlib/src/main/resources/resources/properties/id_messages_de.properties +++ b/id/server/idserverlib/src/main/resources/resources/properties/id_messages_de.properties @@ -128,7 +128,7 @@ cleaner.03=Abgelaufene Anmeldedaten zur SAML-Assertion ID {0} wurden aus dem Spe  proxy.00=MOA ID Proxy wurde erfolgreich gestartet
  proxy.01=Unbekannter URL {0}, erwarteter URL auf {1}
 -proxy.02=Unbekannter URL {0}. <br>Es wurde keine Übereinstimmung zum Attribut publicURLPrefix im Element 'OnlineApplication' der verwendeten MOA-ID Konfigurationsdatei gefunden.
 +proxy.02=Unbekannter URL {0}. <br>Es wurde keine \u00dcbereinstimmung zum Attribut publicURLPrefix im Element 'OnlineApplication' der verwendeten MOA-ID Konfigurationsdatei gefunden.
  proxy.04=URL {0} : {1}
  proxy.05=Fehler beim Aufbauen der SSLSocketFactory f\u00FCr {0} \: {1}
  proxy.06=Fehler beim Starten des Service MOA ID Proxy
 @@ -265,8 +265,10 @@ eIDAS.05=Can not generate eIDAS metadata. Reason:{0}  eIDAS.06=Received eIDAS AuthnRequest can not processed. Reason:{0}
  eIDAS.07=Missing eIDAS-Attribute:{0}
  eIDAS.08=No valid eIDAs-Node configuration for enityID:{0}
 +eIDAS.09=Received eIDAS Response is not valid. Reason:{0}
 +eIDAS.10=Internal server error. Reason:{0}
 +eIDAS.11=Received eIDAS Error-Response. Reason:{0} 
 -pvp2.00={0} ist kein gueltiger consumer service index
  pvp2.01=Fehler beim kodieren der PVP2 Antwort
  pvp2.02=Ungueltiges Datumsformat
  pvp2.03=Vollmachtattribute nicht in Metadaten verfuegbar
 @@ -325,4 +327,4 @@ slo.02=Es wurde keine aktive SSO Session gefunden oder Sie sind bei keiner Onlin  process.01=Fehler beim Ausf\u00FChren des Prozesses.
  process.02=Fehler beim Erstellen eines geeigneten Prozesses f\u00FCr die SessionID {0}.
 -process.03=Fehler beim Weiterführen es Prozesses. Msg:{0}
 +process.03=Fehler beim Weiterf\u00FChren es Prozesses. Msg:{0}
 diff --git a/id/server/idserverlib/src/main/resources/resources/properties/protocol_response_statuscodes_de.properties b/id/server/idserverlib/src/main/resources/resources/properties/protocol_response_statuscodes_de.properties index 92e231bd0..bfaf5ffb1 100644 --- a/id/server/idserverlib/src/main/resources/resources/properties/protocol_response_statuscodes_de.properties +++ b/id/server/idserverlib/src/main/resources/resources/properties/protocol_response_statuscodes_de.properties @@ -213,16 +213,18 @@ stork.19=1203  stork.20=1204  stork.21=1205 -eIDAS.00=TODO -eIDAS.01=TODO -eIDAS.02=TODO -eIDAS.03=TODO -eIDAS.04=TODO -eIDAS.05=TODO -eIDAS.06=TODO -eIDAS.07=TODO -eIDAS.08=TODO - +eIDAS.00=1399 +eIDAS.01=1305 +eIDAS.02=1300 +eIDAS.03=1304 +eIDAS.04=1304 +eIDAS.05=1306 +eIDAS.06=1305 +eIDAS.07=1303 +eIDAS.08=1304 +eIDAS.09=1301 +eIDAS.10=9199 +eIDAS.11=1302  pvp2.01=6100  pvp2.06=6100 diff --git a/id/server/modules/moa-id-module-eIDAS/src/main/java/at/gv/egovernment/moa/id/auth/modules/eidas/exceptions/eIDASResponseNotSuccessException.java b/id/server/modules/moa-id-module-eIDAS/src/main/java/at/gv/egovernment/moa/id/auth/modules/eidas/exceptions/eIDASResponseNotSuccessException.java new file mode 100644 index 000000000..d10ca1c88 --- /dev/null +++ b/id/server/modules/moa-id-module-eIDAS/src/main/java/at/gv/egovernment/moa/id/auth/modules/eidas/exceptions/eIDASResponseNotSuccessException.java @@ -0,0 +1,67 @@ +/* + * Copyright 2014 Federal Chancellery Austria + * MOA-ID has been developed in a cooperation between BRZ, the Federal + * Chancellery Austria - ICT staff unit, and Graz University of Technology. + * + * Licensed under the EUPL, Version 1.1 or - as soon they will be approved by + * the European Commission - subsequent versions of the EUPL (the "Licence"); + * You may not use this work except in compliance with the Licence. + * You may obtain a copy of the Licence at: + * http://www.osor.eu/eupl/ + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the Licence is distributed on an "AS IS" basis, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the Licence for the specific language governing permissions and + * limitations under the Licence. + * + * This product combines work with different licenses. See the "NOTICE" text + * file for details on the various modules and licenses. + * The "NOTICE" text file is part of the distribution. Any derivative works + * that you distribute must include a readable copy of the "NOTICE" text file. + */ +package at.gv.egovernment.moa.id.auth.modules.eidas.exceptions; + +import org.opensaml.saml2.core.StatusCode; + +/** + * @author tlenz + * + */ +public class eIDASResponseNotSuccessException extends