<div dir="ltr"><div>Hey Scott,<br><br>I use all the default timeouts across the board and I couldn't find anything that would explain a 2 minute timeout.   Can you elaborate more on the SameSite issue/mistake?    You might be on to something, but I need to know specifically what to look for.  </div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><br>--<br><br>Thanks,<br><br>Dan</div></div></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Fri, Jun 5, 2026 at 11:55 AM Scott Cantor <<a href="mailto:scott@restingparrotsoftware.com">scott@restingparrotsoftware.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><br>
<br>
> On Jun 5, 2026, at 12:28 PM, Dan McLaughlin <<a href="mailto:dmclaughlin@tech-consortium.com" target="_blank">dmclaughlin@tech-consortium.com</a>> wrote:<br>
> <br>
> To clarify the timeout issue: it occurs when a user is proxied to the MFA provider and takes more than two minutes to enter their code and return to the SP. By that point, the SP session has expired, resulting in the error: "The gap between now and the time you logged into your identity provider exceeds the allowed limit."<br>
<br>
There is (mostly) no SP limit, I assume you mean the IdP. But that is not 2 minutes, it's more like 15 or more, though it's up to you what it is, that's set in web.xml or more often globally.<br>
<br>
Don't, FWIW, confuse SameSite issues with that. A SameSite mistake only breaks Chrome and that is 2 minutes.<br>
<br>
-- Scott<br>
<br>
</blockquote></div>