diff options
2 files changed, 1812 insertions, 1800 deletions
| diff --git a/id/server/idserverlib/src/main/java/at/gv/egovernment/moa/id/auth/AuthenticationServer.java b/id/server/idserverlib/src/main/java/at/gv/egovernment/moa/id/auth/AuthenticationServer.java index 8d2684c9b..33fed945b 100644 --- a/id/server/idserverlib/src/main/java/at/gv/egovernment/moa/id/auth/AuthenticationServer.java +++ b/id/server/idserverlib/src/main/java/at/gv/egovernment/moa/id/auth/AuthenticationServer.java @@ -156,1434 +156,1434 @@ import eu.stork.peps.exceptions.STORKSAMLEngineException;   */  public class AuthenticationServer implements MOAIDAuthConstants { -    /** -     * single instance -     */ -    private static AuthenticationServer instance; - -    /** -     * time out in milliseconds used by {@link cleanup} for session store -     */ -    private long sessionTimeOutCreated = 15 * 60 * 1000; // default 10 minutes -    private long sessionTimeOutUpdated = 10 * 60 * 1000; // default 10 minutes -    /** -     * time out in milliseconds used by {@link cleanup} for authentication data -     * store -     */ -    private long authDataTimeOut = 2 * 60 * 1000; // default 2 minutes - -    /** -     * Returns the single instance of <code>AuthenticationServer</code>. -     * -     * @return the single instance of <code>AuthenticationServer</code> -     */ -    public static AuthenticationServer getInstance() { -        if (instance == null) -            instance = new AuthenticationServer(); -        return instance; -    } - -    /** -     * Constructor for AuthenticationServer. -     */ -    public AuthenticationServer() { -        super(); -    } - - -    /** -     * Processes the beginning of an authentication session. -     * <ul> -     * <li>Starts an authentication session</li> -     * <li>Creates an <code><InfoboxReadRequest></code></li> -     * <li>Creates an HTML form for querying the identity link from the security -     * layer implementation. <br> -     * Form parameters include -     * <ul> -     * <li>the <code><InfoboxReadRequest></code></li> -     * <li>the data URL where the security layer implementation sends it -     * response to</li> -     * </ul> -     * </ul> -     * -     * @param authURL            URL of the servlet to be used as data URL -     * @param target             "Geschäftsbereich" of the online application requested -     * @param targetFriendlyName Friendly name of the target if the target is configured via -     *                           configuration -     * @param oaURL              online application URL requested -     * @param bkuURL             URL of the "Bürgerkartenumgebung" to be used; may be -     *                           <code>null</code>; in this case, the default location will be -     *                           used -     * @param useMandate         Indicates if mandate is used or not -     * @param templateURL        URL providing an HTML template for the HTML form generated -     * @param templateMandteURL  URL providing an HTML template for the HTML form generated -     *                           (for signing in mandates mode) -     * @param req                determines the protocol used -     * @param sourceID -     * @return HTML form -     * @throws AuthenticationException -     * @see GetIdentityLinkFormBuilder -     * @see InfoboxReadRequestBuilder -     */ -    public String startAuthentication(AuthenticationSession session, HttpServletRequest req) throws WrongParametersException, -            AuthenticationException, ConfigurationException, BuildException { - -        if (session == null) { -            throw new AuthenticationException("auth.18", new Object[]{}); -        } - -        //load OnlineApplication configuration -        OAAuthParameter oaParam = -                AuthConfigurationProvider.getInstance().getOnlineApplicationParameter(session.getPublicOAURLPrefix()); -        if (oaParam == null) -            throw new AuthenticationException("auth.00", new Object[]{session.getPublicOAURLPrefix()}); - -        //load Template -        String template = null; -        if (session.getTemplateURL() != null) { -            try { - -                template = new String(FileUtils.readURL(session.getTemplateURL())); -            } catch (IOException ex) { -                throw new AuthenticationException("auth.03", new Object[]{ -                        session.getTemplateURL(), ex.toString()}, ex); -            } -        } - -        String infoboxReadRequest = ""; - -        String domainIdentifier = AuthConfigurationProvider.getInstance().getSSOTagetIdentifier().trim(); -        if (MiscUtil.isEmpty(domainIdentifier) && session.isSsoRequested()) { -            //do not use SSO if no Target is set -            Log.warn("NO SSO-Target found in configuration. Single Sign-On is deaktivated!"); -            session.setSsoRequested(false); - -        } - -        if (session.isSsoRequested()) { -            Log.info("SSO Login requested"); -            //load identityLink with SSO Target -            boolean isbuisness = false; - -            if (domainIdentifier.startsWith(PREFIX_WPBK)) { - -                isbuisness = true; - -            } else { -                isbuisness = false; - -            } - -            //build ReadInfobox request -            infoboxReadRequest = new InfoboxReadRequestBuilder().build( -                    isbuisness, domainIdentifier); - -        } else { -            Log.info("Non-SSO Login requested"); -                //build ReadInfobox request -                infoboxReadRequest = new InfoboxReadRequestBuilder().build( -                        oaParam.getBusinessService(), oaParam -                        .getIdentityLinkDomainIdentifier()); - -        } - - -        String dataURL = new DataURLBuilder().buildDataURL( -                session.getAuthURL(), REQ_VERIFY_IDENTITY_LINK, session -                .getSessionID()); - -        //removed in MOAID 2.0 -        String pushInfobox = ""; - -//		VerifyInfoboxParameters verifyInfoboxParameters = oaParam -//				.getVerifyInfoboxParameters(); -//		if (verifyInfoboxParameters != null) { -//			pushInfobox = verifyInfoboxParameters.getPushInfobox(); -//			session.setPushInfobox(pushInfobox); -//		} +	/** +	 * single instance +	 */ +	private static AuthenticationServer instance; + +	/** +	 * time out in milliseconds used by {@link cleanup} for session store +	 */ +	private long sessionTimeOutCreated = 15 * 60 * 1000; // default 10 minutes +	private long sessionTimeOutUpdated = 10 * 60 * 1000; // default 10 minutes +	/** +	 * time out in milliseconds used by {@link cleanup} for authentication data +	 * store +	 */ +	private long authDataTimeOut = 2 * 60 * 1000; // default 2 minutes + +	/** +	 * Returns the single instance of <code>AuthenticationServer</code>. +	 * +	 * @return the single instance of <code>AuthenticationServer</code> +	 */ +	public static AuthenticationServer getInstance() { +		if (instance == null) +			instance = new AuthenticationServer(); +		return instance; +	} + +	/** +	 * Constructor for AuthenticationServer. +	 */ +	public AuthenticationServer() { +		super(); +	} + + +	/** +	 * Processes the beginning of an authentication session. +	 * <ul> +	 * <li>Starts an authentication session</li> +	 * <li>Creates an <code><InfoboxReadRequest></code></li> +	 * <li>Creates an HTML form for querying the identity link from the security +	 * layer implementation. <br> +	 * Form parameters include +	 * <ul> +	 * <li>the <code><InfoboxReadRequest></code></li> +	 * <li>the data URL where the security layer implementation sends it +	 * response to</li> +	 * </ul> +	 * </ul> +	 * +	 * @param authURL            URL of the servlet to be used as data URL +	 * @param target             "Geschäftsbereich" of the online application requested +	 * @param targetFriendlyName Friendly name of the target if the target is configured via +	 *                           configuration +	 * @param oaURL              online application URL requested +	 * @param bkuURL             URL of the "Bürgerkartenumgebung" to be used; may be +	 *                           <code>null</code>; in this case, the default location will be +	 *                           used +	 * @param useMandate         Indicates if mandate is used or not +	 * @param templateURL        URL providing an HTML template for the HTML form generated +	 * @param templateMandteURL  URL providing an HTML template for the HTML form generated +	 *                           (for signing in mandates mode) +	 * @param req                determines the protocol used +	 * @param sourceID +	 * @return HTML form +	 * @throws AuthenticationException +	 * @see GetIdentityLinkFormBuilder +	 * @see InfoboxReadRequestBuilder +	 */ +	public String startAuthentication(AuthenticationSession session, HttpServletRequest req) throws WrongParametersException, +	AuthenticationException, ConfigurationException, BuildException { + +		if (session == null) { +			throw new AuthenticationException("auth.18", new Object[]{}); +		} + +		//load OnlineApplication configuration +		OAAuthParameter oaParam = +				AuthConfigurationProvider.getInstance().getOnlineApplicationParameter(session.getPublicOAURLPrefix()); +		if (oaParam == null) +			throw new AuthenticationException("auth.00", new Object[]{session.getPublicOAURLPrefix()}); + +		//load Template +		String template = null; +		if (session.getTemplateURL() != null) { +			try { + +				template = new String(FileUtils.readURL(session.getTemplateURL())); +			} catch (IOException ex) { +				throw new AuthenticationException("auth.03", new Object[]{ +						session.getTemplateURL(), ex.toString()}, ex); +			} +		} + +		String infoboxReadRequest = ""; + +		String domainIdentifier = AuthConfigurationProvider.getInstance().getSSOTagetIdentifier().trim(); +		if (MiscUtil.isEmpty(domainIdentifier) && session.isSsoRequested()) { +			//do not use SSO if no Target is set +			Log.warn("NO SSO-Target found in configuration. Single Sign-On is deaktivated!"); +			session.setSsoRequested(false); + +		} + +		if (session.isSsoRequested()) { +			Log.info("SSO Login requested"); +			//load identityLink with SSO Target +			boolean isbuisness = false; + +			if (domainIdentifier.startsWith(PREFIX_WPBK)) { + +				isbuisness = true; + +			} else { +				isbuisness = false; + +			} + +			//build ReadInfobox request +			infoboxReadRequest = new InfoboxReadRequestBuilder().build( +					isbuisness, domainIdentifier); + +		} else { +			Log.info("Non-SSO Login requested"); +			//build ReadInfobox request +			infoboxReadRequest = new InfoboxReadRequestBuilder().build( +					oaParam.getBusinessService(), oaParam +					.getIdentityLinkDomainIdentifier()); + +		} + + +		String dataURL = new DataURLBuilder().buildDataURL( +				session.getAuthURL(), REQ_VERIFY_IDENTITY_LINK, session +				.getSessionID()); + +		//removed in MOAID 2.0 +		String pushInfobox = ""; + +		//		VerifyInfoboxParameters verifyInfoboxParameters = oaParam +		//				.getVerifyInfoboxParameters(); +		//		if (verifyInfoboxParameters != null) { +		//			pushInfobox = verifyInfoboxParameters.getPushInfobox(); +		//			session.setPushInfobox(pushInfobox); +		//		}  		//build CertInfo request  		//removed in MOA-ID 2.0 -//		String certInfoRequest = new CertInfoVerifyXMLSignatureRequestBuilder() -//				.build(); -//		String certInfoDataURL = new DataURLBuilder() -//				.buildDataURL(session.getAuthURL(), REQ_START_AUTHENTICATION, -//						session.getSessionID()); - -        //get Applet Parameters -        String appletwidth = req.getParameter(PARAM_APPLET_WIDTH); -        String appletheigth = req.getParameter(PARAM_APPLET_HEIGTH); -        appletheigth = StringEscapeUtils.escapeHtml(appletheigth); -        appletwidth = StringEscapeUtils.escapeHtml(appletwidth); - -    	 -    	//TODO: cleanup before MOA-ID 2.1 release -        try { -        	String htmlForm = new GetIdentityLinkFormBuilder().build(template, -        			session.getBkuURL(), infoboxReadRequest, dataURL, null, -        			null, pushInfobox, oaParam, appletheigth, appletwidth); -        	 -        	   return htmlForm; -               	 -        } catch (BuildException e) { -        	throw new BuildException("builder.07", null, e); -        	 -        }      -    } - -    /** -     * Processes an <code><InfoboxReadResponse></code> sent by the -     * security layer implementation.<br> -     * <ul> -     * <li>Validates given <code><InfoboxReadResponse></code></li> -     * <li>Parses identity link enclosed in -     * <code><InfoboxReadResponse></code></li> -     * <li>Verifies identity link by calling the MOA SP component</li> -     * <li>Checks certificate authority of identity link</li> -     * <li>Stores identity link in the session</li> -     * <li>Verifies all additional infoboxes returned from the BKU</li> -     * <li>Creates an authentication block to be signed by the user</li> -     * <li>Creates and returns a <code><CreateXMLSignatureRequest></code> -     * containg the authentication block, meant to be returned to the security -     * layer implementation</li> -     * </ul> -     * -     * @param sessionID                     ID of associated authentication session data -     * @param infoboxReadResponseParameters The parameters from the response returned from the BKU -     *                                      including the <code><InfoboxReadResponse></code> -     * @return String representation of the -     * <code><CreateXMLSignatureRequest></code> -     * @throws BKUException -     */ -    public String verifyIdentityLink(AuthenticationSession session, -                                     Map<String, String> infoboxReadResponseParameters) throws AuthenticationException, -            BuildException, ParseException, ConfigurationException, -            ValidateException, ServiceException, BKUException { - -        if (session == null) -            throw new AuthenticationException("auth.10", new Object[]{ -                    REQ_VERIFY_IDENTITY_LINK, PARAM_SESSIONID}); - -        String xmlInfoboxReadResponse = (String) infoboxReadResponseParameters -                .get(PARAM_XMLRESPONSE); - -        if (isEmpty(xmlInfoboxReadResponse)) -            throw new AuthenticationException("auth.10", new Object[]{ -                    REQ_VERIFY_IDENTITY_LINK, PARAM_XMLRESPONSE}); - -        AuthConfigurationProvider authConf = AuthConfigurationProvider -                .getInstance(); - -        // check if an identity link was found -        // Errorcode 2911 von Trustdesk BKU (nicht spezifikationskonform -        // (SL1.2)) -        // CharSequence se = "ErrorCode>2911".substring(0); -        // boolean b = xmlInfoboxReadResponse.contains(se); -        String se = "ErrorCode>2911"; -        int b = xmlInfoboxReadResponse.indexOf(se); -        if (b != -1) { // no identity link found -            Logger -                    .info("Es konnte keine Personenbindung auf der Karte gefunden werden. Versuche Anmeldung als auslaendische eID."); -            return null; -        } -        // spezifikationsgemaess (SL1.2) Errorcode -        se = "ErrorCode>4002"; -        // b = xmlInfoboxReadResponse.contains(se); -        b = xmlInfoboxReadResponse.indexOf(se); -        if (b != -1) { // Unbekannter Infoboxbezeichner -            Logger -                    .info("Unbekannter Infoboxbezeichner. Versuche Anmeldung als auslaendische eID."); -            return null; -        } - -        // parses the <InfoboxReadResponse> -        IdentityLink identityLink = new InfoboxReadResponseParser( -                xmlInfoboxReadResponse).parseIdentityLink(); -        // validates the identity link -        IdentityLinkValidator.getInstance().validate(identityLink); -        // builds a <VerifyXMLSignatureRequest> for a call of MOA-SP -        Element domVerifyXMLSignatureRequest = new VerifyXMLSignatureRequestBuilder() -                .build(identityLink, authConf -                        .getMoaSpIdentityLinkTrustProfileID()); - -        // invokes the call -        Element domVerifyXMLSignatureResponse = new SignatureVerificationInvoker() -                .verifyXMLSignature(domVerifyXMLSignatureRequest); -        // parses the <VerifyXMLSignatureResponse> -        VerifyXMLSignatureResponse verifyXMLSignatureResponse = new VerifyXMLSignatureResponseParser( -                domVerifyXMLSignatureResponse).parseData(); - -        OAAuthParameter oaParam = AuthConfigurationProvider.getInstance() -                .getOnlineApplicationParameter(session.getPublicOAURLPrefix()); - -        // validates the <VerifyXMLSignatureResponse> -        VerifyXMLSignatureResponseValidator.getInstance().validate( -                verifyXMLSignatureResponse, -                authConf.getIdentityLinkX509SubjectNames(), -                VerifyXMLSignatureResponseValidator.CHECK_IDENTITY_LINK, -                oaParam); - -        session.setIdentityLink(identityLink); -        // now validate the extended infoboxes - -        //Removed in MOA-ID 2.0 -        //verifyInfoboxes(session, infoboxReadResponseParameters, false); - -        return "found!"; -    } - -    /** -     * Processes an <code><InfoboxReadResponse></code> sent by the -     * security layer implementation.<br> -     * <ul> -     * <li>Validates given <code><InfoboxReadResponse></code></li> -     * <li>Parses identity link enclosed in -     * <code><InfoboxReadResponse></code></li> -     * <li>Verifies identity link by calling the MOA SP component</li> -     * <li>Checks certificate authority of identity link</li> -     * <li>Stores identity link in the session</li> -     * <li>Verifies all additional infoboxes returned from the BKU</li> -     * <li>Creates an authentication block to be signed by the user</li> -     * <li>Creates and returns a <code><CreateXMLSignatureRequest></code> -     * containg the authentication block, meant to be returned to the security -     * layer implementation</li> -     * </ul> -     * -     * @param sessionID                     ID of associated authentication session data -     * @param infoboxReadResponseParameters The parameters from the response returned from the BKU -     *                                      including the <code><InfoboxReadResponse></code> -     * @return String representation of the -     * <code><CreateXMLSignatureRequest></code> -     */ -    public String verifyCertificate(AuthenticationSession session, -                                    X509Certificate certificate) throws AuthenticationException, -            BuildException, ParseException, ConfigurationException, -            ValidateException, ServiceException, MOAIDException { - -        if (session == null) -            throw new AuthenticationException("auth.10", new Object[]{ -                    REQ_VERIFY_CERTIFICATE, PARAM_SESSIONID}); - -        // check if person is a Organwalter -        // if true - don't show bPK in AUTH Block -        try { -            for (ObjectID OWid : MOAIDAuthConstants.OW_LIST) { -                if (certificate.getExtension(OWid) != null) { -                    session.setOW(true); -                } - -            } - -        } catch (X509ExtensionInitException e) { -            Logger.warn("Certificate extension is not readable."); -            session.setOW(false); -        } - -        AuthConfigurationProvider authConf = AuthConfigurationProvider -                .getInstance(); - -        OAAuthParameter oaParam = AuthConfigurationProvider.getInstance() -                .getOnlineApplicationParameter(session.getPublicOAURLPrefix()); - -        String returnvalue = getCreateXMLSignatureRequestAuthBlockOrRedirect(session, -                authConf, oaParam); - -        return returnvalue; -    } - -    /** -     * Processes an <code>Mandate</code> sent by the MIS.