IDP reports: Message was expired but times look valid

Brent Putman putmanb at georgetown.edu
Thu Nov 14 13:30:33 EST 2013


On 11/14/13 11:20 AM, Douglas E. Engert wrote:
>
> 16:59:28.235 - WARN [org.opensaml.common.binding.security.IssueInstantRule:108] - Message was expired: message issue time was '2013-11-13T10:59:26.348Z', message expired at: 
> '2013-11-13T11:05:26.348Z', current time: '2013-11-13T16:59:28.235-06:00'

Paul's math is correct.  At the IdP, it's 16:59:28 local time, which is
22:59:28 UTC  (local + 6 hours, which is consistent with Chicago Central
Time)


>
> <samlp:AuthnRequest
>
>     IssueInstant="2013-11-13T10:59:26.348Z"


The SP created the message with an IssueInstant of 10:59:26 UTC  (which
btw would be 04:59:26 local Chicago time).

Allowing for a couple of seconds for transmission and processing and
minor clock drift, that's just about exactly 12hours earlier than the
IdP's clock.  So my off-the-cuff guess would be that the SP's clock is
set to AM time instead PM time. Or the IdP's is similarly set
incorrectly.  Or something like that.



More information about the users mailing list