Forum Discussion
ASSERTION_SUBJECT_CONFIRM_NOTONORAFTER not respected
Hi!
I'm using APM to implement a SAML SP.
APM will successfully validate a SAMLResponse even if the time specified by NotOnOrAfter in the SubjectConfirmationData element has passed. Shouldn't this fail? Is there a setting I'm missing?
From my log:
Apr 28 11:19:25 bigip-test debug apd[11857]: 01490000:7: modules/Authentication/Saml/SamlSPAgent.cpp func: "parseAssertion()" line: 3578 Msg: ASSERTION_SUBJECT_CONFIRM_NOTONORAFTER: (24) 2015-04-27T12:01:59.204Z
Apr 28 11:19:25 bigip-test debug apd[11857]: 01490000:7: modules/Authentication/Saml/SamlSPAgent.cpp func: "verifyAssertionSignature()" line: 4614 Msg: Verification of SAML Signature 1 is Successfull
Notice from the log timestamps that the system time during message verification is well after ASSERTION_SUBJECT_CONFIRM_NOTONORAFTER.
3 Replies
- kunjan
Nimbostratus
It is a bug. You may want to raise a support case and get the fix.
- Ingebrigt_Maurs
Nimbostratus
Bug ID for this is BZ520610
- Ingebrigt_Maurs
Nimbostratus
Any progress on this?
NotOnOrAfter is in there to ensure SAML tokens do not remain valid forever, so IMHO a pretty important security feature.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com