Version Affected: All
Overview
SAML assertions can fail due to clock discrepancies between the IdP and a SAML Service Provider (SP). This can manifest as an intermittent or a consistent failure -- how end users perceive it varies by SP, but it usually appears to be an authentication failure. See Troubleshooting: Clock Skew of Message Is Outside Threshold During API Call for the equivalent clock-skew setting for API calls, which is separate from SAML assertion timing.
Cause
Clock synchronization is an important aspect of SAML. If an assertion is made for too far in the past or too far in the future, it fails. Typical tolerances range from 5 to 30 seconds but can be more stringent or more relaxed depending on the SP.
Resolution:
Ensure that the clock is accurately set on the IdP -- using NTP is the preferred way to achieve this. Where the SP is out of sync with atomic time, or has particularly stringent timing requirements, set a non-zero value for SAML Offset Minutes on the Post Authentication tab of the realm making the assertion.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.