@@ -54,57 +54,57 @@ A proofed identity request at AAL2, with phishing resistent MFA, for email, phon
5454{% capture decrypted_response %}
5555``` xml
5656<Assertion xmlns =" urn:oasis:names:tc:SAML:2.0:assertion" ID =" _b7a3ca0f-25a4-4365-af81-da8f04740564" IssueInstant =" 2024-09-18T16:20:36Z" Version =" 2.0" >
57- <Issuer >https://idp.int.identitysandbox.gov/api/saml</Issuer >
58- <ds : Signature xmlns : ds =" http://www.w3.org/2000/09/xmldsig#" >
57+ <Issuer >https://idp.int.identitysandbox.gov/api/saml</Issuer >
58+ <ds : Signature xmlns : ds =" http://www.w3.org/2000/09/xmldsig#" >
5959 <ds : SignedInfo >
60- <ds : CanonicalizationMethod Algorithm =" http://www.w3.org/2001/10/xml-exc-c14n#" />
61- <ds : SignatureMethod Algorithm =" http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" />
62- <ds : Reference URI =" #_b7a3ca0f-25a4-4365-af81-da8f04740564" >
60+ <ds : CanonicalizationMethod Algorithm =" http://www.w3.org/2001/10/xml-exc-c14n#" />
61+ <ds : SignatureMethod Algorithm =" http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" />
62+ <ds : Reference URI =" #_b7a3ca0f-25a4-4365-af81-da8f04740564" >
6363 <ds : Transforms >
64- <ds : Transform Algorithm =" http://www.w3.org/2000/09/xmldsig#enveloped-signature" />
65- <ds : Transform Algorithm =" http://www.w3.org/2001/10/xml-exc-c14n#" />
64+ <ds : Transform Algorithm =" http://www.w3.org/2000/09/xmldsig#enveloped-signature" />
65+ <ds : Transform Algorithm =" http://www.w3.org/2001/10/xml-exc-c14n#" />
6666 </ds : Transforms >
6767 <ds : DigestMethod Algorithm =" http://www.w3.org/2001/04/xmlenc#sha256" />
6868 <ds : DigestValue >5uICLRmnTHr/Ma7+uphAjCf86rmR+P6QELBf2C53mIc=</ds : DigestValue >
69- </ds : Reference >
69+ </ds : Reference >
7070 </ds : SignedInfo >
7171 <ds : SignatureValue >XT9CguQWKBvbqVsJ+Khu5/eyl09JVhHkUuyFHa98ViZUBVgL/Hc9gzwUr43CA7OVOO+uMfCc6WvPKeADF9w9kqJaUgsi8LiKC/nfDCY6+UiRoep2zmXyFJRAvrD/HbgVfayx/4Nn3ponRPZ/T/oezhimssFF66m+/UAwJekO9kuob+5n+uaOiFOMuHEycSdASH/iFnTSR1ajdo6AaLomG6YT8zJbuRzcKmesouAKPiQCJFt2cgstEs1zw8dvTgmozy4qd/0aMiZ52eGcXoORD8VZOQiY63HT8F4wkhk5eGU05sFcyfpg7dXNtKOfCddHwyngmgmPhpRN30ew5njg7w==</ds : SignatureValue >
7272 <ds : KeyInfo >
73- <ds : X509Data >
73+ <ds : X509Data >
7474 <ds:X509Certificate>MIID+TCCAuGgAwIBAgIUUS6s9Rb+KY0fT0qKKgqPPJij/HMwDQYJKoZIhvcNAQELBQAwgYsxCzAJBgNVBAYTAlVTMR0wGwYDVQQIDBREaXN0cmljdCBvZiBDb2x1bWJpYTETMBEGA1UEBwwKV2FzaGluZ3RvbjEMMAoGA1UECgwDR1NBMRIwEAYDVQQLDAlMb2dpbi5nb3YxJjAkBgNVBAMMHWxvZ2luLmdvdi5pZGVudGl0eXNhbmRib3guZ292MB4XDTI0MDEyMjIwMTcwN1oXDTI1MDQwMTIwMTcwN1owgYsxCzAJBgNVBAYTAlVTMR0wGwYDVQQIDBREaXN0cmljdCBvZiBDb2x1bWJpYTETMBEGA1UEBwwKV2FzaGluZ3RvbjEMMAoGA1UECgwDR1NBMRIwEAYDVQQLDAlMb2dpbi5nb3YxJjAkBgNVBAMMHWxvZ2luLmdvdi5pZGVudGl0eXNhbmRib3guZ292MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAhmcFFn4b56vHlGBQ1Lx6AXz17sqKnCc6sJ+9csP1RtQBI0NpPHB2z9Di1PNk/ElK7V7yh3uMu4FJYw30GZFUl2f/ttsDkNHrwfh/jzbMNjrOSc0P25oem4uOUfeGH9jtMhKa+HZLOaOmcyWFKkYR2mwacEbQJ1CWviHtP8AzHUPSbHklAmusRLuygTjq0+QRJZgSezGqwU1L3ixPq+gMzPtMS+fxsMOVo2eosip440gz4rcqUUogtD2hV8EQi3+GIkGYuMTS81ug/385TCPEhzWMnNmDi3HykOZeRNb4GfCYw0Yx+v+cb7BPD5EdxUHNwliHvSiRAeYqLjBjuNUfKQIDAQABo1MwUTAdBgNVHQ4EFgQUusictYnNM2TbIt5STz2lkYN1sI8wHwYDVR0jBBgwFoAUusictYnNM2TbIt5STz2lkYN1sI8wDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEATuLF4kHeP7FY9Wzm3DfF+m/5wUhJEtbsF8J9Wq8duhQ4/gtZVJgMDUKLsnSDLCtWiRlsFXquI8tlo32JsVo5NfZI9WYsub7192iCYpqE+x5G+94tt5vAayoF7GKGPxatyldxAQUz7RUzwqas7NCYXQ0p7wZrMqF8z2yvaUgL55v8TJIb7RP+D8b47Cmzx7IYmx3Co30vZWysQe61Bv880hG11YJsBAc0hmyWlokJYZZVm+xcjKkm6aFyyAbeCe0Kh68QU7f9YkpFv/sW2RIvZ/Z0gvxjJE+YJBwOwPDDHdkb0ZmKOJvlaabi5lkTZvUtTHXb5Hu7DxRRt91dm77MlQ==</ds:X509Certificate>