<br> -     * <ul> -     * <li>Validates given <code>Mandate</code></li> -     * <li>Verifies Mandate by calling the MOA SP component</li> -     * <li>Creates an authentication block to be signed by the user</li> -     * <li>Creates and returns a <code><CreateXMLSignatureRequest></code> -     * containg the authentication block, meant to be returned to the security -     * layer implementation</li> -     * </ul> -     * -     * @param sessionID                     ID of associated authentication session data -     * @param infoboxReadResponseParameters The parameters from the response returned from the BKU -     *                                      including the <code><InfoboxReadResponse></code> -     * @return String representation of the -     * <code><CreateXMLSignatureRequest></code> -     */ -    public void verifyMandate(AuthenticationSession session, MISMandate mandate) -            throws AuthenticationException, BuildException, ParseException, -            ConfigurationException, ValidateException, ServiceException { - -        if (session == null) -            throw new AuthenticationException("auth.10", new Object[]{ -                    GET_MIS_SESSIONID, PARAM_SESSIONID}); - -        OAAuthParameter oaParam = AuthConfigurationProvider.getInstance() -                .getOnlineApplicationParameter(session.getPublicOAURLPrefix()); - -        try { -            // sets the extended SAML attributes for OID (Organwalter) -            setExtendedSAMLAttributeForMandatesOID(session, mandate, oaParam -                    .getBusinessService()); - -            validateExtendedSAMLAttributeForMandates(session, mandate, oaParam.getBusinessService()); - - -        } catch (SAXException e) { -            throw new AuthenticationException("auth.15", -                    new Object[]{GET_MIS_SESSIONID}, e); -        } catch (IOException e) { -            throw new AuthenticationException("auth.15", -                    new Object[]{GET_MIS_SESSIONID}, e); -        } catch (ParserConfigurationException e) { -            throw new AuthenticationException("auth.15", -                    new Object[]{GET_MIS_SESSIONID}, e); -        } catch (TransformerException e) { -            throw new AuthenticationException("auth.15", -                    new Object[]{GET_MIS_SESSIONID}, e); -        } - -    } - -    /** -     * @param session -     * @param authConf -     * @param oaParam -     * @return -     * @throws ConfigurationException -     * @throws BuildException -     * @throws ValidateException -     */ -    public String getCreateXMLSignatureRequestAuthBlockOrRedirect( -            AuthenticationSession session, AuthConfigurationProvider authConf, -            OAAuthParameter oaParam) throws ConfigurationException, -            BuildException, ValidateException { - -//        // check for intermediate processing of the infoboxes -//        if (session.isValidatorInputPending()) -//            return "Redirect to Input Processor"; - -        if (authConf == null) -            authConf = AuthConfigurationProvider.getInstance(); -        if (oaParam == null) -            oaParam = AuthConfigurationProvider.getInstance() -                    .getOnlineApplicationParameter( -                            session.getPublicOAURLPrefix()); - -        // builds the AUTH-block -        String authBlock = buildAuthenticationBlock(session, oaParam); - -        // builds the <CreateXMLSignatureRequest> -        List<String> transformsInfos = authConf.getTransformsInfos(); -         -        String createXMLSignatureRequest = new CreateXMLSignatureRequestBuilder() -                .build(authBlock, oaParam.getKeyBoxIdentifier(), -                        transformsInfos); -        return createXMLSignatureRequest; -    } - -    /** -     * Returns an CreateXMLSignatureRequest for signing the ERnP statement.<br> -     * <ul> -     * <li>Creates an CreateXMLSignatureRequest to be signed by the user</li> -     * </ul> -     * -     * @param sessionID ID of associated authentication session data -     * @param cert      The certificate from the user -     * @return String representation of the -     * <code><CreateXMLSignatureRequest></code> -     */ -    public String createXMLSignatureRequestForeignID(AuthenticationSession session, -                                                     X509Certificate cert) throws AuthenticationException, -            BuildException, ParseException, ConfigurationException, -            ValidateException, ServiceException { - -        if (session == null) -            throw new AuthenticationException("auth.10", new Object[]{ -                    REQ_VERIFY_CERTIFICATE, PARAM_SESSIONID}); - -        AuthConfigurationProvider authConf = AuthConfigurationProvider -                .getInstance(); - -        OAAuthParameter oaParam = AuthConfigurationProvider.getInstance() -                .getOnlineApplicationParameter(session.getPublicOAURLPrefix()); - -        return getCreateXMLSignatureRequestForeigID(session, authConf, oaParam, -                cert); -    } - -    public String getCreateXMLSignatureRequestForeigID( -            AuthenticationSession session, AuthConfigurationProvider authConf, -            OAAuthParameter oaParam, X509Certificate cert) -            throws ConfigurationException { - -//        // check for intermediate processing of the infoboxes -//        if (session.isValidatorInputPending()) -//            return "Redirect to Input Processor"; - -        if (authConf == null) -            authConf = AuthConfigurationProvider.getInstance(); -        if (oaParam == null) -            oaParam = AuthConfigurationProvider.getInstance() -                    .getOnlineApplicationParameter( -                            session.getPublicOAURLPrefix()); - -        Principal subject = cert.getSubjectDN(); - -        String createXMLSignatureRequest = new CreateXMLSignatureRequestBuilder() -                .buildForeignID(subject.toString(), oaParam, session); -        return createXMLSignatureRequest; -    } - -    /** -     * Processes an <code><CreateXMLSignatureResponse></code> sent by the -     * security layer implementation.<br> -     * <ul> -     * <li>Validates given <code><CreateXMLSignatureResponse></code></li> -     * <li>Parses response enclosed in -     * <code><CreateXMLSignatureResponse></code></li> -     * <li>Verifies signature by calling the MOA SP component</li> -     * <li>Returns the signer certificate</li> -     * </ul> -     * -     * @param sessionID                            ID of associated authentication session data -     * @param createXMLSignatureResponseParameters The parameters from the response returned from the BKU -     *                                             including the <code><CreateXMLSignatureResponse></code> -     * @throws BKUException -     */ -    public X509Certificate verifyXMLSignature(String sessionID, -                                              Map<String, String> createXMLSignatureResponseParameters) -            throws AuthenticationException, BuildException, ParseException, -            ConfigurationException, ValidateException, ServiceException, BKUException { - -        if (isEmpty(sessionID)) -            throw new AuthenticationException("auth.10", new Object[]{ -                    REQ_GET_FOREIGN_ID, PARAM_SESSIONID}); - -        String xmlCreateXMLSignatureResponse = (String) createXMLSignatureResponseParameters -                .get(PARAM_XMLRESPONSE); - -        if (isEmpty(xmlCreateXMLSignatureResponse)) -            throw new AuthenticationException("auth.10", new Object[]{ -                    REQ_GET_FOREIGN_ID, PARAM_XMLRESPONSE}); - -        AuthConfigurationProvider authConf = AuthConfigurationProvider -                .getInstance(); - -        // parses the <CreateXMLSignatureResponse> -        CreateXMLSignatureResponseParser p = new CreateXMLSignatureResponseParser( -                xmlCreateXMLSignatureResponse); -        CreateXMLSignatureResponse createXMLSignatureResponse = p -                .parseResponseDsig(); - -        // builds a <VerifyXMLSignatureRequest> for a call of MOA-SP -        Element domVerifyXMLSignatureRequest = new VerifyXMLSignatureRequestBuilder() -                .buildDsig(createXMLSignatureResponse, authConf -                        .getMoaSpAuthBlockTrustProfileID()); - -        // invokes the call -        Element domVerifyXMLSignatureResponse = new SignatureVerificationInvoker() -                .verifyXMLSignature(domVerifyXMLSignatureRequest); - -        // parses the <VerifyXMLSignatureResponse> -        VerifyXMLSignatureResponse verifyXMLSignatureResponse = new VerifyXMLSignatureResponseParser( -                domVerifyXMLSignatureResponse).parseData(); - -        return verifyXMLSignatureResponse.getX509certificate(); - -    } - -    /** -     * Processes an <code><CreateXMLSignatureResponse></code> sent by the -     * security layer implementation.<br> -     * <ul> -     * <li>Validates given <code><CreateXMLSignatureResponse></code></li> -     * <li>Parses response enclosed in -     * <code><CreateXMLSignatureResponse></code></li> -     * <li>Verifies signature by calling the MOA SP component</li> -     * <li>Returns the signer certificate</li> -     * </ul> -     * -     * @param sessionID                     ID of associated authentication session data -     * @param readInfoboxResponseParameters The parameters from the response returned from the BKU -     *                                      including the <code><ReadInfoboxResponse></code> -     * @throws BKUException -     */ -    public X509Certificate getCertificate(String sessionID, -                                          Map<String, String> readInfoboxResponseParameters) throws AuthenticationException, -            BuildException, ParseException, ConfigurationException, -            ValidateException, ServiceException, BKUException { - -        if (isEmpty(sessionID)) -            throw new AuthenticationException("auth.10", new Object[]{ -                    REQ_VERIFY_CERTIFICATE, PARAM_SESSIONID}); - -        String xmlReadInfoboxResponse = (String) readInfoboxResponseParameters -                .get(PARAM_XMLRESPONSE); - -        if (isEmpty(xmlReadInfoboxResponse)) -            throw new AuthenticationException("auth.10", new Object[]{ -                    REQ_VERIFY_CERTIFICATE, PARAM_XMLRESPONSE}); - -        // parses the <CreateXMLSignatureResponse> -        InfoboxReadResponseParser p = new InfoboxReadResponseParser( -                xmlReadInfoboxResponse); -        X509Certificate cert = p.parseCertificate(); - -        return cert; - -    } - -    /** -     * Builds an authentication block <code><saml:Assertion></code> from -     * given session data. -     * -     * @param session authentication session -     * @return <code><saml:Assertion></code> as a String -     * @throws BuildException If an error occurs on serializing an extended SAML attribute -     *                        to be appended to the AUTH-Block. -     */ -    private String buildAuthenticationBlock(AuthenticationSession session, -                                            OAAuthParameter oaParam) throws BuildException { - -        IdentityLink identityLink = session.getIdentityLink(); -        String issuer = identityLink.getName(); -        String gebDat = identityLink.getDateOfBirth(); - -        String identificationValue = null; -        String identificationType = null; - -        //set empty AuthBlock BPK in case of OW or SSO or bpk is not requested -        if (session.isOW() || session.isSsoRequested() || oaParam.isRemovePBKFromAuthBlock()) { -            identificationType = ""; -            identificationValue = ""; - -        } else if (identityLink.getIdentificationType().equals(Constants.URN_PREFIX_BASEID)) { - -            if (oaParam.getBusinessService()) { - -                String bpkBase64 = new BPKBuilder().buildWBPK(identityLink -                        .getIdentificationValue(), oaParam.getIdentityLinkDomainIdentifier()); -                identificationValue = bpkBase64; - -                if (oaParam.getIdentityLinkDomainIdentifier().startsWith(Constants.URN_PREFIX_WBPK + "+")) -                    identificationType = oaParam.getIdentityLinkDomainIdentifier(); -                else -                    identificationType = Constants.URN_PREFIX_WBPK + "+" + oaParam.getIdentityLinkDomainIdentifier(); - -            } else { -                String bpkBase64 = new BPKBuilder().buildBPK(identityLink -                        .getIdentificationValue(), session.getTarget()); -                identificationValue = bpkBase64; -                identificationType = Constants.URN_PREFIX_CDID + "+" + session.getTarget(); -            } - - -        } else { -            identificationValue = identityLink.getIdentificationValue(); -            identificationType = identityLink.getIdentificationType(); - -        } - -        String issueInstant = DateTimeUtils.buildDateTimeUTC(Calendar -                .getInstance()); -        session.setIssueInstant(issueInstant); -        String authURL = session.getAuthURL(); -        String target = session.getTarget(); -        String targetFriendlyName = session.getTargetFriendlyName(); - -        // Bug #485 -        // (https://egovlabs.gv.at/tracker/index.php?func=detail&aid=485&group_id=6&atid=105) -        // String oaURL = session.getPublicOAURLPrefix(); - -        List<ExtendedSAMLAttribute> extendedSAMLAttributes = session.getExtendedSAMLAttributesAUTH(); - - -        if (session.isSsoRequested()) { -            String oaURL = new String(); -            try { -                oaURL = AuthConfigurationProvider.getInstance().getPublicURLPrefix(); - -                if (MiscUtil.isNotEmpty(oaURL)) -                    oaURL = oaURL.replaceAll("&", "&"); - -            } catch (ConfigurationException e) { -            } -            String authBlock = new AuthenticationBlockAssertionBuilder() -                    .buildAuthBlockSSO(issuer, issueInstant, authURL, target, -                            targetFriendlyName, identificationValue, -                            identificationType, oaURL, gebDat, -                            extendedSAMLAttributes, session, oaParam); -            return authBlock; - -        } else { -            String oaURL = session.getPublicOAURLPrefix().replaceAll("&", "&"); -            String authBlock = new AuthenticationBlockAssertionBuilder() -                    .buildAuthBlock(issuer, issueInstant, authURL, target, -                            targetFriendlyName, identificationValue, -                            identificationType, oaURL, gebDat, -                            extendedSAMLAttributes, session, oaParam); -            return authBlock; -        } -    } - - -    /** -     * Verifies the infoboxes (except of the identity link infobox) returned by -     * the BKU by calling appropriate validator classes. -     * -     * @param session The actual authentication session. -     * @param mandate The Mandate from the MIS -     * @throws AuthenticationException -     * @throws ConfigurationException -     * @throws TransformerException -     * @throws ParserConfigurationException -     * @throws IOException -     * @throws SAXException -     */ -    private void validateExtendedSAMLAttributeForMandates( -            AuthenticationSession session, MISMandate mandate, -            boolean business) -            throws ValidateException, ConfigurationException, SAXException, -            IOException, ParserConfigurationException, TransformerException { - -        ExtendedSAMLAttribute[] extendedSAMLAttributes = addExtendedSamlAttributes( -                mandate, business, false); - -        int length = extendedSAMLAttributes.length; -        for (int i = 0; i < length; i++) { -            ExtendedSAMLAttribute samlAttribute = extendedSAMLAttributes[i]; - -            verifySAMLAttribute(samlAttribute, i, "MISService", -                    "MISService"); - -        } -    } - -    /** -     * Verifies the infoboxes (except of the identity link infobox) returned by -     * the BKU by calling appropriate validator classes. -     * -     * @param session The actual authentication session. -     * @param mandate The Mandate from the MIS -     * @throws AuthenticationException -     * @throws ConfigurationException -     * @throws TransformerException -     * @throws ParserConfigurationException -     * @throws IOException -     * @throws SAXException -     */ -    private void setExtendedSAMLAttributeForMandatesOID( -            AuthenticationSession session, MISMandate mandate, boolean business) -            throws ValidateException, ConfigurationException, SAXException, -            IOException, ParserConfigurationException, TransformerException { - -        ExtendedSAMLAttribute[] extendedSamlAttributes = addExtendedSamlAttributesOID( -                mandate, business); - -        AddAdditionalSAMLAttributes(session, extendedSamlAttributes, -                "MISService", "MISService"); - -    } - -    /** -     * Adds given SAML Attributes to the current session. They will be appended -     * to the final SAML Assertion or the AUTH block. If the attributes are -     * already in the list, they will be replaced. -     * -     * @param session                The current session -     * @param extendedSAMLAttributes The SAML attributes to add -     * @param identifier             The infobox identifier for debug purposes -     * @param friendlyNam            The friendly name of the infobox for debug purposes -     */ -    private static void AddAdditionalSAMLAttributes( -            AuthenticationSession session, -            ExtendedSAMLAttribute[] extendedSAMLAttributes, String identifier, -            String friendlyName) throws ValidateException { -        if (extendedSAMLAttributes == null) -            return; -        List<ExtendedSAMLAttribute> oaAttributes = session.getExtendedSAMLAttributesOA(); -        if (oaAttributes == null) -            oaAttributes = new Vector<ExtendedSAMLAttribute>(); -        List<ExtendedSAMLAttribute> authAttributes = session.getExtendedSAMLAttributesAUTH(); -        if (authAttributes == null) -            authAttributes = new Vector<ExtendedSAMLAttribute>(); -        int length = extendedSAMLAttributes.length; -        for (int i = 0; i < length; i++) { -            ExtendedSAMLAttribute samlAttribute = extendedSAMLAttributes[i]; - -            Object value = verifySAMLAttribute(samlAttribute, i, identifier, -                    friendlyName); - -            if ((value instanceof String) || (value instanceof Element)) { -                switch (samlAttribute.getAddToAUTHBlock()) { -                    case ExtendedSAMLAttribute.ADD_TO_AUTHBLOCK_ONLY: -                        replaceExtendedSAMLAttribute(authAttributes, samlAttribute); -                        break; -                    case ExtendedSAMLAttribute.ADD_TO_AUTHBLOCK: -                        replaceExtendedSAMLAttribute(authAttributes, samlAttribute); -                        replaceExtendedSAMLAttribute(oaAttributes, samlAttribute); -                        break; -                    case ExtendedSAMLAttribute.NOT_ADD_TO_AUTHBLOCK: -                        replaceExtendedSAMLAttribute(oaAttributes, samlAttribute); -                        break; -                    default: -                        Logger -                                .info("Invalid return value from method \"getAddToAUTHBlock()\" (" -                                        + samlAttribute.getAddToAUTHBlock() -                                        + ") in SAML attribute number " -                                        + (i + 1) -                                        + " for infobox " + identifier); -                        throw new ValidateException("validator.47", new Object[]{ -                                friendlyName, String.valueOf((i + 1))}); -                } -            } else { -                Logger -                        .info("The type of SAML-Attribute number " -                                + (i + 1) -                                + " returned from " -                                + identifier -                                + "-infobox validator is not valid. Must be either \"java.Lang.String\"" -                                + " or \"org.w3c.dom.Element\""); -                throw new ValidateException("validator.46", new Object[]{ -                        identifier, String.valueOf((i + 1))}); -            } -        } -        session.setExtendedSAMLAttributesAUTH(authAttributes); -        session.setExtendedSAMLAttributesOA(oaAttributes); -    } - -    /** -     * Adds the AUTH block related SAML attributes to the validation result. -     * This is needed always before the AUTH block is to be signed, because the -     * name of the mandator has to be set -     * -     * @throws ParserConfigurationException -     * @throws IOException -     * @throws SAXException -     * @throws TransformerException -     */ - -    protected static ExtendedSAMLAttribute[] addExtendedSamlAttributes( -            MISMandate mandate, boolean business, boolean provideStammzahl) -            throws SAXException, IOException, ParserConfigurationException, -            TransformerException { -        Vector<ExtendedSAMLAttribute> extendedSamlAttributes = new Vector<ExtendedSAMLAttribute>(); - -        extendedSamlAttributes.clear(); - -        // Name -        Element domMandate = mandateToElement(mandate); -        Element nameSpaceNode = domMandate.getOwnerDocument().createElement( -                "NameSpaceNode"); -        nameSpaceNode.setAttribute("xmlns" + SZRGWConstants.PD_POSTFIX, -                Constants.PD_NS_URI); -        nameSpaceNode.setAttribute("xmlns" + SZRGWConstants.MANDATE_POSTFIX, -                SZRGWConstants.MANDATE_NS); - -        Element mandator = (Element) XPathAPI.selectSingleNode(domMandate, -                "//md:Mandate/md:Mandator", nameSpaceNode); - -        // Mandate -        extendedSamlAttributes.add(new ExtendedSAMLAttributeImpl( -                EXT_SAML_MANDATE_RAW, domMandate, -                SZRGWConstants.MANDATE_NS, -                ExtendedSAMLAttribute.NOT_ADD_TO_AUTHBLOCK)); - -        // (w)bpk -        String wbpk = ParepUtils.extractMandatorWbpk(mandator); -        if (!ParepUtils.isEmpty(wbpk)) { -            if (!ParepUtils.isPhysicalPerson(mandator)) { -                String idType = ParepUtils -                        .extractMandatorIdentificationType(mandator); -                if (!ParepUtils.isEmpty(idType) -                        && idType.startsWith(Constants.URN_PREFIX_BASEID)) { -                    extendedSamlAttributes.add(new ExtendedSAMLAttributeImpl( -                            EXT_SAML_MANDATE_CB_BASE_ID, -                            ParepUtils.getRegisterString(idType) + ": " + wbpk, -                            SZRGWConstants.MANDATE_NS, -                            ExtendedSAMLAttribute.ADD_TO_AUTHBLOCK_ONLY)); -                } -            } else if (business) { -                extendedSamlAttributes.add(new ExtendedSAMLAttributeImpl( -                        EXT_SAML_MANDATE_WBPK, wbpk, -                        SZRGWConstants.MANDATE_NS, -                        ExtendedSAMLAttribute.ADD_TO_AUTHBLOCK_ONLY)); -            } -        } - -        ExtendedSAMLAttribute[] ret = new ExtendedSAMLAttribute[extendedSamlAttributes -                .size()]; -        extendedSamlAttributes.copyInto(ret); -        Logger.debug("ExtendedSAML Attributes: " + ret.length); -        return ret; - -    } - -    /** -     * Adds the AUTH block related SAML attributes to the validation result. -     * This is needed always before the AUTH block is to be signed, because the -     * name of the mandator has to be set -     * -     * @throws ParserConfigurationException -     * @throws IOException -     * @throws SAXException -     * @throws TransformerException -     */ -    private static ExtendedSAMLAttribute[] addExtendedSamlAttributesOID( -            MISMandate mandate, boolean business) throws SAXException, -            IOException, ParserConfigurationException, TransformerException { - -        Vector<ExtendedSAMLAttribute> extendedSamlAttributes = new Vector<ExtendedSAMLAttribute>(); - -        extendedSamlAttributes.clear(); - -        // RepresentationType -        extendedSamlAttributes.add(new ExtendedSAMLAttributeImpl( -                EXT_SAML_MANDATE_REPRESENTATIONTYPE, -                EXT_SAML_MANDATE_REPRESENTATIONTEXT, -                SZRGWConstants.MANDATE_NS, -                ExtendedSAMLAttribute.NOT_ADD_TO_AUTHBLOCK)); - -        String oid = mandate.getProfRep(); - -        if (oid != null) { -            extendedSamlAttributes.add(new ExtendedSAMLAttributeImpl( -                    EXT_SAML_MANDATE_OID, oid, -                    SZRGWConstants.MANDATE_NS, -                    ExtendedSAMLAttribute.NOT_ADD_TO_AUTHBLOCK)); -            String oidDescription = mandate.getTextualDescriptionOfOID(); -            extendedSamlAttributes.add(new ExtendedSAMLAttributeImpl( -                    EXT_SAML_MANDATE_OIDTEXTUALDESCRIPTION, -                    oidDescription, SZRGWConstants.MANDATE_NS, -                    ExtendedSAMLAttribute.NOT_ADD_TO_AUTHBLOCK)); - -        } - -        ExtendedSAMLAttribute[] ret = new ExtendedSAMLAttribute[extendedSamlAttributes -                .size()]; -        extendedSamlAttributes.copyInto(ret); -        Logger.debug("ExtendedSAML Attributes: " + ret.length); -        return ret; - -    } - -    /** -     * @param mandate -     * @return -     * @throws ParserConfigurationException -     * @throws IOException -     * @throws SAXException -     */ -    private static Element mandateToElement(MISMandate mandate) -            throws SAXException, IOException, ParserConfigurationException { -        ByteArrayInputStream bais = new ByteArrayInputStream(mandate -                .getMandate()); -        Document doc = DOMUtils.parseDocumentSimple(bais); -        return doc.getDocumentElement(); -    } - -    protected static void replaceExtendedSAMLAttribute(List<ExtendedSAMLAttribute> attributes, -                                                       ExtendedSAMLAttribute samlAttribute) { -        if (null == attributes) { -            attributes = new Vector<ExtendedSAMLAttribute>(); -        } else { -            String id = samlAttribute.getName(); -            int length = attributes.size(); -            for (int i = 0; i < length; i++) { -                ExtendedSAMLAttribute att = (ExtendedSAMLAttribute) attributes -                        .get(i); -                if (id.equals(att.getName())) { -                    // replace attribute -                    attributes.set(i, samlAttribute); -                    return; -                } -            } -            attributes.add(samlAttribute); -        } -    } - -    /** -     * Processes a <code><CreateXMLSignatureResponse></code> sent by the -     * security layer implementation.<br> -     * <ul> -     * <li>Validates given <code><CreateXMLSignatureResponse></code></li> -     * <li>Parses <code><CreateXMLSignatureResponse></code> for error -     * codes</li> -     * <li>Parses authentication block enclosed in -     * <code><CreateXMLSignatureResponse></code></li> -     * <li>Verifies authentication block by calling the MOA SP component</li> -     * <li>Creates authentication data</li> -     * <li>Creates a corresponding SAML artifact</li> -     * <li>Stores authentication data in the authentication data store indexed -     * by the SAML artifact</li> -     * <li>Deletes authentication session</li> -     * <li>Returns the SAML artifact, encoded BASE64</li> -     * </ul> -     * -     * @param sessionID                         session ID of the running authentication session -     * @param xmlCreateXMLSignatureReadResponse String representation of the -     *                                          <code><CreateXMLSignatureResponse></code> -     * @return SAML artifact needed for retrieving authentication data, encoded -     * BASE64 -     * @throws BKUException -     */ -    public String verifyAuthenticationBlock(AuthenticationSession session, -                                            String xmlCreateXMLSignatureReadResponse) -            throws AuthenticationException, BuildException, ParseException, -            ConfigurationException, ServiceException, ValidateException, BKUException { - -        if (session == null) -            throw new AuthenticationException("auth.10", new Object[]{ -                    REQ_VERIFY_AUTH_BLOCK, PARAM_SESSIONID}); -        if (isEmpty(xmlCreateXMLSignatureReadResponse)) -            throw new AuthenticationException("auth.10", new Object[]{ -                    REQ_VERIFY_AUTH_BLOCK, PARAM_XMLRESPONSE}); - -        AuthConfigurationProvider authConf = AuthConfigurationProvider -                .getInstance(); -        // parses <CreateXMLSignatureResponse> -        CreateXMLSignatureResponse csresp = new CreateXMLSignatureResponseParser( -                xmlCreateXMLSignatureReadResponse).parseResponse(); - -        try { -            String serializedAssertion = DOMUtils.serializeNode(csresp -                    .getSamlAssertion()); -            session.setAuthBlock(serializedAssertion); -        } catch (TransformerException e) { -            throw new ParseException("parser.04", new Object[]{ -                    REQ_VERIFY_AUTH_BLOCK, PARAM_XMLRESPONSE}); -        } catch (IOException e) { -            throw new ParseException("parser.04", new Object[]{ -                    REQ_VERIFY_AUTH_BLOCK, PARAM_XMLRESPONSE}); -        } -        // validates <CreateXMLSignatureResponse> -        if (session.isSsoRequested()) -            new CreateXMLSignatureResponseValidator().validateSSO(csresp, session); -        else -            new CreateXMLSignatureResponseValidator().validate(csresp, session); - -        // builds a <VerifyXMLSignatureRequest> for a MOA-SPSS call -        List<String> vtids = authConf.getMoaSpAuthBlockVerifyTransformsInfoIDs(); -        String tpid = authConf.getMoaSpAuthBlockTrustProfileID(); -        Element domVsreq = new VerifyXMLSignatureRequestBuilder().build(csresp, -                vtids, tpid); -        // debug output - -        Element domVsresp = null; -         -//        try { -        	// invokes the call -        	domVsresp = new SignatureVerificationInvoker() -        		.verifyXMLSignature(domVsreq); -        	// debug output -        	 -//        } catch ( ServiceException e) { -//        	Logger.error("Signature verification error. ", e); -//        	Logger.error("Signed Data: " + session.getAuthBlock()); -//        	try {        		 -//				Logger.error("VerifyRequest: " + DOMUtils.serializeNode(domVsreq)); -//			} catch (TransformerException e1) { -//				e1.printStackTrace(); -//				 -//			} catch (IOException e1) { -//				e1.printStackTrace(); -//				 -//			} -//        	 -//        	throw e;  -//        } - -         -        // parses the <VerifyXMLSignatureResponse> -        VerifyXMLSignatureResponse vsresp = new VerifyXMLSignatureResponseParser( -                domVsresp).parseData(); - -        if (Logger.isTraceEnabled()) { -            if (domVsresp != null) { -                try { -                    String xmlVerifyXMLSignatureResponse = DOMUtils -                            .serializeNode(domVsresp, true); -                    Logger.trace(new LogMsg(xmlCreateXMLSignatureReadResponse)); -                    Logger.trace(new LogMsg(xmlVerifyXMLSignatureResponse)); -                } catch (Throwable t) { -                    t.printStackTrace(); -                    Logger.info(new LogMsg(t.getStackTrace())); -                } -            } -        } - -        OAAuthParameter oaParam = AuthConfigurationProvider.getInstance() -                .getOnlineApplicationParameter(session.getPublicOAURLPrefix()); -         -        // validates the <VerifyXMLSignatureResponse> -        VerifyXMLSignatureResponseValidator.getInstance().validate(vsresp, -                null, VerifyXMLSignatureResponseValidator.CHECK_AUTH_BLOCK, -                oaParam); - -        // Compare AuthBlock Data with information stored in session, especially -        // date and time -        CreateXMLSignatureResponseValidator.getInstance().validateSigningDateTime(csresp); - -        try {         -        	// compares the public keys from the identityLink with the AuthBlock -        	VerifyXMLSignatureResponseValidator.getInstance().validateCertificate( -        			vsresp, session.getIdentityLink()); -        	 -        } catch ( ValidateException e) { -        	Logger.error("Signature verification error. ", e); -        	Logger.error("Signed Data: " + session.getAuthBlock()); -        	try {        		 +		//		String certInfoRequest = new CertInfoVerifyXMLSignatureRequestBuilder() +		//				.build(); +		//		String certInfoDataURL = new DataURLBuilder() +		//				.buildDataURL(session.getAuthURL(), REQ_START_AUTHENTICATION, +		//						session.getSessionID()); + +		//get Applet Parameters +		String appletwidth = req.getParameter(PARAM_APPLET_WIDTH); +		String appletheigth = req.getParameter(PARAM_APPLET_HEIGTH); +		appletheigth = StringEscapeUtils.escapeHtml(appletheigth); +		appletwidth = StringEscapeUtils.escapeHtml(appletwidth); + + +		//TODO: cleanup before MOA-ID 2.1 release +		try { +			String htmlForm = new GetIdentityLinkFormBuilder().build(template, +					session.getBkuURL(), infoboxReadRequest, dataURL, null, +					null, pushInfobox, oaParam, appletheigth, appletwidth); + +			return htmlForm; + +		} catch (BuildException e) { +			throw new BuildException("builder.07", null, e); + +		}      +	} + +	/** +	 * Processes an <code><InfoboxReadResponse></code> sent by the +	 * security layer implementation.<br> +	 * <ul> +	 * <li>Validates given <code><InfoboxReadResponse></code></li> +	 * <li>Parses identity link enclosed in +	 * <code><InfoboxReadResponse></code></li> +	 * <li>Verifies identity link by calling the MOA SP component</li> +	 * <li>Checks certificate authority of identity link</li> +	 * <li>Stores identity link in the session</li> +	 * <li>Verifies all additional infoboxes returned from the BKU</li> +	 * <li>Creates an authentication block to be signed by the user</li> +	 * <li>Creates and returns a <code><CreateXMLSignatureRequest></code> +	 * containg the authentication block, meant to be returned to the security +	 * layer implementation</li> +	 * </ul> +	 * +	 * @param sessionID                     ID of associated authentication session data +	 * @param infoboxReadResponseParameters The parameters from the response returned from the BKU +	 *                                      including the <code><InfoboxReadResponse></code> +	 * @return String representation of the +	 * <code><CreateXMLSignatureRequest></code> +	 * @throws BKUException +	 */ +	public String verifyIdentityLink(AuthenticationSession session, +			Map<String, String> infoboxReadResponseParameters) throws AuthenticationException, +			BuildException, ParseException, ConfigurationException, +			ValidateException, ServiceException, BKUException { + +		if (session == null) +			throw new AuthenticationException("auth.10", new Object[]{ +					REQ_VERIFY_IDENTITY_LINK, PARAM_SESSIONID}); + +		String xmlInfoboxReadResponse = (String) infoboxReadResponseParameters +				.get(PARAM_XMLRESPONSE); + +		if (isEmpty(xmlInfoboxReadResponse)) +			throw new AuthenticationException("auth.10", new Object[]{ +					REQ_VERIFY_IDENTITY_LINK, PARAM_XMLRESPONSE}); + +		AuthConfigurationProvider authConf = AuthConfigurationProvider +				.getInstance(); + +		// check if an identity link was found +		// Errorcode 2911 von Trustdesk BKU (nicht spezifikationskonform +		// (SL1.2)) +		// CharSequence se = "ErrorCode>2911".substring(0); +		// boolean b = xmlInfoboxReadResponse.contains(se); +		String se = "ErrorCode>2911"; +		int b = xmlInfoboxReadResponse.indexOf(se); +		if (b != -1) { // no identity link found +			Logger +			.info("Es konnte keine Personenbindung auf der Karte gefunden werden. Versuche Anmeldung als auslaendische eID."); +			return null; +		} +		// spezifikationsgemaess (SL1.2) Errorcode +		se = "ErrorCode>4002"; +		// b = xmlInfoboxReadResponse.contains(se); +		b = xmlInfoboxReadResponse.indexOf(se); +		if (b != -1) { // Unbekannter Infoboxbezeichner +			Logger +			.info("Unbekannter Infoboxbezeichner. Versuche Anmeldung als auslaendische eID."); +			return null; +		} + +		// parses the <InfoboxReadResponse> +		IdentityLink identityLink = new InfoboxReadResponseParser( +				xmlInfoboxReadResponse).parseIdentityLink(); +		// validates the identity link +		IdentityLinkValidator.getInstance().validate(identityLink); +		// builds a <VerifyXMLSignatureRequest> for a call of MOA-SP +		Element domVerifyXMLSignatureRequest = new VerifyXMLSignatureRequestBuilder() +		.build(identityLink, authConf +				.getMoaSpIdentityLinkTrustProfileID()); + +		// invokes the call +		Element domVerifyXMLSignatureResponse = new SignatureVerificationInvoker() +		.verifyXMLSignature(domVerifyXMLSignatureRequest); +		// parses the <VerifyXMLSignatureResponse> +		VerifyXMLSignatureResponse verifyXMLSignatureResponse = new VerifyXMLSignatureResponseParser( +				domVerifyXMLSignatureResponse).parseData(); + +		OAAuthParameter oaParam = AuthConfigurationProvider.getInstance() +				.getOnlineApplicationParameter(session.getPublicOAURLPrefix()); + +		// validates the <VerifyXMLSignatureResponse> +		VerifyXMLSignatureResponseValidator.getInstance().validate( +				verifyXMLSignatureResponse, +				authConf.getIdentityLinkX509SubjectNames(), +				VerifyXMLSignatureResponseValidator.CHECK_IDENTITY_LINK, +				oaParam); + +		session.setIdentityLink(identityLink); +		// now validate the extended infoboxes + +		//Removed in MOA-ID 2.0 +		//verifyInfoboxes(session, infoboxReadResponseParameters, false); + +		return "found!"; +	} + +	/** +	 * Processes an <code><InfoboxReadResponse></code> sent by the +	 * security layer implementation.