Troubleshooting: SAML Assertions Fail Due to Clock Discrepancies

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    SAML assertions can fail due to clock discrepancies between the IdP and a SAML Service Provider (SP). This can manifest as an intermittent or a consistent failure -- how end users perceive it varies by SP, but it usually appears to be an authentication failure. See Troubleshooting: Clock Skew of Message Is Outside Threshold During API Call for the equivalent clock-skew setting for API calls, which is separate from SAML assertion timing.

     

    Cause

    Clock synchronization is an important aspect of SAML. If an assertion is made for too far in the past or too far in the future, it fails. Typical tolerances range from 5 to 30 seconds but can be more stringent or more relaxed depending on the SP.

     

    Resolution:

    Ensure that the clock is accurately set on the IdP -- using NTP is the preferred way to achieve this. Where the SP is out of sync with atomic time, or has particularly stringent timing requirements, set a non-zero value for SAML Offset Minutes on the Post Authentication tab of the realm making the assertion.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.