IdP > SP TImestamps older than 30 days

Peter Schober peter.schober at univie.ac.at
Thu Sep 17 09:01:27 UTC 2026


Dave Perry via users <users at shibboleth.net> [2026-09-17 10:38 CEST]:
> > We've identified the cause of the access issue. Your identity
> > provider (IdP) is sending authentication timestamps that are too
> > old; for security reasons, our system only accepts timestamps no
> > older than 30 days.
> 
> How on earth is this a thing? No other provider is complaining about
> a timestamp difference, and our internal server team have confirmed
> that our VMs have been time locked to our Domain Controllers (which
> in turn are locked to JISC NTP sources).

I read "authentication timestamps" as relating to the point in time
when the subject initially authenticated (and then continuing to enjoy
SSO without explicit authentication), not your IDP's clock.

If so, I don't think it's unreasonable to reject assertions with an
authentication event a month in the past. Are your SSO sessions really
that long? Or could this be a misconfiguration of your IDP?

-peter


More information about the users mailing list