NotBefore condition in assertions
Michael A Grady
mgrady at unicon.net
Sun Oct 21 17:43:45 EDT 2012
I guess the IdP operators on this list have been successful with one or more of the following:
- get all their SPs to allow skew
- get their organization to NOT use an SP that won't allow skew
- simply not have a problem with skew
as there doesn't seem much interest/need in an option to leave off the NotBefore condition. At least given the lack of feedback/discussion on this topic.
I can say that we were interacting with a vendor that refused to allow for skew. They already have a lot of commercial partners that were using a variety of commercial IdPs that apparently support adjusting NotBefore, so this SP is insistent on the IdP making the adjustment, and have been successful in getting their partners to do so. Using a different vendor was not an option at this time (unfortunately), so I did make a simple change to the Shib IdP to remove NotBefore from the assertions. (Not yet as a config option, just altogether, just to see if this worked with the vendor -- because we couldn't get an entirely clear answer as to whether their SP would work fine without the NotBefore condition present.) And it indeed does work, and thus solves the skew problem -- just not send the NotBefore condition. And I know that the Shib SP won't have a problem with this, so the current federated partners would work fine just leaving off NotBefore.
So we're still inclined to add a configurable option (by Relying Party) for NotBefore to the current Shib IdP, but if no one is going to use/need it, then perhaps it isn't a particularly useful contribution to the community. Anyone else have thoughts on this?
On Oct 17, 2012, at 3:29 PM, Christopher Bongaarts wrote:
> On 10/17/2012 2:16 PM, Michael A Grady wrote:
>
>> Any thoughts on this? Anyone else who would like to see this option
>> exist in the IdP? (Note I'm intentionally starting this discussion on
>> the Users list, for the widest input/feedback/thoughts, but recognize
>> that eventually the conversation would most appropriately move to the
>> Dev list.)
>
> So far we have encountered just one SP that had this issue. I suspect
> they were using a homebrew SP of some sort. I quoted the line from the
> SAML standard that indicates that it is the SP's responsibility to deal
> with clock skew. After trying to see if there was some way we could
> apply an offset to our IdP's NotBefores (we said no), they eventually
> took it back to their development team.
>
> Not sure how their SP would behave without a NotBefore...
> --
> %% Christopher A. Bongaarts %% cab at umn.edu %%
> %% OIT - Identity Management %% http://umn.edu/~cab %%
> %% University of Minnesota %% +1 (612) 625-1809 %%
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
--
Michael A. Grady
Senior IAM Consultant, Unicon, Inc.
More information about the users
mailing list