NotBefore condition in assertions

Christopher Bongaarts cab at umn.edu
Tue Oct 23 11:39:31 EDT 2012


On 10/22/2012 4:15 PM, Michael A Grady wrote:
>> Even if you're well-configured, you still can't avoid sub-second
>> differences in time.
>
> Yes, the differences in the use case I cited were almost all
> sub-second. This was even with ensuring syncing to the same time
> sources. Things would be fine for awhile, and then get milliseconds
> off and cause problems. And when an SP is applying the NotBefore
> check without *any* allowance for skew, then a millisecond is all it
> takes to invalidate the assertion.

Amusingly(?) enough, we first noticed this problem shortly after the 
Leap Second Fiasco, when our (Linux) IdP's ntpds had all been killed off 
to work around the problem, but didn't get restarted.  The time slowly 
drifted off on the machines, and the sub-millisecond accuracy fell to 
tenths of seconds, then whole seconds, and we started to notice. :D

-- 
%%  Christopher A. Bongaarts   %%  cab at umn.edu          %%
%%  OIT - Identity Management  %%  http://umn.edu/~cab  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%


More information about the users mailing list