<br> +	 * <ul> +	 * <li>Validates given <code><InfoboxReadResponse></code></li> +	 * <li>Parses identity link enclosed in +	 * <code><InfoboxReadResponse></code></li> +	 * <li>Verifies identity link by calling the MOA SP component</li> +	 * <li>Checks certificate authority of identity link</li> +	 * <li>Stores identity link in the session</li> +	 * <li>Verifies all additional infoboxes returned from the BKU</li> +	 * <li>Creates an authentication block to be signed by the user</li> +	 * <li>Creates and returns a <code><CreateXMLSignatureRequest></code> +	 * containg the authentication block, meant to be returned to the security +	 * layer implementation</li> +	 * </ul> +	 * +	 * @param sessionID                     ID of associated authentication session data +	 * @param infoboxReadResponseParameters The parameters from the response returned from the BKU +	 *                                      including the <code><InfoboxReadResponse></code> +	 * @return String representation of the +	 * <code><CreateXMLSignatureRequest></code> +	 */ +	public String verifyCertificate(AuthenticationSession session, +			X509Certificate certificate) throws AuthenticationException, +			BuildException, ParseException, ConfigurationException, +			ValidateException, ServiceException, MOAIDException { + +		if (session == null) +			throw new AuthenticationException("auth.10", new Object[]{ +					REQ_VERIFY_CERTIFICATE, PARAM_SESSIONID}); + +		// check if person is a Organwalter +		// if true - don't show bPK in AUTH Block +		try { +			for (ObjectID OWid : MOAIDAuthConstants.OW_LIST) { +				if (certificate.getExtension(OWid) != null) { +					session.setOW(true); +				} + +			} + +		} catch (X509ExtensionInitException e) { +			Logger.warn("Certificate extension is not readable."); +			session.setOW(false); +		} + +		AuthConfigurationProvider authConf = AuthConfigurationProvider +				.getInstance(); + +		OAAuthParameter oaParam = AuthConfigurationProvider.getInstance() +				.getOnlineApplicationParameter(session.getPublicOAURLPrefix()); + +		String returnvalue = getCreateXMLSignatureRequestAuthBlockOrRedirect(session, +				authConf, oaParam); + +		return returnvalue; +	} + +	/** +	 * Processes an <code>Mandate</code> sent by the MIS.<br> +	 * <ul> +	 * <li>Validates given <code>Mandate</code></li> +	 * <li>Verifies Mandate by calling the MOA SP component</li> +	 * <li>Creates an authentication block to be signed by the user</li> +	 * <li>Creates and returns a <code><CreateXMLSignatureRequest></code> +	 * containg the authentication block, meant to be returned to the security +	 * layer implementation</li> +	 * </ul> +	 * +	 * @param sessionID                     ID of associated authentication session data +	 * @param infoboxReadResponseParameters The parameters from the response returned from the BKU +	 *                                      including the <code><InfoboxReadResponse></code> +	 * @return String representation of the +	 * <code><CreateXMLSignatureRequest></code> +	 */ +	public void verifyMandate(AuthenticationSession session, MISMandate mandate) +			throws AuthenticationException, BuildException, ParseException, +			ConfigurationException, ValidateException, ServiceException { + +		if (session == null) +			throw new AuthenticationException("auth.10", new Object[]{ +					GET_MIS_SESSIONID, PARAM_SESSIONID}); + +		OAAuthParameter oaParam = AuthConfigurationProvider.getInstance() +				.getOnlineApplicationParameter(session.getPublicOAURLPrefix()); + +		try { +			// sets the extended SAML attributes for OID (Organwalter) +			setExtendedSAMLAttributeForMandatesOID(session, mandate, oaParam +					.getBusinessService()); + +			validateExtendedSAMLAttributeForMandates(session, mandate, oaParam.getBusinessService()); + + +		} catch (SAXException e) { +			throw new AuthenticationException("auth.15", +					new Object[]{GET_MIS_SESSIONID}, e); +		} catch (IOException e) { +			throw new AuthenticationException("auth.15", +					new Object[]{GET_MIS_SESSIONID}, e); +		} catch (ParserConfigurationException e) { +			throw new AuthenticationException("auth.15", +					new Object[]{GET_MIS_SESSIONID}, e); +		} catch (TransformerException e) { +			throw new AuthenticationException("auth.15", +					new Object[]{GET_MIS_SESSIONID}, e); +		} + +	} + +	/** +	 * @param session +	 * @param authConf +	 * @param oaParam +	 * @return +	 * @throws ConfigurationException +	 * @throws BuildException +	 * @throws ValidateException +	 */ +	public String getCreateXMLSignatureRequestAuthBlockOrRedirect( +			AuthenticationSession session, AuthConfigurationProvider authConf, +			OAAuthParameter oaParam) throws ConfigurationException, +			BuildException, ValidateException { + +		//        // check for intermediate processing of the infoboxes +		//        if (session.isValidatorInputPending()) +		//            return "Redirect to Input Processor"; + +		if (authConf == null) +			authConf = AuthConfigurationProvider.getInstance(); +		if (oaParam == null) +			oaParam = AuthConfigurationProvider.getInstance() +			.getOnlineApplicationParameter( +					session.getPublicOAURLPrefix()); + +		// builds the AUTH-block +		String authBlock = buildAuthenticationBlock(session, oaParam); + +		// builds the <CreateXMLSignatureRequest> +		List<String> transformsInfos = authConf.getTransformsInfos(); + +		String createXMLSignatureRequest = new CreateXMLSignatureRequestBuilder() +		.build(authBlock, oaParam.getKeyBoxIdentifier(), +				transformsInfos); +		return createXMLSignatureRequest; +	} + +	/** +	 * Returns an CreateXMLSignatureRequest for signing the ERnP statement.<br> +	 * <ul> +	 * <li>Creates an CreateXMLSignatureRequest to be signed by the user</li> +	 * </ul> +	 * +	 * @param sessionID ID of associated authentication session data +	 * @param cert      The certificate from the user +	 * @return String representation of the +	 * <code><CreateXMLSignatureRequest></code> +	 */ +	public String createXMLSignatureRequestForeignID(AuthenticationSession session, +			X509Certificate cert) throws AuthenticationException, +			BuildException, ParseException, ConfigurationException, +			ValidateException, ServiceException { + +		if (session == null) +			throw new AuthenticationException("auth.10", new Object[]{ +					REQ_VERIFY_CERTIFICATE, PARAM_SESSIONID}); + +		AuthConfigurationProvider authConf = AuthConfigurationProvider +				.getInstance(); + +		OAAuthParameter oaParam = AuthConfigurationProvider.getInstance() +				.getOnlineApplicationParameter(session.getPublicOAURLPrefix()); + +		return getCreateXMLSignatureRequestForeigID(session, authConf, oaParam, +				cert); +	} + +	public String getCreateXMLSignatureRequestForeigID( +			AuthenticationSession session, AuthConfigurationProvider authConf, +			OAAuthParameter oaParam, X509Certificate cert) +					throws ConfigurationException { + +		//        // check for intermediate processing of the infoboxes +		//        if (session.isValidatorInputPending()) +		//            return "Redirect to Input Processor"; + +		if (authConf == null) +			authConf = AuthConfigurationProvider.getInstance(); +		if (oaParam == null) +			oaParam = AuthConfigurationProvider.getInstance() +			.getOnlineApplicationParameter( +					session.getPublicOAURLPrefix()); + +		Principal subject = cert.getSubjectDN(); + +		String createXMLSignatureRequest = new CreateXMLSignatureRequestBuilder() +		.buildForeignID(subject.toString(), oaParam, session); +		return createXMLSignatureRequest; +	} + +	/** +	 * Processes an <code><CreateXMLSignatureResponse></code> sent by the +	 * security layer implementation.<br> +	 * <ul> +	 * <li>Validates given <code><CreateXMLSignatureResponse></code></li> +	 * <li>Parses response enclosed in +	 * <code><CreateXMLSignatureResponse></code></li> +	 * <li>Verifies signature by calling the MOA SP component</li> +	 * <li>Returns the signer certificate</li> +	 * </ul> +	 * +	 * @param sessionID                            ID of associated authentication session data +	 * @param createXMLSignatureResponseParameters The parameters from the response returned from the BKU +	 *                                             including the <code><CreateXMLSignatureResponse></code> +	 * @throws BKUException +	 */ +	public X509Certificate verifyXMLSignature(String sessionID, +			Map<String, String> createXMLSignatureResponseParameters) +					throws AuthenticationException, BuildException, ParseException, +					ConfigurationException, ValidateException, ServiceException, BKUException { + +		if (isEmpty(sessionID)) +			throw new AuthenticationException("auth.10", new Object[]{ +					REQ_GET_FOREIGN_ID, PARAM_SESSIONID}); + +		String xmlCreateXMLSignatureResponse = (String) createXMLSignatureResponseParameters +				.get(PARAM_XMLRESPONSE); + +		if (isEmpty(xmlCreateXMLSignatureResponse)) +			throw new AuthenticationException("auth.10", new Object[]{ +					REQ_GET_FOREIGN_ID, PARAM_XMLRESPONSE}); + +		AuthConfigurationProvider authConf = AuthConfigurationProvider +				.getInstance(); + +		// parses the <CreateXMLSignatureResponse> +		CreateXMLSignatureResponseParser p = new CreateXMLSignatureResponseParser( +				xmlCreateXMLSignatureResponse); +		CreateXMLSignatureResponse createXMLSignatureResponse = p +				.parseResponseDsig(); + +		// builds a <VerifyXMLSignatureRequest> for a call of MOA-SP +		Element domVerifyXMLSignatureRequest = new VerifyXMLSignatureRequestBuilder() +		.buildDsig(createXMLSignatureResponse, authConf +				.getMoaSpAuthBlockTrustProfileID()); + +		// invokes the call +		Element domVerifyXMLSignatureResponse = new SignatureVerificationInvoker() +		.verifyXMLSignature(domVerifyXMLSignatureRequest); + +		// parses the <VerifyXMLSignatureResponse> +		VerifyXMLSignatureResponse verifyXMLSignatureResponse = new VerifyXMLSignatureResponseParser( +				domVerifyXMLSignatureResponse).parseData(); + +		return verifyXMLSignatureResponse.getX509certificate(); + +	} + +	/** +	 * Processes an <code><CreateXMLSignatureResponse></code> sent by the +	 * security layer implementation.<br> +	 * <ul> +	 * <li>Validates given <code><CreateXMLSignatureResponse></code></li> +	 * <li>Parses response enclosed in +	 * <code><CreateXMLSignatureResponse></code></li> +	 * <li>Verifies signature by calling the MOA SP component</li> +	 * <li>Returns the signer certificate</li> +	 * </ul> +	 * +	 * @param sessionID                     ID of associated authentication session data +	 * @param readInfoboxResponseParameters The parameters from the response returned from the BKU +	 *                                      including the <code><ReadInfoboxResponse></code> +	 * @throws BKUException +	 */ +	public X509Certificate getCertificate(String sessionID, +			Map<String, String> readInfoboxResponseParameters) throws AuthenticationException, +			BuildException, ParseException, ConfigurationException, +			ValidateException, ServiceException, BKUException { + +		if (isEmpty(sessionID)) +			throw new AuthenticationException("auth.10", new Object[]{ +					REQ_VERIFY_CERTIFICATE, PARAM_SESSIONID}); + +		String xmlReadInfoboxResponse = (String) readInfoboxResponseParameters +				.get(PARAM_XMLRESPONSE); + +		if (isEmpty(xmlReadInfoboxResponse)) +			throw new AuthenticationException("auth.10", new Object[]{ +					REQ_VERIFY_CERTIFICATE, PARAM_XMLRESPONSE}); + +		// parses the <CreateXMLSignatureResponse> +		InfoboxReadResponseParser p = new InfoboxReadResponseParser( +				xmlReadInfoboxResponse); +		X509Certificate cert = p.parseCertificate(); + +		return cert; + +	} + +	/** +	 * Builds an authentication block <code><saml:Assertion></code> from +	 * given session data. +	 * +	 * @param session authentication session +	 * @return <code><saml:Assertion></code> as a String +	 * @throws BuildException If an error occurs on serializing an extended SAML attribute +	 *                        to be appended to the AUTH-Block. +	 */ +	private String buildAuthenticationBlock(AuthenticationSession session, +			OAAuthParameter oaParam) throws BuildException { + +		IdentityLink identityLink = session.getIdentityLink(); +		String issuer = identityLink.getName(); +		String gebDat = identityLink.getDateOfBirth(); + +		String identificationValue = null; +		String identificationType = null; + +		//set empty AuthBlock BPK in case of OW or SSO or bpk is not requested +		if (session.isOW() || session.isSsoRequested() || oaParam.isRemovePBKFromAuthBlock()) { +			identificationType = ""; +			identificationValue = ""; + +		} else if (identityLink.getIdentificationType().equals(Constants.URN_PREFIX_BASEID)) { + +			if (oaParam.getBusinessService()) { + +				String bpkBase64 = new BPKBuilder().buildWBPK(identityLink +						.getIdentificationValue(), oaParam.getIdentityLinkDomainIdentifier()); +				identificationValue = bpkBase64; + +				if (oaParam.getIdentityLinkDomainIdentifier().startsWith(Constants.URN_PREFIX_WBPK + "+")) +					identificationType = oaParam.getIdentityLinkDomainIdentifier(); +				else +					identificationType = Constants.URN_PREFIX_WBPK + "+" + oaParam.getIdentityLinkDomainIdentifier(); + +			} else { +				String bpkBase64 = new BPKBuilder().buildBPK(identityLink +						.getIdentificationValue(), session.getTarget()); +				identificationValue = bpkBase64; +				identificationType = Constants.URN_PREFIX_CDID + "+" + session.getTarget(); +			} + + +		} else { +			identificationValue = identityLink.getIdentificationValue(); +			identificationType = identityLink.getIdentificationType(); + +		} + +		String issueInstant = DateTimeUtils.buildDateTimeUTC(Calendar +				.getInstance()); +		session.setIssueInstant(issueInstant); +		String authURL = session.getAuthURL(); +		String target = session.getTarget(); +		String targetFriendlyName = session.getTargetFriendlyName(); + +		// Bug #485 +		// (https://egovlabs.gv.at/tracker/index.php?func=detail&aid=485&group_id=6&atid=105) +		// String oaURL = session.getPublicOAURLPrefix(); + +		List<ExtendedSAMLAttribute> extendedSAMLAttributes = session.getExtendedSAMLAttributesAUTH(); + + +		if (session.isSsoRequested()) { +			String oaURL = new String(); +			try { +				oaURL = AuthConfigurationProvider.getInstance().getPublicURLPrefix(); + +				if (MiscUtil.isNotEmpty(oaURL)) +					oaURL = oaURL.replaceAll("&", "&"); + +			} catch (ConfigurationException e) { +			} +			String authBlock = new AuthenticationBlockAssertionBuilder() +			.buildAuthBlockSSO(issuer, issueInstant, authURL, target, +					targetFriendlyName, identificationValue, +					identificationType, oaURL, gebDat, +					extendedSAMLAttributes, session, oaParam); +			return authBlock; + +		} else { +			String oaURL = session.getPublicOAURLPrefix().replaceAll("&", "&"); +			String authBlock = new AuthenticationBlockAssertionBuilder() +			.buildAuthBlock(issuer, issueInstant, authURL, target, +					targetFriendlyName, identificationValue, +					identificationType, oaURL, gebDat, +					extendedSAMLAttributes, session, oaParam); +			return authBlock; +		} +	} + + +	/** +	 * Verifies the infoboxes (except of the identity link infobox) returned by +	 * the BKU by calling appropriate validator classes. +	 * +	 * @param session The actual authentication session. +	 * @param mandate The Mandate from the MIS +	 * @throws AuthenticationException +	 * @throws ConfigurationException +	 * @throws TransformerException +	 * @throws ParserConfigurationException +	 * @throws IOException +	 * @throws SAXException +	 */ +	private void validateExtendedSAMLAttributeForMandates( +			AuthenticationSession session, MISMandate mandate, +			boolean business) +					throws ValidateException, ConfigurationException, SAXException, +					IOException, ParserConfigurationException, TransformerException { + +		ExtendedSAMLAttribute[] extendedSAMLAttributes = addExtendedSamlAttributes( +				mandate, business, false); + +		int length = extendedSAMLAttributes.length; +		for (int i = 0; i < length; i++) { +			ExtendedSAMLAttribute samlAttribute = extendedSAMLAttributes[i]; + +			verifySAMLAttribute(samlAttribute, i, "MISService", +					"MISService"); + +		} +	} + +	/** +	 * Verifies the infoboxes (except of the identity link infobox) returned by +	 * the BKU by calling appropriate validator classes. +	 * +	 * @param session The actual authentication session. +	 * @param mandate The Mandate from the MIS +	 * @throws AuthenticationException +	 * @throws ConfigurationException +	 * @throws TransformerException +	 * @throws ParserConfigurationException +	 * @throws IOException +	 * @throws SAXException +	 */ +	private void setExtendedSAMLAttributeForMandatesOID( +			AuthenticationSession session, MISMandate mandate, boolean business) +					throws ValidateException, ConfigurationException, SAXException, +					IOException, ParserConfigurationException, TransformerException { + +		ExtendedSAMLAttribute[] extendedSamlAttributes = addExtendedSamlAttributesOID( +				mandate, business); + +		AddAdditionalSAMLAttributes(session, extendedSamlAttributes, +				"MISService", "MISService"); + +	} + +	/** +	 * Adds given SAML Attributes to the current session. They will be appended +	 * to the final SAML Assertion or the AUTH block. If the attributes are +	 * already in the list, they will be replaced. +	 * +	 * @param session                The current session +	 * @param extendedSAMLAttributes The SAML attributes to add +	 * @param identifier             The infobox identifier for debug purposes +	 * @param friendlyNam            The friendly name of the infobox for debug purposes +	 */ +	private static void AddAdditionalSAMLAttributes( +			AuthenticationSession session, +			ExtendedSAMLAttribute[] extendedSAMLAttributes, String identifier, +			String friendlyName) throws ValidateException { +		if (extendedSAMLAttributes == null) +			return; +		List<ExtendedSAMLAttribute> oaAttributes = session.getExtendedSAMLAttributesOA(); +		if (oaAttributes == null) +			oaAttributes = new Vector<ExtendedSAMLAttribute>(); +		List<ExtendedSAMLAttribute> authAttributes = session.getExtendedSAMLAttributesAUTH(); +		if (authAttributes == null) +			authAttributes = new Vector<ExtendedSAMLAttribute>(); +		int length = extendedSAMLAttributes.length; +		for (int i = 0; i < length; i++) { +			ExtendedSAMLAttribute samlAttribute = extendedSAMLAttributes[i]; + +			Object value = verifySAMLAttribute(samlAttribute, i, identifier, +					friendlyName); + +			if ((value instanceof String) || (value instanceof Element)) { +				switch (samlAttribute.getAddToAUTHBlock()) { +				case ExtendedSAMLAttribute.ADD_TO_AUTHBLOCK_ONLY: +					replaceExtendedSAMLAttribute(authAttributes, samlAttribute); +					break; +				case ExtendedSAMLAttribute.ADD_TO_AUTHBLOCK: +					replaceExtendedSAMLAttribute(authAttributes, samlAttribute); +					replaceExtendedSAMLAttribute(oaAttributes, samlAttribute); +					break; +				case ExtendedSAMLAttribute.NOT_ADD_TO_AUTHBLOCK: +					replaceExtendedSAMLAttribute(oaAttributes, samlAttribute); +					break; +				default: +					Logger +					.info("Invalid return value from method \"getAddToAUTHBlock()\" (" +							+ samlAttribute.getAddToAUTHBlock() +							+ ") in SAML attribute number " +							+ (i + 1) +							+ " for infobox " + identifier); +									throw new ValidateException("validator.47", new Object[]{ +											friendlyName, String.valueOf((i + 1))}); +				} +			} else { +				Logger +				.info("The type of SAML-Attribute number " +						+ (i + 1) +						+ " returned from " +						+ identifier +						+ "-infobox validator is not valid. Must be either \"java.Lang.String\"" +						+ " or \"org.w3c.dom.Element\""); +				throw new ValidateException("validator.46", new Object[]{ +						identifier, String.valueOf((i + 1))}); +			} +		} +		session.setExtendedSAMLAttributesAUTH(authAttributes); +		session.setExtendedSAMLAttributesOA(oaAttributes); +	} + +	/** +	 * Adds the AUTH block related SAML attributes to the validation result. +	 * This is needed always before the AUTH block is to be signed, because the +	 * name of the mandator has to be set +	 * +	 * @throws ParserConfigurationException +	 * @throws IOException +	 * @throws SAXException +	 * @throws TransformerException +	 */ + +	protected static ExtendedSAMLAttribute[] addExtendedSamlAttributes( +			MISMandate mandate, boolean business, boolean provideStammzahl) +					throws SAXException, IOException, ParserConfigurationException, +					TransformerException { +		Vector<ExtendedSAMLAttribute> extendedSamlAttributes = new Vector<ExtendedSAMLAttribute>(); + +		extendedSamlAttributes.clear(); + +		// Name +		Element domMandate = mandateToElement(mandate); +		Element nameSpaceNode = domMandate.getOwnerDocument().createElement( +				"NameSpaceNode"); +		nameSpaceNode.setAttribute("xmlns" + SZRGWConstants.PD_POSTFIX, +				Constants.PD_NS_URI); +		nameSpaceNode.setAttribute("xmlns" + SZRGWConstants.MANDATE_POSTFIX, +				SZRGWConstants.MANDATE_NS); + +		Element mandator = (Element) XPathAPI.selectSingleNode(domMandate, +				"//md:Mandate/md:Mandator", nameSpaceNode); + +		// Mandate +		extendedSamlAttributes.add(new ExtendedSAMLAttributeImpl( +				EXT_SAML_MANDATE_RAW, domMandate, +				SZRGWConstants.MANDATE_NS, +				ExtendedSAMLAttribute.NOT_ADD_TO_AUTHBLOCK)); + +		// (w)bpk +		String wbpk = ParepUtils.extractMandatorWbpk(mandator); +		if (!ParepUtils.isEmpty(wbpk)) { +			if (!ParepUtils.isPhysicalPerson(mandator)) { +				String idType = ParepUtils +						.extractMandatorIdentificationType(mandator); +				if (!ParepUtils.isEmpty(idType) +						&& idType.startsWith(Constants.URN_PREFIX_BASEID)) { +					extendedSamlAttributes.add(new ExtendedSAMLAttributeImpl( +							EXT_SAML_MANDATE_CB_BASE_ID, +							ParepUtils.getRegisterString(idType) + ": " + wbpk, +							SZRGWConstants.MANDATE_NS, +							ExtendedSAMLAttribute.ADD_TO_AUTHBLOCK_ONLY)); +				} +			} else if (business) { +				extendedSamlAttributes.add(new ExtendedSAMLAttributeImpl( +						EXT_SAML_MANDATE_WBPK, wbpk, +						SZRGWConstants.MANDATE_NS, +						ExtendedSAMLAttribute.ADD_TO_AUTHBLOCK_ONLY)); +			} +		} + +		ExtendedSAMLAttribute[] ret = new ExtendedSAMLAttribute[extendedSamlAttributes +		                                                        .size()]; +		extendedSamlAttributes.copyInto(ret); +		Logger.debug("ExtendedSAML Attributes: " + ret.length); +		return ret; + +	} + +	/** +	 * Adds the AUTH block related SAML attributes to the validation result. +	 * This is needed always before the AUTH block is to be signed, because the +	 * name of the mandator has to be set +	 * +	 * @throws ParserConfigurationException +	 * @throws IOException +	 * @throws SAXException +	 * @throws TransformerException +	 */ +	private static ExtendedSAMLAttribute[] addExtendedSamlAttributesOID( +			MISMandate mandate, boolean business) throws SAXException, +			IOException, ParserConfigurationException, TransformerException { + +		Vector<ExtendedSAMLAttribute> extendedSamlAttributes = new Vector<ExtendedSAMLAttribute>(); + +		extendedSamlAttributes.clear(); + +		// RepresentationType +		extendedSamlAttributes.add(new ExtendedSAMLAttributeImpl( +				EXT_SAML_MANDATE_REPRESENTATIONTYPE, +				EXT_SAML_MANDATE_REPRESENTATIONTEXT, +				SZRGWConstants.MANDATE_NS, +				ExtendedSAMLAttribute.NOT_ADD_TO_AUTHBLOCK)); + +		String oid = mandate.getProfRep(); + +		if (oid != null) { +			extendedSamlAttributes.add(new ExtendedSAMLAttributeImpl( +					EXT_SAML_MANDATE_OID, oid, +					SZRGWConstants.MANDATE_NS, +					ExtendedSAMLAttribute.NOT_ADD_TO_AUTHBLOCK)); +			String oidDescription = mandate.getTextualDescriptionOfOID(); +			extendedSamlAttributes.add(new ExtendedSAMLAttributeImpl( +					EXT_SAML_MANDATE_OIDTEXTUALDESCRIPTION, +					oidDescription, SZRGWConstants.MANDATE_NS, +					ExtendedSAMLAttribute.NOT_ADD_TO_AUTHBLOCK)); + +		} + +		ExtendedSAMLAttribute[] ret = new ExtendedSAMLAttribute[extendedSamlAttributes +		                                                        .size()]; +		extendedSamlAttributes.copyInto(ret); +		Logger.debug("ExtendedSAML Attributes: " + ret.length); +		return ret; + +	} + +	/** +	 * @param mandate +	 * @return +	 * @throws ParserConfigurationException +	 * @throws IOException +	 * @throws SAXException +	 */ +	private static Element mandateToElement(MISMandate mandate) +			throws SAXException, IOException, ParserConfigurationException { +		ByteArrayInputStream bais = new ByteArrayInputStream(mandate +				.getMandate()); +		Document doc = DOMUtils.parseDocumentSimple(bais); +		return doc.getDocumentElement(); +	} + +	protected static void replaceExtendedSAMLAttribute(List<ExtendedSAMLAttribute> attributes, +			ExtendedSAMLAttribute samlAttribute) { +		if (null == attributes) { +			attributes = new Vector<ExtendedSAMLAttribute>(); +		} else { +			String id = samlAttribute.getName(); +			int length = attributes.size(); +			for (int i = 0; i < length; i++) { +				ExtendedSAMLAttribute att = (ExtendedSAMLAttribute) attributes +						.get(i); +				if (id.equals(att.getName())) { +					// replace attribute +					attributes.set(i, samlAttribute); +					return; +				} +			} +			attributes.add(samlAttribute); +		} +	} + +	/** +	 * Processes a <code><CreateXMLSignatureResponse></code> sent by the +	 * security layer implementation.<br> +	 * <ul> +	 * <li>Validates given <code><CreateXMLSignatureResponse></code></li> +	 * <li>Parses <code><CreateXMLSignatureResponse></code> for error +	 * codes</li> +	 * <li>Parses authentication block enclosed in +	 * <code><CreateXMLSignatureResponse></code></li> +	 * <li>Verifies authentication block by calling the MOA SP component</li> +	 * <li>Creates authentication data</li> +	 * <li>Creates a corresponding SAML artifact</li> +	 * <li>Stores authentication data in the authentication data store indexed +	 * by the SAML artifact</li> +	 * <li>Deletes authentication session</li> +	 * <li>Returns the SAML artifact, encoded BASE64</li> +	 * </ul> +	 * +	 * @param sessionID                         session ID of the running authentication session +	 * @param xmlCreateXMLSignatureReadResponse String representation of the +	 *                                          <code><CreateXMLSignatureResponse></code> +	 * @return SAML artifact needed for retrieving authentication data, encoded +	 * BASE64 +	 * @throws BKUException +	 */ +	public String verifyAuthenticationBlock(AuthenticationSession session, +			String xmlCreateXMLSignatureReadResponse) +					throws AuthenticationException, BuildException, ParseException, +					ConfigurationException, ServiceException, ValidateException, BKUException { + +		if (session == null) +			throw new AuthenticationException("auth.10", new Object[]{ +					REQ_VERIFY_AUTH_BLOCK, PARAM_SESSIONID}); +		if (isEmpty(xmlCreateXMLSignatureReadResponse)) +			throw new AuthenticationException("auth.10", new Object[]{ +					REQ_VERIFY_AUTH_BLOCK, PARAM_XMLRESPONSE}); + +		AuthConfigurationProvider authConf = AuthConfigurationProvider +				.getInstance(); +		// parses <CreateXMLSignatureResponse> +		CreateXMLSignatureResponse csresp = new CreateXMLSignatureResponseParser( +				xmlCreateXMLSignatureReadResponse).parseResponse(); + +		try { +			String serializedAssertion = DOMUtils.serializeNode(csresp +					.getSamlAssertion()); +			session.setAuthBlock(serializedAssertion); +		} catch (TransformerException e) { +			throw new ParseException("parser.04", new Object[]{ +					REQ_VERIFY_AUTH_BLOCK, PARAM_XMLRESPONSE}); +		} catch (IOException e) { +			throw new ParseException("parser.04", new Object[]{ +					REQ_VERIFY_AUTH_BLOCK, PARAM_XMLRESPONSE}); +		} +		// validates <CreateXMLSignatureResponse> +		if (session.isSsoRequested()) +			new CreateXMLSignatureResponseValidator().validateSSO(csresp, session); +		else +			new CreateXMLSignatureResponseValidator().validate(csresp, session); + +		// builds a <VerifyXMLSignatureRequest> for a MOA-SPSS call +		List<String> vtids = authConf.getMoaSpAuthBlockVerifyTransformsInfoIDs(); +		String tpid = authConf.getMoaSpAuthBlockTrustProfileID(); +		Element domVsreq = new VerifyXMLSignatureRequestBuilder().build(csresp, +				vtids, tpid); +		// debug output + +		Element domVsresp = null; + +		//        try { +		// invokes the call +		domVsresp = new SignatureVerificationInvoker() +		.verifyXMLSignature(domVsreq); +		// debug output + +		//        } catch ( ServiceException e) { +		//        	Logger.error("Signature verification error. ", e); +		//        	Logger.error("Signed Data: " + session.getAuthBlock()); +		//        	try {        		 +		//				Logger.error("VerifyRequest: " + DOMUtils.serializeNode(domVsreq)); +		//			} catch (TransformerException e1) { +		//				e1.printStackTrace(); +		//				 +		//			} catch (IOException e1) { +		//				e1.printStackTrace(); +		//				 +		//			} +		//        	 +		//        	throw e;  +		//        } + + +		// parses the <VerifyXMLSignatureResponse> +		VerifyXMLSignatureResponse vsresp = new VerifyXMLSignatureResponseParser( +				domVsresp).parseData(); + +		if (Logger.isTraceEnabled()) { +			if (domVsresp != null) { +				try { +					String xmlVerifyXMLSignatureResponse = DOMUtils +							.serializeNode(domVsresp, true); +					Logger.trace(new LogMsg(xmlCreateXMLSignatureReadResponse)); +					Logger.trace(new LogMsg(xmlVerifyXMLSignatureResponse)); +				} catch (Throwable t) { +					t.printStackTrace(); +					Logger.info(new LogMsg(t.getStackTrace())); +				} +			} +		} + +		OAAuthParameter oaParam = AuthConfigurationProvider.getInstance() +				.getOnlineApplicationParameter(session.getPublicOAURLPrefix()); + +		// validates the <VerifyXMLSignatureResponse> +		VerifyXMLSignatureResponseValidator.getInstance().validate(vsresp, +				null, VerifyXMLSignatureResponseValidator.CHECK_AUTH_BLOCK, +				oaParam); + +		// Compare AuthBlock Data with information stored in session, especially +		// date and time +		CreateXMLSignatureResponseValidator.getInstance().validateSigningDateTime(csresp); + +		try {         +			// compares the public keys from the identityLink with the AuthBlock +			VerifyXMLSignatureResponseValidator.getInstance().validateCertificate( +					vsresp, session.getIdentityLink()); + +		} catch ( ValidateException e) { +			Logger.error("Signature verification error. ", e); +			Logger.error("Signed Data: " + session.getAuthBlock()); +			try {        		  				Logger.error("VerifyRequest: " + DOMUtils.serializeNode(domVsreq));  				Logger.error("VerifyResponse: " + DOMUtils.serializeNode(domVsresp));				  			} catch (TransformerException e1) {  				e1.printStackTrace(); -				 +  			} catch (IOException e1) {  				e1.printStackTrace(); -				 +  			} -        	 -        	throw e;  -        }        	 - -//        // post processing of the infoboxes -//        Iterator iter = session.getInfoboxValidatorIterator(); -//        boolean formpending = false; -//        if (iter != null) { -//            while (!formpending && iter.hasNext()) { -//                Vector infoboxValidatorVector = (Vector) iter.next(); -//                String identifier = (String) infoboxValidatorVector.get(0); -//                String friendlyName = (String) infoboxValidatorVector.get(1); -//                InfoboxValidator infoboxvalidator = (InfoboxValidator) infoboxValidatorVector -//                        .get(2); -//                InfoboxValidationResult infoboxValidationResult = null; -//                try { -//                    infoboxValidationResult = infoboxvalidator.validate(csresp -//                            .getSamlAssertion()); -//                } catch (ValidateException e) { -//                    Logger.error("Error validating " + identifier + " infobox:" -//                            + e.getMessage()); -//                    throw new ValidateException("validator.44", -//                            new Object[]{friendlyName}); -//                } -//                if (!infoboxValidationResult.isValid()) { -//                    Logger.info("Validation of " + identifier -//                            + " infobox failed."); -//                    throw new ValidateException("validator.40", new Object[]{ -//                            friendlyName, -//                            infoboxValidationResult.getErrorMessage()}); -//                } -//                String form = infoboxvalidator.getForm(); -//                if (ParepUtils.isEmpty(form)) { -//                    AddAdditionalSAMLAttributes( -//                            session, -//                            infoboxValidationResult.getExtendedSamlAttributes(), -//                            identifier, friendlyName); -//                } else { -//                    return "Redirect to Input Processor"; -//                } -//            } -//        } - -        session.setXMLVerifySignatureResponse(vsresp); -        session.setSignerCertificate(vsresp.getX509certificate()); -        vsresp.setX509certificate(null); -        session.setForeigner(false); - -        if (session.getUseMandate()) { -            // mandate mode -            return null; - -        } else { - -            session.setAuthenticatedUsed(false); -            session.setAuthenticated(true); - -            //set QAA Level four in case of card authentifcation -            session.setQAALevel(PVPConstants.STORK_QAA_1_4); - - -            String oldsessionID = session.getSessionID(); - -            //Session is implicte stored in changeSessionID!!! -            String newMOASessionID = AuthenticationSessionStoreage.changeSessionID(session); - -            Logger.info("Changed MOASession " + oldsessionID + " to Session " + newMOASessionID); -            Logger.info("Daten angelegt zu MOASession " + newMOASessionID); - -            return newMOASessionID; -        } -    } - -    /** -     * Processes a <code><CreateXMLSignatureResponse></code> sent by the -     * security layer implementation.<br> -     * <ul> -     * <li>Validates given <code><CreateXMLSignatureResponse></code></li> -     * <li>Parses <code><CreateXMLSignatureResponse></code> for error -     * codes</li> -     * <li>Parses authentication block enclosed in -     * <code><CreateXMLSignatureResponse></code></li> -     * <li>Verifies authentication block by calling the MOA SP component</li> -     * <li>Creates authentication data</li> -     * <li>Creates a corresponding SAML artifact</li> -     * <li>Stores authentication data in the authentication data store indexed -     * by the SAML artifact</li> -     * <li>Deletes authentication session</li> -     * <li>Returns the SAML artifact, encoded BASE64</li> -     * </ul> -     * -     * @param sessionID                         session ID of the running authentication session -     * @param xmlCreateXMLSignatureReadResponse String representation of the -     *                                          <code><CreateXMLSignatureResponse></code> -     * @return SAML artifact needed for retrieving authentication data, encoded -     * BASE64 -     */ - -    protected Element createIdentificationBPK(Element mandatePerson, -                                              String baseid, String target) throws BuildException { -        Element identificationBpK = mandatePerson.getOwnerDocument() -                .createElementNS(Constants.PD_NS_URI, "Identification"); -        Element valueBpK = mandatePerson.getOwnerDocument().createElementNS( -                Constants.PD_NS_URI, "Value"); - -        String bpkBase64 = new BPKBuilder().buildBPK(baseid, target); -        valueBpK.appendChild(mandatePerson.getOwnerDocument().createTextNode( -                bpkBase64)); -        Element typeBpK = mandatePerson.getOwnerDocument().createElementNS( -                Constants.PD_NS_URI, "Type"); -        typeBpK.appendChild(mandatePerson.getOwnerDocument().createTextNode( -                "urn:publicid:gv.at:cdid+bpk")); -        identificationBpK.appendChild(valueBpK); -        identificationBpK.appendChild(typeBpK); - -        return identificationBpK; - -    } - -    protected String getBaseId(Element mandatePerson) -            throws TransformerException, IOException { -        NodeList list = mandatePerson.getElementsByTagNameNS( -                Constants.PD_NS_URI, "Identification"); -        for (int i = 0; i < list.getLength(); i++) { -            Element identification = (Element) list.item(i); -            Element type = (Element) identification.getElementsByTagNameNS( -                    Constants.PD_NS_URI, "Type").item(0); -            if (type.getTextContent().compareToIgnoreCase( -                    "urn:publicid:gv.at:baseid") == 0) { -                Element value = (Element) identification -                        .getElementsByTagNameNS(Constants.PD_NS_URI, "Value") -                        .item(0); -                return value.getTextContent(); -            } -        } -        return null; - -    } - -    /** -     * Gets the foreign authentication data.