IdP > SP TImestamps older than 30 days

Dave Perry d.perry1 at yorksj.ac.uk
Thu Sep 17 08:37:57 UTC 2026


Hi all

I'm confused as hell about a statement a service provider (Clinicalkey Student, if anyone has heard of it), has given us about ongoing authentication failures via shibboleth:

We've identified the cause of the access issue. Your identity provider (IdP) is sending authentication timestamps that are too old; for security reasons, our system only accepts timestamps no older than 30 days.

How on earth is this a thing? No other provider is complaining about a timestamp difference, and our internal server team have confirmed that our VMs have been time locked to our Domain Controllers (which in turn are locked to JISC NTP sources).

If anyone has suggestions how we tackle this (either side), they would be appreciated.


Thanks
Dave

_________________________________________________

Dave Perry
Application Analyst  |  Innovation & Technology Services

York St John University

Lord Mayor’s Walk, York, YO31 7EX
T: +44(0)1904 876 0000
d.perry1 at yorksj.ac.uk<mailto:d.perry1 at yorksj.ac.uk>  |  www.yorksj.ac.uk<http://www.yorksj.ac.uk>

[cid:0a90e36d-39cc-47a9-8b45-6795ac38a038]
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260917/bfa2a4cb/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image.png
Type: image/png
Size: 12155 bytes
Desc: image.png
URL: <http://shibboleth.net/pipermail/users/attachments/20260917/bfa2a4cb/attachment.png>


More information about the users mailing list