Clock Skew Problems with Shibboleth
Shibboleth
IdP and SPs relies on SAML assertions being passed between for exchanging handles and attributes. Each assertion is signed and timestamp with a date of when it is valid. If the system clock between the two end systems are not in sync, then the receiving end will receive an assertion that it either consider no longer valid/expire, or is not yet valid. As a result, end users will see error messages saying the assertion has expired.
Check
Clock Skewed and
Assertion Condition Invalid
to top