SAML 2.0 implementation for the NERC DataGrid based on the Java OpenSAML library
SAML 2.0 implementation for use with the Earth System Grid Federation Attribute and Authorisation Query interfaces. The implementation is based on the Java OpenSAML libraries. An implementation is provided with ElementTree but it can easily be extended to use other Python XML parsers.
- Minor fixes for PyOpenSSL imports
- Allow for authorisation decision query response not setting Action namespace correctly. - Accept response with warning.
- Fixes for SAML response processing - allow for more liberal check of response type and for case for status message value not returned
- Re-factored to use ndg-httpsclient for client HTTP calls in place of M2Crypto.
- decoupled SAML bindings classes from types.
- add command line script for making attribute and authorisation decision query client calls.
added support for SAML 2.0 profile of XACML v2.0 (http://docs.oasis-open.org/xacml/2.0/access_control-xacml-2.0-saml-profile-spec-os.pdf), specifically the SAML request extensions: XACMLAuthzDecisionQuery and XACMLAuthzDecisionStatement. This an alternative to the SAML defined AuthzDecisionQuery. It enables a richer functionality for expressing queries and authorisation decisions taking advantage of the full capabilities of a XACML PDP.
fixed bug in SAML SOAP binding code: RequestBaseSOAPBinding and derived classes to act as a query factory, instead of container, for thread safety.
Thanks to Richard Wilkinson for these contributions.
- allow passing a client certificate chain in client HTTPS requests
- fix for ndg.saml.saml2.binding.soap.server.wsgi.queryinterface.SOAPQueryInterfaceMiddleware: bug in issuerFormat property setter - setting issuerName value.
- fix for ndg.soap.utils.etree.prettyPrint for undeclared Nss.
- fix for applying clock skew property in queryinterface WSGI middleware, and various minor fixes for classfactory module and m2crytpo utilities.
- fix for date time parsing where no seconds fraction is present, fixed error message for InResponseTo ID check for Subject Query.
- adds WSGI middleware and clients for SAML SOAP binding and assertion query/request profile.
It is not a complete implementation of SAML 2.0. Only those components required for the NERC DataGrid have been provided (Attribute and AuthZ Decision Query/ Response). Where possible, stubs have been provided for other classes.