IdP > SP TImestamps older than 30 days
John Watt
John.Watt at glasgow.ac.uk
Thu Sep 17 10:06:33 UTC 2026
Hi Dave,
I'm a bit wary we were solving a different issue from you, but [1] describes where to put that setting in the SAML.SSO profile config bean, for us we use metadata driven so it was:
<bean parent="SAML2.SSO.MDDriven" p:proxiedAuthnInstant="false"/>
Thanks
John
[1] https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199505973/SAMLAuthnConfiguration#Authentication-Time
________________________________
From: Dave Perry <d.perry1 at yorksj.ac.uk>
Sent: 17 September 2026 10:54
To: John Watt <John.Watt at glasgow.ac.uk>; Shib Users <users at shibboleth.net>
Subject: Re: IdP > SP TImestamps older than 30 days
Hi John
Would you mind sharing that snippet please, and where to put it?
When I got JISC help setting up the 365 proxying, this was never mentioned as a potential gotcha.
Thanks
Dave
_________________________________________________
Dave Perry
Application Analyst | Innovation & Technology Services
York St John University
Lord Mayor’s Walk, York, YO31 7EX
T: +44(0)1904 876 0000
d.perry1 at yorksj.ac.uk<mailto:d.perry1 at yorksj.ac.uk> | www.yorksj.ac.uk<http://www.yorksj.ac.uk/>
[cid:85e6295b-777f-42be-8ef9-19e0c1ec0534]
________________________________
From: John Watt <John.Watt at glasgow.ac.uk>
Sent: Thursday, September 17, 2026 10:52 AM
To: Dave Perry <d.perry1 at yorksj.ac.uk>; Shib Users <users at shibboleth.net>
Subject: Re: IdP > SP TImestamps older than 30 days
Caution: Please take care when clicking on links or opening attachments in emails that originate from outside of the university. When in doubt, contact the ITS service desk.
Hi Dave,
I'm not sure, I would assume so, or some override at least.
We apply it globally as we run a hybrid O365 SAML proxy/Local LDAP authN and we needed that setting so our timeouts would be honoured.
Cheers,
John
________________________________
From: Dave Perry <d.perry1 at yorksj.ac.uk>
Sent: 17 September 2026 10:38
To: John Watt <John.Watt at glasgow.ac.uk>; Shib Users <users at shibboleth.net>
Subject: Re: IdP > SP TImestamps older than 30 days
Thanks John.
Would I need to setup a relying party just for this provider then?
Thanks
Dave
_________________________________________________
Dave Perry
Application Analyst | Innovation & Technology Services
York St John University
Lord Mayor’s Walk, York, YO31 7EX
T: +44(0)1904 876 0000
d.perry1 at yorksj.ac.uk<mailto:d.perry1 at yorksj.ac.uk> | www.yorksj.ac.uk<http://www.yorksj.ac.uk/>
[cid:c813aec3-f2c6-49e5-95a3-bbc6001006cc]
________________________________
From: John Watt <John.Watt at glasgow.ac.uk>
Sent: Thursday, September 17, 2026 10:31 AM
To: Shib Users <users at shibboleth.net>
Cc: Dave Perry <d.perry1 at yorksj.ac.uk>
Subject: Re: IdP > SP TImestamps older than 30 days
Caution: Please take care when clicking on links or opening attachments in emails that originate from outside of the university. When in doubt, contact the ITS service desk.
Hi Dave,
We use the proxiedAuthnInstant="false" in the Relying Party config to allow us more control over that timestamp.
Cheers,
John
________________________________
From: users <users-bounces at shibboleth.net> on behalf of Dave Perry via users <users at shibboleth.net>
Sent: 17 September 2026 10:24
To: Shib Users <users at shibboleth.net>
Cc: Dave Perry <d.perry1 at yorksj.ac.uk>
Subject: Re: IdP > SP TImestamps older than 30 days
Peter
Fair point in that regard.
The IdP is SAML proxying to 365 (instead of using LDAP previously) - usually a lookup from IdP to 365 only takes place when a new browser session has been opened (e.g. restarting Edge after an update).
If there is a setting that can make these SAML proxy lookups more frequent, that would be great to try.
We are running IdP v5.2.3 in case that makes a difference.
Thanks
Dave
_________________________________________________
Dave Perry
Application Analyst | Innovation & Technology Services
York St John University
Lord Mayor’s Walk, York, YO31 7EX
T: +44(0)1904 876 0000
d.perry1 at yorksj.ac.uk<mailto:d.perry1 at yorksj.ac.uk> | www.yorksj.ac.uk<http://www.yorksj.ac.uk/>
[cid:208e165d-3eb7-4560-ac78-6bdfb0082c0e]
________________________________
From: users <users-bounces at shibboleth.net> on behalf of Peter Schober via users <users at shibboleth.net>
Sent: Thursday, September 17, 2026 10:01 AM
To: users at shibboleth.net <users at shibboleth.net>
Cc: Peter Schober <peter.schober at univie.ac.at>
Subject: Re: IdP > SP TImestamps older than 30 days
Caution: Please take care when clicking on links or opening attachments in emails that originate from outside of the university. When in doubt, contact the ITS service desk.
Dave Perry via users <users at shibboleth.net> [2026-09-17 10:38 CEST]:
> > We've identified the cause of the access issue. Your identity
> > provider (IdP) is sending authentication timestamps that are too
> > old; for security reasons, our system only accepts timestamps no
> > older than 30 days.
>
> How on earth is this a thing? No other provider is complaining about
> a timestamp difference, and our internal server team have confirmed
> that our VMs have been time locked to our Domain Controllers (which
> in turn are locked to JISC NTP sources).
I read "authentication timestamps" as relating to the point in time
when the subject initially authenticated (and then continuing to enjoy
SSO without explicit authentication), not your IDP's clock.
If so, I don't think it's unreasonable to reject assertions with an
authentication event a month in the past. Are your SSO sessions really
that long? Or could this be a misconfiguration of your IDP?
-peter
--
For Consortium Member technical support, see https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C02%7Cd.perry1%40yorksj.ac.uk%7Cc8ca0d0966024aa0f68708df149a4e9f%7C5c8ae38ef85b4309b7ec862815a37aee%7C0%7C0%7C639252325145182873%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=hyAYXYGRi83q8xp97OQswVy14NQ47chGSiCdhme5rJY%3D&reserved=0<https://shibboleth.atlassian.net/wiki/x/ZYEpPw>
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260917/69a85e6e/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image.png
Type: image/png
Size: 12155 bytes
Desc: image.png
URL: <http://shibboleth.net/pipermail/users/attachments/20260917/69a85e6e/attachment.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image.png
Type: image/png
Size: 12155 bytes
Desc: image.png
URL: <http://shibboleth.net/pipermail/users/attachments/20260917/69a85e6e/attachment-0001.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image.png
Type: image/png
Size: 12155 bytes
Desc: image.png
URL: <http://shibboleth.net/pipermail/users/attachments/20260917/69a85e6e/attachment-0002.png>
More information about the users
mailing list