<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Hi Dave,</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
We use the proxiedAuthnInstant="false" in the Relying Party config to allow us more control over that timestamp.</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Cheers,</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
John</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Dave Perry via users <users@shibboleth.net><br>
<b>Sent:</b> 17 September 2026 10:24<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Dave Perry <d.perry1@yorksj.ac.uk><br>
<b>Subject:</b> Re: IdP > SP TImestamps older than 30 days</font>
<div> </div>
</div>
<style type="text/css" style="display:none">
<!--
p
        {margin-top:0;
        margin-bottom:0}
-->
</style>
<div dir="ltr">
<div class="x_elementToProof" style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Peter</div>
<div class="x_elementToProof" style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div class="x_elementToProof" style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Fair point in that regard.</div>
<div class="x_elementToProof" style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div class="x_elementToProof" style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
The IdP is SAML proxying to 365 (instead of using LDAP previously) - usually a lookup from IdP to 365 only takes place when a new browser session has been opened (e.g. restarting Edge after an update).</div>
<div class="x_elementToProof" style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div class="x_elementToProof" style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
If there is a setting that can make these SAML proxy lookups more frequent, that would be great to try.</div>
<div class="x_elementToProof" style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
We are running IdP v5.2.3 in case that makes a difference.</div>
<div class="x_elementToProof" style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div class="x_elementToProof" style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Thanks</div>
<div class="x_elementToProof" style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Dave</div>
<div id="x_Signature" class="x_elementToProof">
<div class="x_elementToProof" style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div class="x_elementToProof" style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:10pt; color:rgb(0,0,0)">
_________________________________________________</div>
<table style="box-sizing:border-box; border-collapse:collapse; border-spacing:0px">
<tbody>
<tr>
<td style="padding:0cm 5.4pt; vertical-align:top; width:303.75pt; height:96.45pt">
<p class="x_elementToProof" style="line-height:120%; margin:0cm; font-family:Calibri,sans-serif; font-size:11pt">
<span style="font-family:Arial,sans-serif; font-size:10pt"><b>Dave Perry</b></span><span style="font-family:"Times New Roman",serif; font-size:12pt"><br>
</span><span style="font-family:Arial,sans-serif; font-size:9pt">Application Analyst 
<b>|  </b>Innovation & Technology Services<br>
<br>
York St John University </span></p>
<p class="x_elementToProof" style="line-height:120%; margin:0cm; font-family:Calibri,sans-serif; font-size:11pt">
<span style="font-family:Arial,sans-serif; font-size:9pt">Lord Mayor’s Walk, York, YO31 7EX<br>
T: +44(0)1904 876 0000<br>
</span><a href="mailto:d.perry1@yorksj.ac.uk" id="OWAd897a794-a813-500a-9712-4ec92cab14ee" class="x_OWAAutoLink" title="mailto:d.perry1@yorksj.ac.uk" style="margin-top:0px; margin-bottom:0px">d.perry1@yorksj.ac.uk</a><span style="font-family:Arial,sans-serif; font-size:9pt"> 
<b>|  </b><a href="http://www.yorksj.ac.uk/" originalsrc="http://www.yorksj.ac.uk/" id="OWA0b480e2c-00f6-18d2-aded-ecdd64fb868a" class="x_OWAAutoLink" style="margin-top:0px; margin-bottom:0px">www.yorksj.ac.uk</a> </span></p>
</td>
</tr>
<tr>
<td style="padding:0cm 5.4pt; vertical-align:top; width:303.75pt; height:74.7pt">
<p class="x_elementToProof" style="margin:0cm; font-family:Calibri,sans-serif; font-size:11pt">
<span style="font-family:Arial,sans-serif; font-size:12pt"><b><img size="12155" style="max-width:100%; margin-top:0px; margin-bottom:0px" data-outlook-trace="F:2|T:2" src="cid:208e165d-3eb7-4560-ac78-6bdfb0082c0e"> </b></span></p>
</td>
</tr>
</tbody>
</table>
</div>
<div id="x_appendonsend"></div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Peter Schober via users <users@shibboleth.net><br>
<b>Sent:</b> Thursday, September 17, 2026 10:01 AM<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Cc:</b> Peter Schober <peter.schober@univie.ac.at><br>
<b>Subject:</b> Re: IdP > SP TImestamps older than 30 days</font>
<div> </div>
</div>
<div class="x_BodyFragment"><font size="2"><span style="font-size:11pt">
<div class="x_PlainText">Caution: Please take care when clicking on links or opening attachments in emails that originate from outside of the university. When in doubt, contact the ITS service desk.<br>
<br>
<br>
Dave Perry via users <users@shibboleth.net> [2026-09-17 10:38 CEST]:<br>
> > We've identified the cause of the access issue. Your identity<br>
> > provider (IdP) is sending authentication timestamps that are too<br>
> > old; for security reasons, our system only accepts timestamps no<br>
> > older than 30 days.<br>
><br>
> How on earth is this a thing? No other provider is complaining about<br>
> a timestamp difference, and our internal server team have confirmed<br>
> that our VMs have been time locked to our Domain Controllers (which<br>
> in turn are locked to JISC NTP sources).<br>
<br>
I read "authentication timestamps" as relating to the point in time<br>
when the subject initially authenticated (and then continuing to enjoy<br>
SSO without explicit authentication), not your IDP's clock.<br>
<br>
If so, I don't think it's unreasonable to reject assertions with an<br>
authentication event a month in the past. Are your SSO sessions really<br>
that long? Or could this be a misconfiguration of your IDP?<br>
<br>
-peter<br>
--<br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" originalsrc="https://shibboleth.atlassian.net/wiki/x/ZYEpPw">
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C02%7Cd.perry1%40yorksj.ac.uk%7Cc8ca0d0966024aa0f68708df149a4e9f%7C5c8ae38ef85b4309b7ec862815a37aee%7C0%7C0%7C639252325145182873%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=hyAYXYGRi83q8xp97OQswVy14NQ47chGSiCdhme5rJY%3D&reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</div>
</body>
</html>