eIDASException { + +	/** +	 *  +	 */ +	private static final long serialVersionUID = 6145402939313568907L; + +	public eIDASResponseNotSuccessException(String messageId, Object[] parameters) { +		super(messageId, parameters); +	} +	 +	/** +	 * @param messageId +	 * @param parameters +	 * @param e +	 */ +	public eIDASResponseNotSuccessException(String messageId, Object[] parameters, Throwable e) { +		super(messageId, parameters, e); +	} + +	/* (non-Javadoc) +	 * @see at.gv.egovernment.moa.id.auth.modules.eidas.exceptions.eIDASException#getStatusCodeFirstLevel() +	 */ +	@Override +	public String getStatusCodeFirstLevel() { +		return StatusCode.RESPONDER_URI; +	} + +	/* (non-Javadoc) +	 * @see at.gv.egovernment.moa.id.auth.modules.eidas.exceptions.eIDASException#getStatusCodeSecondLevel() +	 */ +	@Override +	public String getStatusCodeSecondLevel() { +		return StatusCode.AUTHN_FAILED_URI; +	} + +} diff --git a/id/server/modules/moa-id-module-eIDAS/src/main/java/at/gv/egovernment/moa/id/auth/modules/eidas/tasks/ReceiveAuthnResponseTask.java b/id/server/modules/moa-id-module-eIDAS/src/main/java/at/gv/egovernment/moa/id/auth/modules/eidas/tasks/ReceiveAuthnResponseTask.java index b73c2a873..fae06031a 100644 --- a/id/server/modules/moa-id-module-eIDAS/src/main/java/at/gv/egovernment/moa/id/auth/modules/eidas/tasks/ReceiveAuthnResponseTask.java +++ b/id/server/modules/moa-id-module-eIDAS/src/main/java/at/gv/egovernment/moa/id/auth/modules/eidas/tasks/ReceiveAuthnResponseTask.java @@ -3,6 +3,7 @@ package at.gv.egovernment.moa.id.auth.modules.eidas.tasks;  import javax.servlet.http.HttpServletRequest;  import javax.servlet.http.HttpServletResponse; +import org.opensaml.saml2.core.StatusCode;  import org.springframework.stereotype.Component;  import at.gv.egovernment.moa.id.advancedlogging.MOAIDEventConstants; @@ -11,6 +12,7 @@ import at.gv.egovernment.moa.id.auth.modules.AbstractAuthServletTask;  import at.gv.egovernment.moa.id.auth.modules.TaskExecutionException;  import at.gv.egovernment.moa.id.auth.modules.eidas.Constants;  import at.gv.egovernment.moa.id.auth.modules.eidas.exceptions.EIDASEngineException; +import at.gv.egovernment.moa.id.auth.modules.eidas.exceptions.eIDASResponseNotSuccessException;  import at.gv.egovernment.moa.id.auth.modules.eidas.utils.MOAPersonalAttributeList;  import at.gv.egovernment.moa.id.auth.modules.eidas.utils.SAMLEngineUtils;  import at.gv.egovernment.moa.id.commons.api.exceptions.MOAIDException; @@ -58,7 +60,15 @@ public class ReceiveAuthnResponseTask extends AbstractAuthServletTask {  				//TODO: check if additional decryption operation is required  			} -						 + +			//check response StatusCode +			if (!samlResp.getStatusCode().equals(StatusCode.SUCCESS_URI)) { +				Logger.info("Receice eIDAS Response with StatusCode:" + samlResp.getStatusCode() +				+ " Subcode:" + samlResp.getSubStatusCode() + " Msg:" + samlResp.getMessage()); +				throw new eIDASResponseNotSuccessException("eIDAS.11", new Object[]{samlResp.getMessage()}); +				 +			} +			  			//MOA-ID specific response validation  			//TODO: implement MOA-ID specific response validation @@ -89,18 +99,20 @@ public class ReceiveAuthnResponseTask extends AbstractAuthServletTask {  			revisionsLogger.logEvent(pendingReq.getOnlineApplicationConfiguration(), pendingReq,   					MOAIDEventConstants.AUTHPROCESS_PEPS_RECEIVED_ERROR);  			throw new TaskExecutionException(pendingReq, "eIDAS AuthnRequest generation FAILED.",  -					new EIDASEngineException("eIDAS.00", new Object[]{e.getMessage()}, e)); -			 -		} catch (MOAIDException | MOADatabaseException e) { +					new EIDASEngineException("eIDAS.09", new Object[]{e.getMessage()}, e)); +					 +		} catch (MOADatabaseException e) {  			revisionsLogger.logEvent(pendingReq.getOnlineApplicationConfiguration(), pendingReq,   					MOAIDEventConstants.AUTHPROCESS_PEPS_RECEIVED_ERROR); -			throw new TaskExecutionException(pendingReq, "eIDAS Response processing FAILED.", e); +			throw new TaskExecutionException(pendingReq, "eIDAS Response processing FAILED.",  +					new MOAIDException("init.04", new Object[]{""}, e));  		} catch (Exception e) {  			Logger.error("eIDAS Response processing FAILED.", e);  			revisionsLogger.logEvent(pendingReq.getOnlineApplicationConfiguration(), pendingReq,   					MOAIDEventConstants.AUTHPROCESS_PEPS_RECEIVED_ERROR); -			throw new TaskExecutionException(pendingReq, e.getMessage(), e); +			throw new TaskExecutionException(pendingReq, e.getMessage(),  +					new MOAIDException("eIDAS.10", new Object[]{e.getMessage()}, e));  		}	 | 
