NotBefore condition in assertions

Christopher Bongaarts cab at umn.edu
Mon Oct 22 15:22:27 EDT 2012


On 10/21/2012 4:43 PM, Michael A Grady wrote:

> I can say that we were interacting with a vendor that refused to
> allow for skew. They already have a lot of commercial partners that
> were using a variety of commercial IdPs that apparently support
> adjusting NotBefore, so this SP is insistent on the IdP making the
> adjustment, and have been successful in getting their partners to do
> so.  Using a different vendor was not an option at this time
> (unfortunately), so I did make a simple change to the Shib IdP to
> remove NotBefore from the assertions.

What I told our vendor was quoted from the SAML2 errata[1]:

         SAML system entities SHOULD allow for reasonable clock skew
         between systems when interpreting time instants and enforcing
         security policies based on them. Tolerances of 3-5 minutes are
         reasonable defaults, but allowing for configurability is a
         suggested practice in implementations.

Note that the skew is handled when *interpreting* and *enforcing*, not 
when *generating* time instants.


[1] SAML Version 2.0 Errata 05. 01 May 2012. OASIS Approved Errata. 
http://docs.oasis-open.org/security/saml/v2.0/errata05/os/saml-v2.0-errata05-os.html 
. Errata E92, line 1542.
-- 
%%  Christopher A. Bongaarts   %%  cab at umn.edu          %%
%%  OIT - Identity Management  %%  http://umn.edu/~cab  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%


More information about the users mailing list