I had that error one Time, The main cause was the différence of date between the server of cas and the server of applications... 3 minutes And WE had exactly the same error message.
Arnauld Peyrou Inrap Chef de service Infrastructure et Sécurité. 121 rue d'Alésia 75014 07 62 60 45 63 / 01 40 08 80 48 Le jeu. 30 nov. 2023, 11:31, Mohamed Amdouni <[email protected]> a écrit : > Hello, > > When comparing the behavior between cas 5.X and cas 6.X there are some > differences in building the SAML2 Response : > > *CAS 5.X :* > The authenticationDate is returned from the validateTicket method here > <https://github.com/apereo/cas/blob/ebf8a8e192ca0569ef92f95421039ad68b44fe3d/support/cas-server-support-saml-idp-web/src/main/java/org/apereo/cas/support/saml/web/idp/profile/sso/SSOSamlProfileCallbackHandlerController.java#L129> > which uses an updated date from the ST ticket, not the TGT one. > Assertions (AuthnDate) are built from the ST Ticket. > > *CAS 6.X : * > The build cas assertions method here > <https://github.com/apereo/cas/blob/7dc053c83bde300b50027d70b5102a391057435c/support/cas-server-support-saml-idp-web/src/main/java/org/apereo/cas/support/saml/web/idp/profile/AbstractSamlIdPProfileHandlerController.java#L150> > uses the authenticationDate of the TGT ticket which is an old date, so if > the TGT timeout is set to more than 2Hours Spring Saml2 Clients will reject > the response because it's an old date. > Assertions (AuthnDate) are built from TGT ticket. > > Is it a bug ? Is there a property that will restore the old behavior? > > Thank you. > > > > Le ven. 24 nov. 2023 à 16:59, Mohamed Amdouni <[email protected]> a > écrit : > >> Hello, >> >> When I test with the old version of cas 5.3.X (same saml client) --> >> there is no issue even after 1hour2 or 3 hours. >> >> When I test with the new version 6.6.X (same SAML client) --> first >> response OK , second OK, after 2 hours : problem with the SAML response : >> Authentication >> statement is too old error >> >> The same configuration of TGT (10H) and st timeouts is applicable for >> the two versions : >> >> >> - cas.ticket.tgt.timeout.max-time-to-live-in-seconds=36000 >> - cas.ticket.st.time-to-kill-in-seconds=120 >> >> >> The problem is with the SAML response which is different in the two >> versions. In version 6.6.X the saml:AuthnStatement/AuthnInstance is not >> updated. In the version 5.3.X the date is updated even if it is with the >> same TGT, so the client does not display error messages. >> >> >> Do you know which parameter in cas 6.6.X that update the *AuthnInstance* >> when used with the same TGT but not the same ST? >> >> Thank you. >> >> >> >> Best Regards, >> >> Le jeudi 23 novembre 2023 à 06:38:55 UTC+1, Mohamed Amdouni a écrit : >> >>> Hello, >>> >>> I’m testing a saml client after cas migration from 5.3 to 6.6. >>> >>> The saml authentication is processed successfully ( using spnego & >>> Kerberos): no login details are entered, the spnego token is sent and >>> validated .After a long idle period, if I refresh the page I got an error >>> on the wall client saying that « Authentication statement is too long » >>> which is not the cas in the old version 5. >>> No error are generated in the cas server. >>> >>> I would like to know if there are some default values that are not used >>> any more in the new version of cas that could be related to this issue. >>> >>> >>> I also detected that the time zone is no more sent in the assertions. >>> >>> It seems that the locale are no more detected automatically ? No value >>> are specified in the old version but the time zone is returned in the >>> assertions. >>> >>> In debug mode some locale error are detected about messages but the >>> langage is correct when cas displays some screens ( I don’t have any custom >>> translation) >>> >>> Thank you. >>> >>> >>> >>> -- > - Website: https://apereo.github.io/cas > - Gitter Chatroom: https://gitter.im/apereo/cas > - List Guidelines: https://goo.gl/1VRrw7 > - Contributions: https://goo.gl/mh7qDG > --- > You received this message because you are subscribed to the Google Groups > "CAS Community" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > To view this discussion on the web visit > https://groups.google.com/a/apereo.org/d/msgid/cas-user/CALmwvcZfkWhiYx2OV2ZzXPAwrDNDt420Ms96p%3DVP8-KRPJMQLQ%40mail.gmail.com > <https://groups.google.com/a/apereo.org/d/msgid/cas-user/CALmwvcZfkWhiYx2OV2ZzXPAwrDNDt420Ms96p%3DVP8-KRPJMQLQ%40mail.gmail.com?utm_medium=email&utm_source=footer> > . > -- - Website: https://apereo.github.io/cas - Gitter Chatroom: https://gitter.im/apereo/cas - List Guidelines: https://goo.gl/1VRrw7 - Contributions: https://goo.gl/mh7qDG --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAE5VfR1SqywkBLSr5fEeX%3DHeXjK5MVL5n2A31wE%3DAz1zUF87-w%40mail.gmail.com.
