Survey: (IssueInstant - AuthnInstant) vs. (SP local clock time - AuthnInstant) or SP clockskew
Cantor, Scott
cantor.2 at osu.edu
Tue Jun 30 20:52:56 EDT 2015
On 6/30/15, 7:20 PM, "users on behalf of Eric Goodman" <users-bounces at shibboleth.net on behalf of
>>
>>The timestamp for an External is set by the method if it wants to, so that doesn't really count.
>
>I'm not sure how I should interpret "doesn't really count" in this context.
I'm just saying that you specified "interactive login", and if that's the case, then it would normally be the case that even if the External method was feeding in the timestamp, it ought to be the current time or you're getting into one of those "strong authentication" cases where it isn't really clear what the login time really applies to.
> I think you mean your original response didn't address the External case, because you can't know what it does. But the expectation would still be that the value set should still represent the actual AuthnInstant, and so some External methods may have more variance than say, forms based LDAP from the IdP. Is that a correct interpretation?
No, I don't see what kind of "variance" you mean really. I'm just saying the time is normally set to whenever the method that runs returns, no matter what the method is, unless it's External, and in that case I still don't see what you're expecting would be different unless the External method is just lying.
>(For purposes of this whole thread I'm ignoring the different situations where an IdP might report a "current" AuthnInstant when the user hasn't performed any actual interactive authentication action.)
Right, so how can it possibly matter what method is used?
I think your original question is the relevant thing here, I don't think it really matters what login method is involved, that just muddies up the conversation.
-- Scott
More information about the users
mailing list