75- </ds : X509Data >
75+ </ds : X509Data >
7676 </ds : KeyInfo >
77- </ds : Signature >
78- <Subject >
77+ </ds : Signature >
78+ <Subject >
7979 <NameID Format =" urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" >34abda40-d5aa-4259-9f17-a3757fd2e094</NameID >
8080 <SubjectConfirmation Method =" urn:oasis:names:tc:SAML:2.0:cm:bearer" >
81- <SubjectConfirmationData InResponseTo =" _bf054c05-5b2c-4773-a6a9-9ba075a87bc9" NotOnOrAfter =" 2024-09-18T16:23:36Z" Recipient =" https://sp.int.identitysandbox.gov/auth/saml/callback" />
81+ <SubjectConfirmationData InResponseTo =" _bf054c05-5b2c-4773-a6a9-9ba075a87bc9" NotOnOrAfter =" 2024-09-18T16:23:36Z" Recipient =" https://sp.int.identitysandbox.gov/auth/saml/callback" />
8282 </SubjectConfirmation >
83- </Subject >
84- <Conditions NotBefore =" 2024-09-18T16:20:31Z" NotOnOrAfter =" 2024-09-18T17:20:36Z" >
83+ </Subject >
84+ <Conditions NotBefore =" 2024-09-18T16:20:31Z" NotOnOrAfter =" 2024-09-18T17:20:36Z" >
8585 <AudienceRestriction >
86- <Audience >urn:gov:gsa:SAML:2.0.profiles:sp:sso:identitysandbox</Audience >
86+ <Audience >urn:gov:gsa:SAML:2.0.profiles:sp:sso:identitysandbox</Audience >
8787 </AudienceRestriction >
88- </Conditions >
89- <AttributeStatement >
88+ </Conditions >
89+ <AttributeStatement >
9090 <Attribute Name =" uuid" NameFormat =" urn:oasis:names:tc:SAML:2.0:attrname-format:basic" FriendlyName =" uuid" >
91- <AttributeValue >34abda40-d5aa-4259-9f17-a3757fd2e094</AttributeValue >
91+ <AttributeValue >34abda40-d5aa-4259-9f17-a3757fd2e094</AttributeValue >
9292 </Attribute >
9393 <Attribute Name =" email" NameFormat =" urn:oasis:names:tc:SAML:2.0:attrname-format:basic" FriendlyName =" email" >
94- <AttributeValue >subcriber @example.com</AttributeValue >
94+ <AttributeValue >vraj @example.com</AttributeValue >
9595 </Attribute >
9696 <Attribute Name =" aal" NameFormat =" urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName =" aal" >
97- <AttributeValue >http://idmanagement.gov/ns/assurance/aal/2</AttributeValue >
97+ <AttributeValue >http://idmanagement.gov/ns/assurance/aal/2</AttributeValue >
9898 </Attribute >
9999 <Attribute Name =" ial" NameFormat =" urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName =" ial" >
100- <AttributeValue >http://idmanagement.gov/ns/assurance/ial/1</AttributeValue >
100+ <AttributeValue >http://idmanagement.gov/ns/assurance/ial/1</AttributeValue >
101101 </Attribute >
102- </AttributeStatement >
103- <AuthnStatement AuthnInstant =" 2024-09-18T16:20:36Z" SessionIndex =" _b7a3ca0f-25a4-4365-af81-da8f04740564" >
102+ </AttributeStatement >
103+ <AuthnStatement AuthnInstant =" 2024-09-18T16:20:36Z" SessionIndex =" _b7a3ca0f-25a4-4365-af81-da8f04740564" >
104104 <AuthnContext >
105- <AuthnContextClassRef >http://idmanagement.gov/ns/assurance/aal/2?phishing_resistant=true</AuthnContextClassRef >
105+ <AuthnContextClassRef >http://idmanagement.gov/ns/assurance/aal/2?phishing_resistant=true</AuthnContextClassRef >
106106 </AuthnContext >
107- </AuthnStatement >
107+ </AuthnStatement >
108108</Assertion >
109109```
110110{% endcapture %}
0 commit comments