<br> -     * <ul> -     * <li>Creates authentication data</li> -     * <li>Creates a corresponding SAML artifact</li> -     * <li>Stores authentication data in the authentication data store indexed -     * by the SAML artifact</li> -     * <li>Deletes authentication session</li> -     * <li>Returns the SAML artifact, encoded BASE64</li> -     * </ul> -     * -     * @param sessionID session ID of the running authentication session -     * @return SAML artifact needed for retrieving authentication data, encoded -     * BASE64 -     */ -    public String getForeignAuthenticationData(AuthenticationSession session) -            throws AuthenticationException, BuildException, ParseException, -            ConfigurationException, ServiceException, ValidateException { - -        if (session == null) -            throw new AuthenticationException("auth.10", new Object[]{ -                    REQ_VERIFY_AUTH_BLOCK, PARAM_SESSIONID}); - -//        // post processing of the infoboxes -//        Iterator iter = session.getInfoboxValidatorIterator(); -//        boolean formpending = false; -//        if (iter != null) { -//            while (!formpending && iter.hasNext()) { -//                Vector infoboxValidatorVector = (Vector) iter.next(); -//                String identifier = (String) infoboxValidatorVector.get(0); -//                String friendlyName = (String) infoboxValidatorVector.get(1); -//                InfoboxValidator infoboxvalidator = (InfoboxValidator) infoboxValidatorVector -//                        .get(2); -//                InfoboxValidationResult infoboxValidationResult = null; -//                try { -//                    infoboxValidationResult = infoboxvalidator.validate(session -//                            .getIdentityLink().getSamlAssertion()); -//                } catch (ValidateException e) { -//                    Logger.error("Error validating " + identifier + " infobox:" -//                            + e.getMessage()); -//                    throw new ValidateException("validator.44", -//                            new Object[]{friendlyName}); -//                } -//                if (!infoboxValidationResult.isValid()) { -//                    Logger.info("Validation of " + identifier -//                            + " infobox failed."); -//                    throw new ValidateException("validator.40", new Object[]{ -//                            friendlyName, -//                            infoboxValidationResult.getErrorMessage()}); -//                } -//                String form = infoboxvalidator.getForm(); -//                if (ParepUtils.isEmpty(form)) { -//                    AddAdditionalSAMLAttributes( -//                            session, -//                            infoboxValidationResult.getExtendedSamlAttributes(), -//                            identifier, friendlyName); -//                } else { -//                    return "Redirect to Input Processor"; -//                } -//            } -//        } - -        VerifyXMLSignatureResponse vsresp = new VerifyXMLSignatureResponse(); -        X509Certificate cert = session.getSignerCertificate(); -        vsresp.setX509certificate(cert); - -        session.setAuthenticatedUsed(false); -        session.setAuthenticated(true); - - -        session.setXMLVerifySignatureResponse(vsresp); -        session.setSignerCertificate(vsresp.getX509certificate()); -        vsresp.setX509certificate(null); -        session.setForeigner(true); - -        //TODO: regenerate MOASession ID! -        return "new Session"; -    } - -    /** -     * Retrieves a session from the session store. -     * -     * @param id session ID -     * @return <code>AuthenticationSession</code> stored with given session ID, -     * <code>null</code> if session ID unknown -     */ -    public static AuthenticationSession getSession(String id) -            throws AuthenticationException { -        AuthenticationSession session; -        try { -            session = AuthenticationSessionStoreage.getSession(id); - -            if (session == null) -                throw new AuthenticationException("auth.02", new Object[]{id}); -            return session; - -        } catch (MOADatabaseException e) { -        	throw new AuthenticationException("auth.02", new Object[]{id}); -             -        } catch (Exception e) { -        	throw new AuthenticationException("parser.04", new Object[]{id}); -        } -    } - -    /** -     * Cleans up expired session and authentication data stores. -     */ -    public void cleanup() { -        long now = new Date().getTime(); - -        //clean AuthenticationSessionStore - -        AuthenticationSessionStoreage.clean(now, sessionTimeOutCreated, sessionTimeOutUpdated); - -        //clean AssertionStore -        AssertionStorage assertionstore = AssertionStorage.getInstance(); -        assertionstore.clean(now, authDataTimeOut); - -        //clean ExeptionStore -        DBExceptionStoreImpl exstore = DBExceptionStoreImpl.getStore(); -        exstore.clean(now, authDataTimeOut); - -    } - -    /** -     * Sets the sessionTimeOut. -     * -     * @param seconds Time out of the session in seconds -     */ -    public void setSecondsSessionTimeOutCreated(long seconds) { -        sessionTimeOutCreated = seconds * 1000; -    } - -    public void setSecondsSessionTimeOutUpdated(long seconds) { -        sessionTimeOutUpdated = seconds * 1000; -    } - -    /** -     * Sets the authDataTimeOut. -     * -     * @param seconds Time out for signing AuthData in seconds -     */ -    public void setSecondsAuthDataTimeOut(long seconds) { -        authDataTimeOut = seconds * 1000; -    } - -    /** -     * Checks a parameter. -     * -     * @param param parameter -     * @return true if the parameter is null or empty -     */ -    private boolean isEmpty(String param) { -        return param == null || param.length() == 0; -    } - -    /** -     * Checks the correctness of SAML attributes and returns its value. -     * -     * @param param        samlAttribute -     * @param i            the number of the verified attribute for messages -     * @param identifier   the infobox identifier for messages -     * @param friendlyname the friendly name of the infobox for messages -     * @return the SAML attribute value (Element or String) -     */ -    protected static Object verifySAMLAttribute( -            ExtendedSAMLAttribute samlAttribute, int i, String identifier, -            String friendlyName) throws ValidateException { -        String name = samlAttribute.getName(); - -        if (name == null) { -            Logger.info("The name of SAML-Attribute number " + (i + 1) -                    + " returned from " + identifier -                    + "-infobox validator is null."); -            throw new ValidateException("validator.45", new Object[]{ -                    friendlyName, "Name", String.valueOf((i + 1)), "null"}); -        } -        if (name == "") { -            Logger.info("The name of SAML-Attribute number " + (i + 1) -                    + " returned from " + identifier -                    + "-infobox validator is empty."); -            throw new ValidateException("validator.45", new Object[]{ -                    friendlyName, "Name", String.valueOf((i + 1)), "leer"}); -        } -        if (samlAttribute.getNameSpace() == null) { -            Logger.info("The namespace of SAML-Attribute number " + (i + 1) -                    + " returned from " + identifier -                    + "-infobox validator is null."); -            throw new ValidateException("validator.45", -                    new Object[]{friendlyName, "Namespace", -                            String.valueOf((i + 1)), "null"}); -        } -        Object value = samlAttribute.getValue(); -        if (value == null) { -            Logger.info("The value of SAML-Attribute number " + (i + 1) -                    + " returned from " + identifier -                    + "-infobox validator is null."); -            throw new ValidateException("validator.45", new Object[]{ -                    friendlyName, "Wert", String.valueOf((i + 1)), "null"}); -        } -         -        return value; -    } -	 + +			throw e;  +		}        	 + +		//        // post processing of the infoboxes +		//        Iterator iter = session.getInfoboxValidatorIterator(); +		//        boolean formpending = false; +		//        if (iter != null) { +		//            while (!formpending && iter.hasNext()) { +		//                Vector infoboxValidatorVector = (Vector) iter.next(); +		//                String identifier = (String) infoboxValidatorVector.get(0); +		//                String friendlyName = (String) infoboxValidatorVector.get(1); +		//                InfoboxValidator infoboxvalidator = (InfoboxValidator) infoboxValidatorVector +		//                        .get(2); +		//                InfoboxValidationResult infoboxValidationResult = null; +		//                try { +		//                    infoboxValidationResult = infoboxvalidator.validate(csresp +		//                            .getSamlAssertion()); +		//                } catch (ValidateException e) { +		//                    Logger.error("Error validating " + identifier + " infobox:" +		//                            + e.getMessage()); +		//                    throw new ValidateException("validator.44", +		//                            new Object[]{friendlyName}); +		//                } +		//                if (!infoboxValidationResult.isValid()) { +		//                    Logger.info("Validation of " + identifier +		//                            + " infobox failed."); +		//                    throw new ValidateException("validator.40", new Object[]{ +		//                            friendlyName, +		//                            infoboxValidationResult.getErrorMessage()}); +		//                } +		//                String form = infoboxvalidator.getForm(); +		//                if (ParepUtils.isEmpty(form)) { +		//                    AddAdditionalSAMLAttributes( +		//                            session, +		//                            infoboxValidationResult.getExtendedSamlAttributes(), +		//                            identifier, friendlyName); +		//                } else { +		//                    return "Redirect to Input Processor"; +		//                } +		//            } +		//        } + +		session.setXMLVerifySignatureResponse(vsresp); +		session.setSignerCertificate(vsresp.getX509certificate()); +		vsresp.setX509certificate(null); +		session.setForeigner(false); + +		if (session.getUseMandate()) { +			// mandate mode +			return null; + +		} else { + +			session.setAuthenticatedUsed(false); +			session.setAuthenticated(true); + +			//set QAA Level four in case of card authentifcation +			session.setQAALevel(PVPConstants.STORK_QAA_1_4); + + +			String oldsessionID = session.getSessionID(); + +			//Session is implicte stored in changeSessionID!!! +			String newMOASessionID = AuthenticationSessionStoreage.changeSessionID(session); + +			Logger.info("Changed MOASession " + oldsessionID + " to Session " + newMOASessionID); +			Logger.info("Daten angelegt zu MOASession " + newMOASessionID); + +			return newMOASessionID; +		} +	} + +	/** +	 * Processes a <code><CreateXMLSignatureResponse></code> sent by the +	 * security layer implementation.<br> +	 * <ul> +	 * <li>Validates given <code><CreateXMLSignatureResponse></code></li> +	 * <li>Parses <code><CreateXMLSignatureResponse></code> for error +	 * codes</li> +	 * <li>Parses authentication block enclosed in +	 * <code><CreateXMLSignatureResponse></code></li> +	 * <li>Verifies authentication block by calling the MOA SP component</li> +	 * <li>Creates authentication data</li> +	 * <li>Creates a corresponding SAML artifact</li> +	 * <li>Stores authentication data in the authentication data store indexed +	 * by the SAML artifact</li> +	 * <li>Deletes authentication session</li> +	 * <li>Returns the SAML artifact, encoded BASE64</li> +	 * </ul> +	 * +	 * @param sessionID                         session ID of the running authentication session +	 * @param xmlCreateXMLSignatureReadResponse String representation of the +	 *                                          <code><CreateXMLSignatureResponse></code> +	 * @return SAML artifact needed for retrieving authentication data, encoded +	 * BASE64 +	 */ + +	protected Element createIdentificationBPK(Element mandatePerson, +			String baseid, String target) throws BuildException { +		Element identificationBpK = mandatePerson.getOwnerDocument() +				.createElementNS(Constants.PD_NS_URI, "Identification"); +		Element valueBpK = mandatePerson.getOwnerDocument().createElementNS( +				Constants.PD_NS_URI, "Value"); + +		String bpkBase64 = new BPKBuilder().buildBPK(baseid, target); +		valueBpK.appendChild(mandatePerson.getOwnerDocument().createTextNode( +				bpkBase64)); +		Element typeBpK = mandatePerson.getOwnerDocument().createElementNS( +				Constants.PD_NS_URI, "Type"); +		typeBpK.appendChild(mandatePerson.getOwnerDocument().createTextNode( +				"urn:publicid:gv.at:cdid+bpk")); +		identificationBpK.appendChild(valueBpK); +		identificationBpK.appendChild(typeBpK); + +		return identificationBpK; + +	} + +	protected String getBaseId(Element mandatePerson) +			throws TransformerException, IOException { +		NodeList list = mandatePerson.getElementsByTagNameNS( +				Constants.PD_NS_URI, "Identification"); +		for (int i = 0; i < list.getLength(); i++) { +			Element identification = (Element) list.item(i); +			Element type = (Element) identification.getElementsByTagNameNS( +					Constants.PD_NS_URI, "Type").item(0); +			if (type.getTextContent().compareToIgnoreCase( +					"urn:publicid:gv.at:baseid") == 0) { +				Element value = (Element) identification +						.getElementsByTagNameNS(Constants.PD_NS_URI, "Value") +						.item(0); +				return value.getTextContent(); +			} +		} +		return null; + +	} + +	/** +	 * Gets the foreign authentication data.<br> +	 * <ul> +	 * <li>Creates authentication data</li> +	 * <li>Creates a corresponding SAML artifact</li> +	 * <li>Stores authentication data in the authentication data store indexed +	 * by the SAML artifact</li> +	 * <li>Deletes authentication session</li> +	 * <li>Returns the SAML artifact, encoded BASE64</li> +	 * </ul> +	 * +	 * @param sessionID session ID of the running authentication session +	 * @return SAML artifact needed for retrieving authentication data, encoded +	 * BASE64 +	 */ +	public String getForeignAuthenticationData(AuthenticationSession session) +			throws AuthenticationException, BuildException, ParseException, +			ConfigurationException, ServiceException, ValidateException { + +		if (session == null) +			throw new AuthenticationException("auth.10", new Object[]{ +					REQ_VERIFY_AUTH_BLOCK, PARAM_SESSIONID}); + +		//        // post processing of the infoboxes +		//        Iterator iter = session.getInfoboxValidatorIterator(); +		//        boolean formpending = false; +		//        if (iter != null) { +		//            while (!formpending && iter.hasNext()) { +		//                Vector infoboxValidatorVector = (Vector) iter.next(); +		//                String identifier = (String) infoboxValidatorVector.get(0); +		//                String friendlyName = (String) infoboxValidatorVector.get(1); +		//                InfoboxValidator infoboxvalidator = (InfoboxValidator) infoboxValidatorVector +		//                        .get(2); +		//                InfoboxValidationResult infoboxValidationResult = null; +		//                try { +		//                    infoboxValidationResult = infoboxvalidator.validate(session +		//                            .getIdentityLink().getSamlAssertion()); +		//                } catch (ValidateException e) { +		//                    Logger.error("Error validating " + identifier + " infobox:" +		//                            + e.getMessage()); +		//                    throw new ValidateException("validator.44", +		//                            new Object[]{friendlyName}); +		//                } +		//                if (!infoboxValidationResult.isValid()) { +		//                    Logger.info("Validation of " + identifier +		//                            + " infobox failed."); +		//                    throw new ValidateException("validator.40", new Object[]{ +		//                            friendlyName, +		//                            infoboxValidationResult.getErrorMessage()}); +		//                } +		//                String form = infoboxvalidator.getForm(); +		//                if (ParepUtils.isEmpty(form)) { +		//                    AddAdditionalSAMLAttributes( +		//                            session, +		//                            infoboxValidationResult.getExtendedSamlAttributes(), +		//                            identifier, friendlyName); +		//                } else { +		//                    return "Redirect to Input Processor"; +		//                } +		//            } +		//        } + +		VerifyXMLSignatureResponse vsresp = new VerifyXMLSignatureResponse(); +		X509Certificate cert = session.getSignerCertificate(); +		vsresp.setX509certificate(cert); + +		session.setAuthenticatedUsed(false); +		session.setAuthenticated(true); + + +		session.setXMLVerifySignatureResponse(vsresp); +		session.setSignerCertificate(vsresp.getX509certificate()); +		vsresp.setX509certificate(null); +		session.setForeigner(true); + +		//TODO: regenerate MOASession ID! +		return "new Session"; +	} + +	/** +	 * Retrieves a session from the session store. +	 * +	 * @param id session ID +	 * @return <code>AuthenticationSession</code> stored with given session ID, +	 * <code>null</code> if session ID unknown +	 */ +	public static AuthenticationSession getSession(String id) +			throws AuthenticationException { +		AuthenticationSession session; +		try { +			session = AuthenticationSessionStoreage.getSession(id); + +			if (session == null) +				throw new AuthenticationException("auth.02", new Object[]{id}); +			return session; + +		} catch (MOADatabaseException e) { +			throw new AuthenticationException("auth.02", new Object[]{id}); + +		} catch (Exception e) { +			throw new AuthenticationException("parser.04", new Object[]{id}); +		} +	} + +	/** +	 * Cleans up expired session and authentication data stores. +	 */ +	public void cleanup() { +		long now = new Date().getTime(); + +		//clean AuthenticationSessionStore + +		AuthenticationSessionStoreage.clean(now, sessionTimeOutCreated, sessionTimeOutUpdated); + +		//clean AssertionStore +		AssertionStorage assertionstore = AssertionStorage.getInstance(); +		assertionstore.clean(now, authDataTimeOut); + +		//clean ExeptionStore +		DBExceptionStoreImpl exstore = DBExceptionStoreImpl.getStore(); +		exstore.clean(now, authDataTimeOut); + +	} + +	/** +	 * Sets the sessionTimeOut. +	 * +	 * @param seconds Time out of the session in seconds +	 */ +	public void setSecondsSessionTimeOutCreated(long seconds) { +		sessionTimeOutCreated = seconds * 1000; +	} + +	public void setSecondsSessionTimeOutUpdated(long seconds) { +		sessionTimeOutUpdated = seconds * 1000; +	} + +	/** +	 * Sets the authDataTimeOut. +	 * +	 * @param seconds Time out for signing AuthData in seconds +	 */ +	public void setSecondsAuthDataTimeOut(long seconds) { +		authDataTimeOut = seconds * 1000; +	} + +	/** +	 * Checks a parameter. +	 * +	 * @param param parameter +	 * @return true if the parameter is null or empty +	 */ +	private boolean isEmpty(String param) { +		return param == null || param.length() == 0; +	} + +	/** +	 * Checks the correctness of SAML attributes and returns its value. +	 * +	 * @param param        samlAttribute +	 * @param i            the number of the verified attribute for messages +	 * @param identifier   the infobox identifier for messages +	 * @param friendlyname the friendly name of the infobox for messages +	 * @return the SAML attribute value (Element or String) +	 */ +	protected static Object verifySAMLAttribute( +			ExtendedSAMLAttribute samlAttribute, int i, String identifier, +			String friendlyName) throws ValidateException { +		String name = samlAttribute.getName(); + +		if (name == null) { +			Logger.info("The name of SAML-Attribute number " + (i + 1) +					+ " returned from " + identifier +					+ "-infobox validator is null."); +			throw new ValidateException("validator.45", new Object[]{ +					friendlyName, "Name", String.valueOf((i + 1)), "null"}); +		} +		if (name == "") { +			Logger.info("The name of SAML-Attribute number " + (i + 1) +					+ " returned from " + identifier +					+ "-infobox validator is empty."); +			throw new ValidateException("validator.45", new Object[]{ +					friendlyName, "Name", String.valueOf((i + 1)), "leer"}); +		} +		if (samlAttribute.getNameSpace() == null) { +			Logger.info("The namespace of SAML-Attribute number " + (i + 1) +					+ " returned from " + identifier +					+ "-infobox validator is null."); +			throw new ValidateException("validator.45", +					new Object[]{friendlyName, "Namespace", +					String.valueOf((i + 1)), "null"}); +		} +		Object value = samlAttribute.getValue(); +		if (value == null) { +			Logger.info("The value of SAML-Attribute number " + (i + 1) +					+ " returned from " + identifier +					+ "-infobox validator is null."); +			throw new ValidateException("validator.45", new Object[]{ +					friendlyName, "Wert", String.valueOf((i + 1)), "null"}); +		} + +		return value; +	} +  	/**  	 * Does the request to the SZR-GW.  	 * @@ -1595,7 +1595,7 @@ public class AuthenticationServer implements MOAIDAuthConstants {  	public CreateIdentityLinkResponse getIdentityLink(Element signature) throws SZRGWClientException, ConfigurationException {  		return getIdentityLink(null, null, null, null, XMLHelper.nodeToString(signature), null);  	} -     +  	/**  	 * Does the request to the SZR-GW.  	 * @@ -1611,396 +1611,400 @@ public class AuthenticationServer implements MOAIDAuthConstants {  	public CreateIdentityLinkResponse getIdentityLink(String PEPSIdentifier, String PEPSFirstname, String PEPSFamilyname, String PEPSDateOfBirth, String signature, String PEPSFiscalNumber) throws SZRGWClientException {  		return getIdentityLink(PEPSIdentifier, PEPSFirstname, PEPSFamilyname, PEPSDateOfBirth, null, signature, null, null, null, null, null, null, null, PEPSFiscalNumber);  	} -	 - 	/** -	  * SZR-GW Client interface. -	  * -	  * @param eIdentifier the e identifier -	  * @param givenName the given name -	  * @param lastName the last name -	  * @param dateOfBirth the date of birth -	  * @param citizenSignature the citizen signature -	  * @param representative the representative -	  * @param represented the represented -	  * @param mandate the mandate -	  * @return the identity link -	  * @throws SZRGWClientException the sZRGW client exception -	  */ -	 public CreateIdentityLinkResponse getIdentityLink(String eIdentifier, - 			String givenName, String lastName, String dateOfBirth, String gender, - 			String citizenSignature, String representative, String represented, - 			String mandate, String targetType, String targetValue, String oaFriendlyName, List<String> filters, String PEPSFiscalNumber) throws SZRGWClientException { - 		return getIdentityLink(eIdentifier, givenName, lastName, dateOfBirth, gender, - 				citizenSignature, representative, represented, mandate, null, - 				null, targetType, targetValue, oaFriendlyName, filters, PEPSFiscalNumber); - 	} -	 -		/** -		 * Gets the identity link. -		 * -		 * @param citizenSignature the citizen signature -		 * @param representative the representative -		 * @param represented the represented -		 * @param mandate the mandate -		 * @param organizationAddress the organization address -		 * @param organizationType the organization type -		 * @return the identity link -		 * @throws SZRGWClientException  -		 */ -		public CreateIdentityLinkResponse getIdentityLink(String citizenSignature, -				String representative, String represented, String mandateContent, -				String organizationAddress, String organizationType, String targetType, String targetValue, String oaFriendlyName, List<String> filters, String PEPSFiscalNumber) throws SZRGWClientException { -			return getIdentityLink(null, null, null, null, null, -					citizenSignature, represented, representative, mandateContent, organizationAddress, -					organizationType, targetType, targetValue, oaFriendlyName, filters, PEPSFiscalNumber); -		}	  -	  -    public CreateIdentityLinkResponse getIdentityLink(String PEPSIdentifier, String PEPSFirstname, String PEPSFamilyname, String PEPSDateOfBirth, String gender, String citizenSignature, String represented, String representative, String mandateContent, String organizationAddress, String organizationType, String targetType, String targetValue, String oaFriendlyName, List<String> filters, String PEPSFiscalNumber) throws SZRGWClientException { + +	/** +	 * SZR-GW Client interface. +	 * +	 * @param eIdentifier the e identifier +	 * @param givenName the given name +	 * @param lastName the last name +	 * @param dateOfBirth the date of birth +	 * @param citizenSignature the citizen signature +	 * @param representative the representative +	 * @param represented the represented +	 * @param mandate the mandate +	 * @return the identity link +	 * @throws SZRGWClientException the sZRGW client exception +	 */ +	public CreateIdentityLinkResponse getIdentityLink(String eIdentifier, +			String givenName, String lastName, String dateOfBirth, String gender, +			String citizenSignature, String representative, String represented, +			String mandate, String targetType, String targetValue, String oaFriendlyName, List<String> filters, String PEPSFiscalNumber) throws SZRGWClientException { +		return getIdentityLink(eIdentifier, givenName, lastName, dateOfBirth, gender, +				citizenSignature, representative, represented, mandate, null, +				null, targetType, targetValue, oaFriendlyName, filters, PEPSFiscalNumber); +	} + +	/** +	 * Gets the identity link. +	 * +	 * @param citizenSignature the citizen signature +	 * @param representative the representative +	 * @param represented the represented +	 * @param mandate the mandate +	 * @param organizationAddress the organization address +	 * @param organizationType the organization type +	 * @return the identity link +	 * @throws SZRGWClientException  +	 */ +	public CreateIdentityLinkResponse getIdentityLink(String citizenSignature, +			String representative, String represented, String mandateContent, +			String organizationAddress, String organizationType, String targetType, String targetValue, String oaFriendlyName, List<String> filters, String PEPSFiscalNumber) throws SZRGWClientException { +		return getIdentityLink(null, null, null, null, null, +				citizenSignature, represented, representative, mandateContent, organizationAddress, +				organizationType, targetType, targetValue, oaFriendlyName, filters, PEPSFiscalNumber); +	}	  + +	public CreateIdentityLinkResponse getIdentityLink(String PEPSIdentifier, String PEPSFirstname, String PEPSFamilyname, String PEPSDateOfBirth, String gender, String citizenSignature, String represented, String representative, String mandateContent, String organizationAddress, String organizationType, String targetType, String targetValue, String oaFriendlyName, List<String> filters, String PEPSFiscalNumber) throws SZRGWClientException {  		try { -	    	AuthConfigurationProvider authConf = AuthConfigurationProvider.getInstance(); -	    	ConnectionParameter connectionParameters = authConf.getForeignIDConnectionParameter(); - -	    	SZRGWClient client = new SZRGWClient(connectionParameters); -	    	 	    	 -	    	CreateIdentityLinkRequest request = new CreateIdentityLinkRequest(); -	    	request.setSignature(citizenSignature.getBytes("UTF-8")); -	 -            PEPSData data = new PEPSData(); -            data.setDateOfBirth(PEPSDateOfBirth); -            data.setFamilyname(PEPSFamilyname); -            data.setFirstname(PEPSFirstname); -            data.setIdentifier(PEPSIdentifier); - -            data.setRepresentative(representative); -            data.setRepresented(represented); -            data.setMandateContent(mandateContent); - -            data.setLegalPersonCanonicalRegisteredAddress(organizationAddress); -            data.setLegalPersonTranslatableType(organizationType); - -            if (null != mandateContent) { -                MISType mis = new MISType(); - -                Target targetObject = new Target(); -                targetObject.setType(targetType); -                targetObject.setValue(targetValue); -                mis.setTarget(targetObject); - -                mis.setOAFriendlyName(oaFriendlyName); - -                Filters filterObject = new Filters(); -                MandateIdentifiers mandateIds = new MandateIdentifiers(); -		        for(String current : filters) -		        	mandateIds.getMandateIdentifier().add(current.trim()); -		    	filterObject.setMandateIdentifiers(mandateIds); -		    	mis.setFilters(filterObject); - -                request.setMIS(mis); -            } - -            if (MiscUtil.isEmpty(connectionParameters.getUrl())) { -            	Logger.warn("SZR-Gateway Service URL is empty"); -            	throw new SZRGWClientException("service.07"); -            } -             -            Logger.info("Starte Kommunikation mit dem Stammzahlenregister Gateway(" + connectionParameters.getUrl() + ")..."); -            CreateIdentityLinkResponse response = client.sentCreateIDLRequest(request, connectionParameters.getUrl()); -            return response; -             -	    } -	    catch (ConfigurationException e) { -	    	Logger.warn(e); -	    	Logger.warn(MOAIDMessageProvider.getInstance().getMessage("config.12", null )); +			AuthConfigurationProvider authConf = AuthConfigurationProvider.getInstance(); +			ConnectionParameter connectionParameters = authConf.getForeignIDConnectionParameter(); + +			SZRGWClient client = new SZRGWClient(connectionParameters); + +			CreateIdentityLinkRequest request = new CreateIdentityLinkRequest(); +			request.setSignature(citizenSignature.getBytes("UTF-8")); + +			if(PEPSDateOfBirth!=null || PEPSFamilyname!=null || PEPSFirstname!=null || PEPSIdentifier!=null || representative!=null || represented!=null || mandateContent!=null || organizationAddress!=null || organizationType!=null) +			{ +				PEPSData data = new PEPSData(); +				data.setDateOfBirth(PEPSDateOfBirth); +				data.setFamilyname(PEPSFamilyname); +				data.setFirstname(PEPSFirstname); +				data.setIdentifier(PEPSIdentifier); + +				data.setRepresentative(representative); +				data.setRepresented(represented); +				data.setMandateContent(mandateContent); + +				data.setLegalPersonCanonicalRegisteredAddress(organizationAddress); +				data.setLegalPersonTranslatableType(organizationType); + +				request.setPEPSData(data); +			} +			if (null != mandateContent) { +				MISType mis = new MISType(); + +				Target targetObject = new Target(); +				targetObject.setType(targetType); +				targetObject.setValue(targetValue); +				mis.setTarget(targetObject); + +				mis.setOAFriendlyName(oaFriendlyName); + +				Filters filterObject = new Filters(); +				MandateIdentifiers mandateIds = new MandateIdentifiers(); +				for(String current : filters) +					mandateIds.getMandateIdentifier().add(current.trim()); +				filterObject.setMandateIdentifiers(mandateIds); +				mis.setFilters(filterObject); + +				request.setMIS(mis); +			} + +			if (MiscUtil.isEmpty(connectionParameters.getUrl())) { +				Logger.warn("SZR-Gateway Service URL is empty"); +				throw new SZRGWClientException("service.07"); +			} + +			Logger.info("Starte Kommunikation mit dem Stammzahlenregister Gateway(" + connectionParameters.getUrl() + ")..."); +			CreateIdentityLinkResponse response = client.sentCreateIDLRequest(request, connectionParameters.getUrl()); +			return response; + +		} +		catch (ConfigurationException e) { +			Logger.warn(e); +			Logger.warn(MOAIDMessageProvider.getInstance().getMessage("config.12", null ));  		} catch (UnsupportedEncodingException e) {  			Logger.warn(e);  		} -	     -	    return null; -	 -  } - -    /** -     * Starts a MOA-ID authentication process using STORK -     * -     * @param req                HttpServletRequest -     * @param resp               HttpServletResponse -     * @param ccc                Citizen country code -     * @param oaURL              URL of the online application -     * @param target             Target parameter -     * @param targetFriendlyName Friendly Name of Target -     * @param authURL            Authentication URL -     * @param sourceID           SourceID parameter -     * @throws MOAIDException -     * @throws AuthenticationException -     * @throws WrongParametersException -     * @throws ConfigurationException -     */ -    public static void startSTORKAuthentication( -            HttpServletRequest req, -            HttpServletResponse resp, -            AuthenticationSession moasession) throws MOAIDException, AuthenticationException, WrongParametersException, ConfigurationException { - -        if (moasession == null) { -            throw new AuthenticationException("auth.18", new Object[]{}); -        } - -        //read configuration paramters of OA -        OAAuthParameter oaParam = AuthConfigurationProvider.getInstance().getOnlineApplicationParameter(moasession.getPublicOAURLPrefix()); -        if (oaParam == null) -            throw new AuthenticationException("auth.00", new Object[]{moasession.getPublicOAURLPrefix()}); - -        //Start of STORK Processing -        STORKConfig storkConfig = AuthConfigurationProvider.getInstance().getStorkConfig(); - -        CPEPS cpeps = storkConfig.getCPEPS(moasession.getCcc()); - -        Logger.debug("Preparing to assemble STORK AuthnRequest with the following values:"); -        String destination = cpeps.getPepsURL().toExternalForm(); -        Logger.debug("C-PEPS URL: " + destination); - -        -        String issuerValue = AuthConfigurationProvider.getInstance().getPublicURLPrefix(); -//        String acsURL = new DataURLBuilder().buildDataURL(issuerValue,  -//    			PEPSConnectorServlet.PEPSCONNECTOR_SERVLET_URL_PATTERN, moasession.getSessionID()); -         -        //solve Problem with sessionIDs  -        String acsURL = issuerValue + PEPSConnectorServlet.PEPSCONNECTOR_SERVLET_URL_PATTERN; -         -        Logger.debug("MOA Assertion Consumer URL (PEPSConnctor): " + acsURL); - -        String providerName = oaParam.getFriendlyName(); -        Logger.debug("Issuer value: " + issuerValue); - -        // prepare collection of required attributes -        // - attributes for online application -        List<OAStorkAttribute> attributesFromConfig = oaParam.getRequestedAttributes(); - -        // - prepare attribute list -        PersonalAttributeList attributeList = new PersonalAttributeList(); - -        // - fill container -        for (OAStorkAttribute current : attributesFromConfig) { -            PersonalAttribute newAttribute = new PersonalAttribute(); -            newAttribute.setName(current.getName()); - -            boolean globallyMandatory = false; -            for (StorkAttribute currentGlobalAttribute : storkConfig.getStorkAttributes()) -                if (current.getName().equals(currentGlobalAttribute.getName())) { -                    globallyMandatory = currentGlobalAttribute.isMandatory(); -                    break; -                } - -            newAttribute.setIsRequired(current.isMandatory() || globallyMandatory); -            attributeList.add(newAttribute); -        } - -        // add sign request -        PersonalAttribute newAttribute = new PersonalAttribute(); -        newAttribute.setName("signedDoc"); -        List<String> value = new ArrayList<String>(); -         -        Logger.debug("PEPS supports XMLSignatures:"+cpeps.isXMLSignatureSupported()); -        if(cpeps.isXMLSignatureSupported())//Send SignRequest to PEPS -        { -        	value.add(generateDssSignRequest(CreateXMLSignatureRequestBuilder.buildForeignIDTextToBeSigned("wie im  Signaturzertifikat (as in my signature certificate)", oaParam, moasession), -                "application/xhtml+xml", moasession.getCcc())); -        	newAttribute.setValue(value); -        	attributeList.add(newAttribute); -        } -        else//Process SignRequest locally with MOCCA -        { -        	String target = moasession.getTarget(); -        	moasession.setTarget("AT"); -        	String signedDoc = (generateDssSignRequest(CreateXMLSignatureRequestBuilder.buildForeignIDTextToBeSigned("wie im  Signaturzertifikat (as in my signature certificate)", oaParam, moasession), -                    "application/xhtml+xml", "AT"));//moasession.getCcc() -        	moasession.setTarget(target); -        	Logger.warn("signedDoc to store:"+signedDoc); -            //attributeList.add(newAttribute); -        	 -            //store SignRequest for later... -            moasession.setSignedDoc(signedDoc); -             -            acsURL = issuerValue + PEPSConnectorWithLocalSigningServlet.PEPSCONNECTOR_SERVLET_URL_PATTERN; -            try { + +		return null; + +	} + +	/** +	 * Starts a MOA-ID authentication process using STORK +	 * +	 * @param req                HttpServletRequest +	 * @param resp               HttpServletResponse +	 * @param ccc                Citizen country code +	 * @param oaURL              URL of the online application +	 * @param target             Target parameter +	 * @param targetFriendlyName Friendly Name of Target +	 * @param authURL            Authentication URL +	 * @param sourceID           SourceID parameter +	 * @throws MOAIDException +	 * @throws AuthenticationException +	 * @throws