SecureBlackbox 2020 Android Edition

Questions / Feedback?

SAMLWriter Component

Properties   Methods   Events   Configuration Settings   Errors  

The SAMLWriter component offers SAML message generation functions.




SAMLWriter provides means of serialization of SAML entities into valid SAML protocol messages. Together with SAMLReader, this class provides fine-grained access to the composition of SAML requests, responses, assertions, and statements. You can use it as part of your SAML client or SAML server implementation for creating individual SAML entities.

SAMLReader and SAMLWriter are independent of SAML server controls that are also included in SecureBlackbox, and are aimed at scenarios that require lower-level access to SAML functionality than that provided by the server controls.

SAMLWriter can create the following kinds of SAML messages:

  • AssertionIDRequest
  • SubjectQuery
  • AuthnQuery
  • AttributeQuery
  • AuthzDecisionQuery
  • AuthnRequest
  • ManageNameIDRequest
  • LogoutRequest
  • NameIDMappingRequest
  • ArtifactResolve
  • Response

Please find below a quick-and-dirty example of the use of SAMLWriter class for creating a signed AuthnRequest message:

  Samlwriter writer = new Samlwriter();

  // configuring general message properties
  writer.Destination = "";
  writer.IssueInstant = DateTime.UtcNow.ToString("yyyy-MM-ddTHH:mm:ss.fffZ");
  writer.Issuer = "Value=;Format=urn:oasis:names:tc:SAML:2.0:nameid-format:entity;IDType=Issuer";

  // configuring general AuthnRequest properties
  writer.AuthnRequest.IsPassive = false;
  writer.AuthnRequest.UseIsPassive = true;
  writer.AuthnRequest.ForceAuthn = true;
  writer.AuthnRequest.ProtocolBinding = "urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST";
  writer.AuthnRequest.AssertionConsumerServiceURL = "";
  writer.AuthnRequest.AttributeConsumingServiceIndex = 1;
  writer.AuthnRequest.NameIDPolicyAllowCreate = false;
  writer.AuthnRequest.NameIDPolicyFormat = "urn:oasis:names:tc:SAML:2.0:nameid-format:persistent";
  writer.AuthnRequest.ConditionsNotBefore = DateTime.UtcNow.ToString("yyyy-MM-ddTHH:mm:ss.fffZ");
  writer.AuthnRequest.ConditionsNotOnOrAfter = DateTime.UtcNow.AddMinutes(30).ToString("yyyy-MM-ddTHH:mm:ss.fffZ");

  // adjusting request conditions if required
  SAMLAssertionCondition cond = new SAMLAssertionCondition();
  cond.ConditionType = SAMLConditionTypes.csctOneTimeUse;

  // configuring signing properties
  Certificate certificate = new Certificate("C:\\Certs\\samlCert.pfx", "password");
  writer.Sign = true;
  writer.SigningCertificate = certificate;

  // creating the SAML entity of the required type

  // adjusting low-level signature parameters
  // signing the request and serializing it to XML
  string request = writer.Save();
The above code produces the following AuthnRequest:
    xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" ID="53GhrzQ5f89fu214ANAR" Version="2.0" 
    IssueInstant="2021-12-15T10:39:31Z" Destination="" IsPassive="false" 
    AssertionConsumerServiceURL="" AttributeConsumingServiceIndex="1" 
    <saml:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity"></saml:Issuer>
    <ds:Signature xmlns:ds="">
        <ds:CanonicalizationMethod Algorithm=""/>
        <ds:SignatureMethod Algorithm=""/>
        <ds:Reference URI="#53GhrzQ5f89fu214ANAR">
            <ds:Transform Algorithm=""/>
            <ds:Transform Algorithm=""/>
          <ds:DigestMethod Algorithm=""/><ds:DigestValue>+xhhgXtwYN0/r9h7WAwg=</ds:DigestValue>
    <samlp:NameIDPolicy Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"/>
    <saml:Conditions NotBefore="2021-12-15T10:39:31Z" NotOnOrAfter="2021-12-15T11:09:31Z"><saml:OneTimeUse/></saml:Conditions>

Property List

The following is the full list of the properties of the component with short descriptions. Click on the links for further details.

