NotBefore condition in assertions
Christopher Bongaarts
cab at umn.edu
Mon Oct 22 15:22:27 EDT 2012
On 10/21/2012 4:43 PM, Michael A Grady wrote:
> I can say that we were interacting with a vendor that refused to
> allow for skew. They already have a lot of commercial partners that
> were using a variety of commercial IdPs that apparently support
> adjusting NotBefore, so this SP is insistent on the IdP making the
> adjustment, and have been successful in getting their partners to do
> so. Using a different vendor was not an option at this time
> (unfortunately), so I did make a simple change to the Shib IdP to
> remove NotBefore from the assertions.
What I told our vendor was quoted from the SAML2 errata[1]:
SAML system entities SHOULD allow for reasonable clock skew
between systems when interpreting time instants and enforcing
security policies based on them. Tolerances of 3-5 minutes are
reasonable defaults, but allowing for configurability is a
suggested practice in implementations.
Note that the skew is handled when *interpreting* and *enforcing*, not
when *generating* time instants.
[1] SAML Version 2.0 Errata 05. 01 May 2012. OASIS Approved Errata.
http://docs.oasis-open.org/security/saml/v2.0/errata05/os/saml-v2.0-errata05-os.html
. Errata E92, line 1542.
--
%% Christopher A. Bongaarts %% cab at umn.edu %%
%% OIT - Identity Management %% http://umn.edu/~cab %%
%% University of Minnesota %% +1 (612) 625-1809 %%
More information about the users
mailing list