WrongParametersException +	 * @throws ConfigurationException +	 */ +	public static void startSTORKAuthentication( +			HttpServletRequest req, +			HttpServletResponse resp, +			AuthenticationSession moasession) throws MOAIDException, AuthenticationException, WrongParametersException, ConfigurationException { + +		if (moasession == null) { +			throw new AuthenticationException("auth.18", new Object[]{}); +		} + +		//read configuration paramters of OA +		OAAuthParameter oaParam = AuthConfigurationProvider.getInstance().getOnlineApplicationParameter(moasession.getPublicOAURLPrefix()); +		if (oaParam == null) +			throw new AuthenticationException("auth.00", new Object[]{moasession.getPublicOAURLPrefix()}); + +		//Start of STORK Processing +		STORKConfig storkConfig = AuthConfigurationProvider.getInstance().getStorkConfig(); + +		CPEPS cpeps = storkConfig.getCPEPS(moasession.getCcc()); + +		Logger.debug("Preparing to assemble STORK AuthnRequest with the following values:"); +		String destination = cpeps.getPepsURL().toExternalForm(); +		Logger.debug("C-PEPS URL: " + destination); + + +		String issuerValue = AuthConfigurationProvider.getInstance().getPublicURLPrefix(); +		//        String acsURL = new DataURLBuilder().buildDataURL(issuerValue,  +		//    			PEPSConnectorServlet.PEPSCONNECTOR_SERVLET_URL_PATTERN, moasession.getSessionID()); + +		//solve Problem with sessionIDs  +		String acsURL = issuerValue + PEPSConnectorServlet.PEPSCONNECTOR_SERVLET_URL_PATTERN; + +		Logger.debug("MOA Assertion Consumer URL (PEPSConnctor): " + acsURL); + +		String providerName = oaParam.getFriendlyName(); +		Logger.debug("Issuer value: " + issuerValue); + +		// prepare collection of required attributes +		// - attributes for online application +		List<OAStorkAttribute> attributesFromConfig = oaParam.getRequestedAttributes(); + +		// - prepare attribute list +		PersonalAttributeList attributeList = new PersonalAttributeList(); + +		// - fill container +		for (OAStorkAttribute current : attributesFromConfig) { +			PersonalAttribute newAttribute = new PersonalAttribute(); +			newAttribute.setName(current.getName()); + +			boolean globallyMandatory = false; +			for (StorkAttribute currentGlobalAttribute : storkConfig.getStorkAttributes()) +				if (current.getName().equals(currentGlobalAttribute.getName())) { +					globallyMandatory = currentGlobalAttribute.isMandatory(); +					break; +				} + +			newAttribute.setIsRequired(current.isMandatory() || globallyMandatory); +			attributeList.add(newAttribute); +		} + +		// add sign request +		PersonalAttribute newAttribute = new PersonalAttribute(); +		newAttribute.setName("signedDoc"); +		List<String> value = new ArrayList<String>(); + +		Logger.debug("PEPS supports XMLSignatures:"+cpeps.isXMLSignatureSupported()); +		if(cpeps.isXMLSignatureSupported())//Send SignRequest to PEPS +		{ +			value.add(generateDssSignRequest(CreateXMLSignatureRequestBuilder.buildForeignIDTextToBeSigned("wie im  Signaturzertifikat (as in my signature certificate)", oaParam, moasession), +					"application/xhtml+xml", moasession.getCcc())); +			newAttribute.setValue(value); +			attributeList.add(newAttribute); +		} +		else//Process SignRequest locally with MOCCA +		{ +			String target = moasession.getTarget(); +			moasession.setTarget("AT"); +			String signedDoc = (generateDssSignRequest(CreateXMLSignatureRequestBuilder.buildForeignIDTextToBeSigned("wie im  Signaturzertifikat (as in my signature certificate)", oaParam, moasession), +					"application/xhtml+xml", "AT"));//moasession.getCcc() +			moasession.setTarget(target); +			Logger.warn("signedDoc to store:"+signedDoc); +			//attributeList.add(newAttribute); + +			//store SignRequest for later... +			moasession.setSignedDoc(signedDoc); + +			acsURL = issuerValue + PEPSConnectorWithLocalSigningServlet.PEPSCONNECTOR_SERVLET_URL_PATTERN; +			try {  				AuthenticationSessionStoreage.storeSession(moasession);  			} catch (MOADatabaseException e) {  				// TODO Auto-generated catch block  				e.printStackTrace();  			} -             -        } - -        if (Logger.isDebugEnabled()) { -            Logger.debug("The following attributes are requested for this OA:"); -            for (OAStorkAttribute logReqAttr : attributesFromConfig) -                Logger.debug("OA specific requested attribute: " + logReqAttr.getName() + ", isRequired: " + logReqAttr.isMandatory()); -        } - -        //TODO: check Target in case of SSO!! -        String spSector = StringUtils.isEmpty(moasession.getTarget()) ? "Business" : moasession.getTarget(); -        String spInstitution = StringUtils.isEmpty(oaParam.getFriendlyName()) ? "UNKNOWN" : oaParam.getFriendlyName(); -        String spApplication = spInstitution; -        String spCountry = "AT"; - -        //generate AuthnRquest -        STORKAuthnRequest authnRequest = new STORKAuthnRequest(); -        authnRequest.setDestination(destination); -        authnRequest.setAssertionConsumerServiceURL(acsURL);//PEPSConnectorWithLocalSigning -        authnRequest.setProviderName(providerName); -        authnRequest.setIssuer(issuerValue); -        authnRequest.setQaa(oaParam.getQaaLevel()); -        authnRequest.setSpInstitution(spInstitution); -        authnRequest.setCountry(spCountry); -        authnRequest.setSpApplication(spApplication); -        authnRequest.setSpSector(spSector); -        authnRequest.setPersonalAttributeList(attributeList); - -        //TODO change -        authnRequest.setEIDCrossBorderShare(true); -        authnRequest.setEIDCrossSectorShare(true); -        authnRequest.setEIDSectorShare(true); - -        authnRequest.setCitizenCountryCode(moasession.getCcc()); - -        Logger.debug("STORK AuthnRequest succesfully assembled."); - -        STORKSAMLEngine samlEngine = STORKSAMLEngine.getInstance("outgoing"); -         -        if (samlEngine == null) { -            Logger.error("Could not initalize STORK SAML engine."); -            throw new MOAIDException("stork.00", null); -        } -         -        try { -            authnRequest = samlEngine.generateSTORKAuthnRequest(authnRequest); -        } catch (STORKSAMLEngineException e) { -            Logger.error("Could not sign STORK SAML AuthnRequest.", e); -            throw new MOAIDException("stork.00", null); -        } - -        Logger.info("STORK AuthnRequest successfully signed!"); - -        //validate AuthnRequest -        try { -            samlEngine.validateSTORKAuthnRequest(authnRequest.getTokenSaml()); -        } catch (STORKSAMLEngineException e) { -            Logger.error("STORK SAML AuthnRequest not valid.", e); -            throw new MOAIDException("stork.01", null); -        } - -        Logger.debug("STORK AuthnRequest successfully internally validated."); - -        //send -        moasession.setStorkAuthnRequest(authnRequest); - -        AuthenticationSessionStoreage.changeSessionID(moasession, authnRequest.getSamlId()); -         -         -        Logger.info("Preparing to send STORK AuthnRequest."); -        Logger.info("prepared STORKAuthnRequest: "); -        Logger.info(new String(authnRequest.getTokenSaml())); - -        try { -            Logger.trace("Initialize VelocityEngine..."); - -            VelocityEngine velocityEngine = VelocityProvider.getClassPathVelocityEngine(); -            Template template = velocityEngine.getTemplate("/resources/templates/saml2-post-binding-moa.vm"); -            VelocityContext context = new VelocityContext(); -            context.put("SAMLRequest", PEPSUtil.encodeSAMLToken(authnRequest.getTokenSaml())); -            context.put("RelayState", moasession.getSessionID()); -            context.put("action", destination); - -            StringWriter writer = new StringWriter(); -            template.merge(context, writer); - -            resp.setContentType("text/html;charset=UTF-8");             -            resp.getOutputStream().write(writer.toString().getBytes("UTF-8")); - -        } catch (Exception e) { -            Logger.error("Error sending STORK SAML AuthnRequest.", e); -            throw new MOAIDException("stork.02", new Object[]{destination}); -             -        } - -        Logger.info("STORK AuthnRequest successfully successfully prepared for client with target location: " + authnRequest.getDestination()); -    } - -    private static String generateDssSignRequest(String text, String mimeType, String citizenCountry) { -        IdentifierGenerator idGenerator; -        try { -            idGenerator = new SecureRandomIdentifierGenerator(); - -            DocumentType doc = new DocumentType(); -            doc.setBase64XML(text.getBytes("UTF-8")); -            doc.setID(idGenerator.generateIdentifier()); - -            SignRequest request = new SignRequest(); -            request.setInputDocuments(ApiUtils.createInputDocuments(doc)); - -            String id = idGenerator.generateIdentifier(); -            request.setRequestID(id); -            request.setDocUI(id); - -            request.setProfile(Profiles.XADES_BES.toString()); -            request.setNumberOfSigners(BigInteger.ONE); -            request.setTargetCountry(citizenCountry); - -            // no, no todo. PEPS will alter this value anyhow. -            request.setReturnURL("http://invalid_return"); - -            AnyType required = new AnyType(); -            required.getAny().add(ApiUtils.createSignatureType(SignatureTypes.XMLSIG_RFC3275.toString())); -            required.getAny().add(ApiUtils.createAdditionalProfile(AdditionalProfiles.XADES.toString())); -            required.getAny().add(ApiUtils.createQualityRequirements(QualityLevels.QUALITYLEVEL_QUALIFIEDSIG)); -            required.getAny().add(ApiUtils.createIncludeObject(doc)); -            request.setOptionalInputs(required); - -            return IOUtils.toString(ApiUtils.marshalToInputStream(request)); -        } catch (NoSuchAlgorithmException e) { -            Logger.error("Cannot generate id", e); -            throw new RuntimeException(e); -        } catch (ApiUtilsException e) { -            Logger.error("Could not create SignRequest", e); -            throw new RuntimeException(e); -        } catch (DOMException e) { -            Logger.error("Could not create SignRequest", e); -            throw new RuntimeException(e); -        } catch (IOException e) { -            Logger.error("Could not create SignRequest", e); -            throw new RuntimeException(e); -        } -    } - -    /** -     * Extracts an X509 Certificate out of an XML signagture element -     * -     * @param signedXML XML signature element -     * @return X509Certificate -     * @throws CertificateException -     */ -    public static X509Certificate getCertificateFromXML(Element signedXML) throws CertificateException { - -        NodeList nList = signedXML.getElementsByTagNameNS(Constants.DSIG_NS_URI, "X509Certificate"); - -        String base64CertString = XMLUtil.getFirstTextValueFromNodeList(nList); - -        if (StringUtils.isEmpty(base64CertString)) { -            String msg = "XML does not contain a X509Certificate element."; -            Logger.error(msg); -            throw new CertificateException(msg); -        } - -        InputStream is = new ByteArrayInputStream(Base64.decode(base64CertString)); - -        X509Certificate cert; -        try { -            cert = new X509Certificate(is); -            return cert; - -        } catch (Throwable e) { -            throw new CertificateException(e); -        } -    } + +		} + +		if (Logger.isDebugEnabled()) { +			Logger.debug("The following attributes are requested for this OA:"); +			for (OAStorkAttribute logReqAttr : attributesFromConfig) +				Logger.debug("OA specific requested attribute: " + logReqAttr.getName() + ", isRequired: " + logReqAttr.isMandatory()); +		} + +		//TODO: check Target in case of SSO!! +		String spSector = StringUtils.isEmpty(moasession.getTarget()) ? "Business" : moasession.getTarget(); +		String spInstitution = StringUtils.isEmpty(oaParam.getFriendlyName()) ? "UNKNOWN" : oaParam.getFriendlyName(); +		String spApplication = spInstitution; +		String spCountry = "AT"; + +		//generate AuthnRquest +		STORKAuthnRequest authnRequest = new STORKAuthnRequest(); +		authnRequest.setDestination(destination); +		authnRequest.setAssertionConsumerServiceURL(acsURL);//PEPSConnectorWithLocalSigning +		authnRequest.setProviderName(providerName); +		authnRequest.setIssuer(issuerValue); +		authnRequest.setQaa(oaParam.getQaaLevel()); +		authnRequest.setSpInstitution(spInstitution); +		authnRequest.setCountry(spCountry); +		authnRequest.setSpApplication(spApplication); +		authnRequest.setSpSector(spSector); +		authnRequest.setPersonalAttributeList(attributeList); + +		//TODO change +		authnRequest.setEIDCrossBorderShare(true); +		authnRequest.setEIDCrossSectorShare(true); +		authnRequest.setEIDSectorShare(true); + +		authnRequest.setCitizenCountryCode(moasession.getCcc()); + +		Logger.debug("STORK AuthnRequest succesfully assembled."); + +		STORKSAMLEngine samlEngine = STORKSAMLEngine.getInstance("outgoing"); + +		if (samlEngine == null) { +			Logger.error("Could not initalize STORK SAML engine."); +			throw new MOAIDException("stork.00", null); +		} + +		try { +			authnRequest = samlEngine.generateSTORKAuthnRequest(authnRequest); +		} catch (STORKSAMLEngineException e) { +			Logger.error("Could not sign STORK SAML AuthnRequest.", e); +			throw new MOAIDException("stork.00", null); +		} + +		Logger.info("STORK AuthnRequest successfully signed!"); + +		//validate AuthnRequest +		try { +			samlEngine.validateSTORKAuthnRequest(authnRequest.getTokenSaml()); +		} catch (STORKSAMLEngineException e) { +			Logger.error("STORK SAML AuthnRequest not valid.", e); +			throw new MOAIDException("stork.01", null); +		} + +		Logger.debug("STORK AuthnRequest successfully internally validated."); + +		//send +		moasession.setStorkAuthnRequest(authnRequest); + +		AuthenticationSessionStoreage.changeSessionID(moasession, authnRequest.getSamlId()); + + +		Logger.info("Preparing to send STORK AuthnRequest."); +		Logger.info("prepared STORKAuthnRequest: "); +		Logger.info(new String(authnRequest.getTokenSaml())); + +		try { +			Logger.trace("Initialize VelocityEngine..."); + +			VelocityEngine velocityEngine = VelocityProvider.getClassPathVelocityEngine(); +			Template template = velocityEngine.getTemplate("/resources/templates/saml2-post-binding-moa.vm"); +			VelocityContext context = new VelocityContext(); +			context.put("SAMLRequest", PEPSUtil.encodeSAMLToken(authnRequest.getTokenSaml())); +			context.put("RelayState", moasession.getSessionID()); +			context.put("action", destination); + +			StringWriter writer = new StringWriter(); +			template.merge(context, writer); + +			resp.setContentType("text/html;charset=UTF-8");             +			resp.getOutputStream().write(writer.toString().getBytes("UTF-8")); + +		} catch (Exception e) { +			Logger.error("Error sending STORK SAML AuthnRequest.", e); +			throw new MOAIDException("stork.02", new Object[]{destination}); + +		} + +		Logger.info("STORK AuthnRequest successfully successfully prepared for client with target location: " + authnRequest.getDestination()); +	} + +	private static String generateDssSignRequest(String text, String mimeType, String citizenCountry) { +		IdentifierGenerator idGenerator; +		try { +			idGenerator = new SecureRandomIdentifierGenerator(); + +			DocumentType doc = new DocumentType(); +			doc.setBase64XML(text.getBytes("UTF-8")); +			doc.setID(idGenerator.generateIdentifier()); + +			SignRequest request = new SignRequest(); +			request.setInputDocuments(ApiUtils.createInputDocuments(doc)); + +			String id = idGenerator.generateIdentifier(); +			request.setRequestID(id); +			request.setDocUI(id); + +			request.setProfile(Profiles.XADES_BES.toString()); +			request.setNumberOfSigners(BigInteger.ONE); +			request.setTargetCountry(citizenCountry); + +			// no, no todo. PEPS will alter this value anyhow. +			request.setReturnURL("http://invalid_return"); + +			AnyType required = new AnyType(); +			required.getAny().add(ApiUtils.createSignatureType(SignatureTypes.XMLSIG_RFC3275.toString())); +			required.getAny().add(ApiUtils.createAdditionalProfile(AdditionalProfiles.XADES.toString())); +			required.getAny().add(ApiUtils.createQualityRequirements(QualityLevels.QUALITYLEVEL_QUALIFIEDSIG)); +			required.getAny().add(ApiUtils.createIncludeObject(doc)); +			request.setOptionalInputs(required); + +			return IOUtils.toString(ApiUtils.marshalToInputStream(request)); +		} catch (NoSuchAlgorithmException e) { +			Logger.error("Cannot generate id", e); +			throw new RuntimeException(e); +		} catch (ApiUtilsException e) { +			Logger.error("Could not create SignRequest", e); +			throw new RuntimeException(e); +		} catch (DOMException e) { +			Logger.error("Could not create SignRequest", e); +			throw new RuntimeException(e); +		} catch (IOException e) { +			Logger.error("Could not create SignRequest", e); +			throw new RuntimeException(e); +		} +	} + +	/** +	 * Extracts an X509 Certificate out of an XML signagture element +	 * +	 * @param signedXML XML signature element +	 * @return X509Certificate +	 * @throws CertificateException +	 */ +	public static X509Certificate getCertificateFromXML(Element signedXML) throws CertificateException { + +		NodeList nList = signedXML.getElementsByTagNameNS(Constants.DSIG_NS_URI, "X509Certificate"); + +		String base64CertString = XMLUtil.getFirstTextValueFromNodeList(nList); + +		if (StringUtils.isEmpty(base64CertString)) { +			String msg = "XML does not contain a X509Certificate element."; +			Logger.error(msg); +			throw new CertificateException(msg); +		} + +		InputStream is = new ByteArrayInputStream(Base64.decode(base64CertString)); + +		X509Certificate cert; +		try { +			cert = new X509Certificate(is); +			return cert; + +		} catch (Throwable e) { +			throw new CertificateException(e); +		} +	}  } diff --git a/id/server/idserverlib/src/main/java/at/gv/egovernment/moa/id/protocols/stork2/attributeproviders/SignedDocAttributeRequestProvider.java b/id/server/idserverlib/src/main/java/at/gv/egovernment/moa/id/protocols/stork2/attributeproviders/SignedDocAttributeRequestProvider.java index 2aa10b9dd..13b14b0be 100644 --- a/id/server/idserverlib/src/main/java/at/gv/egovernment/moa/id/protocols/stork2/attributeproviders/SignedDocAttributeRequestProvider.java +++ b/id/server/idserverlib/src/main/java/at/gv/egovernment/moa/id/protocols/stork2/attributeproviders/SignedDocAttributeRequestProvider.java @@ -131,6 +131,14 @@ public class SignedDocAttributeRequestProvider extends AttributeProvider {  		}  		requestedAttribute = attribute; +		try +		{ +			 String tmp = requestedAttribute.getValue().get(0); +		}catch(Exception e) +		{ +			Logger.info("SignedDocAttributeProvide failed:"+e.toString()); +			throw new UnsupportedAttributeException(); +		}  		throw new ExternalAttributeRequestRequiredException(this);  	} | 