AddXMLHeaderControls the inclusion of an XML header in the message.
ArtifactProvides access to the Artifact element of the message.
ArtifactResolveQueryContains the artifact resolve query.
AssertionAttributesContains a list of assertion attributes.
AssertionConditionsContains a list of assertion conditions.
AssertionCountReturns the number of assertions in the message.
AssertionIDRequestContains the properties of AssertionIDRequest element.
AssertionInfoContains assertion information.
AssertionIssuerSpecifies the assertion issuer.
AssertionStatementsContains assertion statements.
AssertionSubjectConfirmationsProvides access to assertion SubjectConfirmations list.
AssertionSubjectIDSpecifies the assertion subject ID.
AttrQueryAttributesContains a list of attribute query attributes.
AuthnQueryProvides access to the AuthnQuery SAML element.
AuthnRequestPublishes the properties of AuthnRequest element.
AuthnRequestConditionsContains a list of AuthnRequest conditions.
AuthnRequestScopingIDPListProvides access to the list of scoping IDP eleements.
AuthzDecisionQueryProvides access to AuthzDecisionQuery element.
BindingSpecifies the type of the binding to use.
ConsentContains the Consent parameter of the request.
DestinationContains the Destination parameter of the SAML object.
EncryptionCertificateSets the encryption certificate.
IDThe ID of the request.
InResponseToContains the InResponseTo property of the SAML request.
IssueInstantContains request issuance timestamp.
IssuerSets the issuer of the message.
LogoutRequestContains the properties of SAML LogoutRequest element.
ManageNameIDRequestProvides access to ManageNameIDRequest element.
NameIDMappingRequestPublishes the properties of NameIDMappingRequest entity.
OutputTypeReturns the SAML type of message being created.
POSTBindingExposes the POST binding properties.
ProfileSpecifies a pre-defined profile to apply when creating the signature.
RedirectBindingPublishes the redirect binding settings.
RedirectBindingCertificateContains a certificate to sign the redirect binding.
ResponseProvides access to the SAML response object properties.
SignSpecifies whether the created SAML message should be signed.
SigningCertificateThe certificate to be used for signing.
SigningChainThe signing certificate chain.
SubjectConfirmationsProvides access to the list of subject confirmation elements.
SubjectIDSets the subject of the message.
VersionSpecifies the protocol version of the SAML message.

Method List

The following is the full list of the methods of the component with short descriptions. Click on the links for further details.

addAdviceAssertionAdds an advice assertion to the message.
addAssertionAdds assertion to a SAML message.
clearAssertionResets the contents of all assertion-related properties.
compareIDsCompares two SAML IDs.
configSets or retrieves a configuration setting.
createNewCreates a new SAML message with the given type.
getIDPropReturns an element of the SAML ID.
removeAdviceRemoves an advice from an assertion.
removeAdviceAssertionRemoves an advice from an assertion.
removeAllAssertionsRemoves all assertions currently configured in the message.
removeAssertionRemoves an assertion from the message.
saveSaves the configured message to a string.
saveBytesSaves the configured message to a byte array.
saveFileSaves the configured message to a file.
saveStreamSaves the configured message to a stream.

Event List

The following is the full list of the events fired by the component with short descriptions. Click on the links for further details.

ErrorFires to report an error condition.
NotificationThis event notifies the application about an underlying control flow event.

Configuration Settings

The following is a list of configuration settings for the component with short descriptions. Click on the links for further details.

IgnoreSystemTrustWhether trusted Windows Certificate Stores should be treated as trusted.
SigAfterIssuerSpecifies whether to insert the signature after the issuer tag in the SAML document.
SigCanonicalizationMethodThe canonicalization method to use in the signature.
SigDigestMethodThe digest method to use.
SigMethodThe signature method to use.
TolerateMinorChainIssuesWhether to tolerate minor chain issues.
UseMicrosoftCTLEnables or disables automatic use of Microsoft online certificate trust list.
UseSystemCertificatesEnables or disables the use of the system certificates.
CheckKeyIntegrityBeforeUseEnables or disable private key integrity check before use.
CookieCachingSpecifies whether a cookie cache should be used for HTTP(S) transports.
CookiesGets or sets local cookies for the component (supported for HTTPClient, RESTClient and SOAPClient only).
DefDeriveKeyIterationsSpecifies the default key derivation algorithm iteration count.
EnableClientSideSSLFFDHEEnables or disables finite field DHE key exchange support in TLS clients.
GlobalCookiesGets or sets global cookies for all the HTTP transports.
HttpUserAgentSpecifies the user agent name to be used by all HTTP clients.
LogDestinationSpecifies the debug log destination.
LogDetailsSpecifies the debug log details to dump.
LogFileSpecifies the debug log filename.
LogFiltersSpecifies the debug log filters.
LogFlushModeSpecifies the log flush mode.
LogLevelSpecifies the debug log level.
LogMaxEventCountSpecifies the maximum number of events to cache before further action is taken.
LogRotationModeSpecifies the log rotation mode.
MaxASN1BufferLengthSpecifies the maximal allowed length for ASN.1 primitive tag data.
MaxASN1TreeDepthSpecifies the maximal depth for processed ASN.1 trees.
OCSPHashAlgorithmSpecifies the hash algorithm to be used to identify certificates in OCSP requests.
UseOwnDNSResolverSpecifies whether the client components should use own DNS resolver.
UseSharedSystemStoragesSpecifies whether the validation engine should use a global per-process copy of the system certificate stores.
UseSystemOAEPAndPSSEnforces or disables the use of system-driven RSA OAEP and PSS computations.
UseSystemRandomEnables or disables the use of the OS PRNG.

Copyright (c) 2022 /n software inc. - All rights reserved.
SecureBlackbox 2020 Android Edition - Version 20.0 [Build 8156]