IdP > SP TImestamps older than 30 days

John Watt John.Watt at glasgow.ac.uk
Thu Sep 17 09:31:04 UTC 2026


Hi Dave,

We use the proxiedAuthnInstant="false" in the Relying Party config to allow us more control over that timestamp.

Cheers,
John
________________________________
From: users <users-bounces at shibboleth.net> on behalf of Dave Perry via users <users at shibboleth.net>
Sent: 17 September 2026 10:24
To: Shib Users <users at shibboleth.net>
Cc: Dave Perry <d.perry1 at yorksj.ac.uk>
Subject: Re: IdP > SP TImestamps older than 30 days

Peter

Fair point in that regard.

The IdP is SAML proxying to 365 (instead of using LDAP previously) - usually a lookup from IdP to 365 only takes place when a new browser session has been opened (e.g. restarting Edge after an update).

If there is a setting that can make these SAML proxy lookups more frequent, that would be great to try.
We are running IdP v5.2.3 in case that makes a difference.

Thanks
Dave

_________________________________________________

Dave Perry
Application Analyst  |  Innovation & Technology Services

York St John University

Lord Mayor’s Walk, York, YO31 7EX
T: +44(0)1904 876 0000
d.perry1 at yorksj.ac.uk<mailto:d.perry1 at yorksj.ac.uk>  |  www.yorksj.ac.uk<http://www.yorksj.ac.uk/>

[cid:208e165d-3eb7-4560-ac78-6bdfb0082c0e]

________________________________
From: users <users-bounces at shibboleth.net> on behalf of Peter Schober via users <users at shibboleth.net>
Sent: Thursday, September 17, 2026 10:01 AM
To: users at shibboleth.net <users at shibboleth.net>
Cc: Peter Schober <peter.schober at univie.ac.at>
Subject: Re: IdP > SP TImestamps older than 30 days

Caution: Please take care when clicking on links or opening attachments in emails that originate from outside of the university. When in doubt, contact the ITS service desk.


Dave Perry via users <users at shibboleth.net> [2026-09-17 10:38 CEST]:
> > We've identified the cause of the access issue. Your identity
> > provider (IdP) is sending authentication timestamps that are too
> > old; for security reasons, our system only accepts timestamps no
> > older than 30 days.
>
> How on earth is this a thing? No other provider is complaining about
> a timestamp difference, and our internal server team have confirmed
> that our VMs have been time locked to our Domain Controllers (which
> in turn are locked to JISC NTP sources).

I read "authentication timestamps" as relating to the point in time
when the subject initially authenticated (and then continuing to enjoy
SSO without explicit authentication), not your IDP's clock.

If so, I don't think it's unreasonable to reject assertions with an
authentication event a month in the past. Are your SSO sessions really
that long? Or could this be a misconfiguration of your IDP?

-peter
--
For Consortium Member technical support, see https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C02%7Cd.perry1%40yorksj.ac.uk%7Cc8ca0d0966024aa0f68708df149a4e9f%7C5c8ae38ef85b4309b7ec862815a37aee%7C0%7C0%7C639252325145182873%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=hyAYXYGRi83q8xp97OQswVy14NQ47chGSiCdhme5rJY%3D&reserved=0<https://shibboleth.atlassian.net/wiki/x/ZYEpPw>
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260917/8520dce0/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image.png
Type: image/png
Size: 12155 bytes
Desc: image.png
URL: <http://shibboleth.net/pipermail/users/attachments/20260917/8520dce0/attachment.png>


More information about the users mailing list