<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: "Palatino Linotype", "Book Antiqua", Palatino, serif; font-size: 12pt; color: rgb(0, 0, 0);">
Hi,</div>
<div style="font-family: "Palatino Linotype", "Book Antiqua", Palatino, serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: "Palatino Linotype", "Book Antiqua", Palatino, serif; font-size: 12pt; color: rgb(0, 0, 0);">
We have an SP that's rejecting our SAML responses, apparently due to clock differences. The SP uses Unsolicited SAML requests, so I cannot see a SAML AuthnRequest and, thus far, I have no means of checking the SP's clock. The SP suggests that we set our NotBefore
 time back a minute. They offer an ADFS recipe:</div>
<div style="font-family: "Palatino Linotype", "Book Antiqua", Palatino, serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: "Palatino Linotype", "Book Antiqua", Palatino, serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="font-family: "Courier New", monospace; font-size: 11pt;">Set-ADFSRelyingPartyTrust -TargetIdentifier "$entityID" -NotBeforeSkew 1</span><br>
</div>
<div style="font-family: "Palatino Linotype", "Book Antiqua", Palatino, serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: "Palatino Linotype", "Book Antiqua", Palatino, serif; font-size: 12pt; color: rgb(0, 0, 0);">
and it's interesting that this ADFS feature exists.</div>
<div>
<div style="font-family: "Palatino Linotype", "Book Antiqua", Palatino, serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: "Palatino Linotype", "Book Antiqua", Palatino, serif; font-size: 12pt; color: rgb(0, 0, 0);">
But we're running Shibboleth, so that doesn't help us. And I don't think our system is the problem. Our servers appear to be within milliseconds of Stratus1 NTP servers. The clocks match time.gov and time.apple.com within a second.</div>
<div style="font-family: "Palatino Linotype", "Book Antiqua", Palatino, serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: "Palatino Linotype", "Book Antiqua", Palatino, serif; font-size: 12pt; color: rgb(0, 0, 0);">
But I wonder what the NotBefore tolerance is. We usually see that security data is valid for a few minutes with most protocols (e.g. NotOnOrAfter=(now + 5 minutes)), but what about NotBefore? How many seconds difference is permitted? If an SP is 5 seconds behind
 the IdP, will that break logins? Is it tunable?</div>
<div style="font-family: "Palatino Linotype", "Book Antiqua", Palatino, serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: "Palatino Linotype", "Book Antiqua", Palatino, serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thanks,</div>
<div style="font-family: "Palatino Linotype", "Book Antiqua", Palatino, serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: "Palatino Linotype", "Book Antiqua", Palatino, serif; font-size: 12pt; color: rgb(0, 0, 0);">
Paul</div>
<div id="Signature">
<div>
<div style="font-family:"Palatino Linotype","Book Antiqua",Palatino,serif; font-size:12pt; color:rgb(0,0,0)">
-- </div>
<div style="font-family:"Palatino Linotype","Book Antiqua",Palatino,serif; font-size:12pt; color:rgb(0,0,0)">
<span style="font-family:Arial,Helvetica,sans-serif; color:rgb(23,78,134)">Paul Fardy, Shib Admin, Info Security, ITS</span></div>
<div style="font-family:"Palatino Linotype","Book Antiqua",Palatino,serif; font-size:12pt; color:rgb(0,0,0)">
<span style="font-family:Arial,Helvetica,sans-serif; color:rgb(23,78,134)">University of Toronto</span></div>
</div>
</div>
</div>
</body>
</html>