<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
Vanna,
<div class=""><br class="">
</div>
<div class="">
<div>
<blockquote type="cite" class="">
<div class="">
<div class="WordSection1" style="page: WordSection1; font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;">
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
We are having an issue with one of the SPs. AuthInstant is a second before the validity time period. So, the SP is receiving the expired certificate error. How to match them?</div>
</div>
</div>
</blockquote>
<div><br class="">
</div>
<div>I’m not sure that I’m getting your question completely. &nbsp;I can’t think through why an AuthnInstant could be related to a certificate expiration, though, so I’m going to guess you meant assertion.</div>
<div><br class="">
</div>
<blockquote type="cite" class="">
<div class="WordSection1" style="page: WordSection1; font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;">
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
<o:p class=""></o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
We even tried server ntp restart.<o:p class=""></o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
<span style="color: rgb(31, 73, 125);" class="">&lt;saml2:Conditions NotBefore=&quot;2014-11-19T01:38:01.167Z&quot; NotOnOrAfter=&quot;2014-11-19T01:43:01.167Z&quot;&gt;</span><o:p class=""></o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
<span style="color: rgb(31, 73, 125);" class="">&lt;saml2:AuthnStatement AuthnInstant=&quot;2014-11-19T01:38:00.620Z”</span></div>
</div>
</blockquote>
<br class="">
</div>
</div>
<div>These timestamps seem very close and acceptable to most SP’s. &nbsp;I would be more suspicious of the SP than your IdP. &nbsp;They need to permit for some modest amount of clock skew.</div>
<div><br class="">
</div>
<div>Hope this helps,</div>
<div>Nate.</div>
</body>
</html>