I had that error one Time,
The main cause was the différence of date between the server of cas and the
server of applications... 3 minutes
And WE had exactly the same error message.


Arnauld Peyrou
Inrap
Chef de service Infrastructure et Sécurité.
121 rue d'Alésia 75014
07 62 60 45 63 / 01 40 08 80 48

Le jeu. 30 nov. 2023, 11:31, Mohamed Amdouni <[email protected]> a
écrit :

> Hello,
>
> When comparing the behavior between cas 5.X and cas 6.X there are some
> differences in building the SAML2 Response :
>
> *CAS 5.X :*
> The authenticationDate is returned from the validateTicket method here
> <https://github.com/apereo/cas/blob/ebf8a8e192ca0569ef92f95421039ad68b44fe3d/support/cas-server-support-saml-idp-web/src/main/java/org/apereo/cas/support/saml/web/idp/profile/sso/SSOSamlProfileCallbackHandlerController.java#L129>
> which uses an updated date from the ST ticket, not the TGT one.
> Assertions (AuthnDate)  are built from the ST Ticket.
>
> *CAS 6.X : *
> The build cas assertions method here
> <https://github.com/apereo/cas/blob/7dc053c83bde300b50027d70b5102a391057435c/support/cas-server-support-saml-idp-web/src/main/java/org/apereo/cas/support/saml/web/idp/profile/AbstractSamlIdPProfileHandlerController.java#L150>
> uses the authenticationDate of the TGT ticket which is an old date, so if
> the TGT timeout is set to more than 2Hours Spring Saml2 Clients will reject
> the response because it's an old date.
> Assertions (AuthnDate) are built from TGT ticket.
>
> Is it a bug ? Is there a property that will restore the old behavior?
>
> Thank you.
>
>
>
> Le ven. 24 nov. 2023 à 16:59, Mohamed Amdouni <[email protected]> a
> écrit :
>
>> Hello,
>>
>> When I test with the old version of cas 5.3.X (same saml client) -->
>> there is no issue even after 1hour2 or 3 hours.
>>
>> When I test with the new version 6.6.X (same SAML client) --> first
>> response OK , second OK, after 2 hours : problem with the SAML response : 
>> Authentication
>> statement is too old error
>>
>> The same configuration of TGT  (10H) and st timeouts is applicable for
>> the two versions :
>>
>>
>>    - cas.ticket.tgt.timeout.max-time-to-live-in-seconds=36000
>>    - cas.ticket.st.time-to-kill-in-seconds=120
>>
>>
>> The problem is with the SAML response which is different in the two
>> versions. In version 6.6.X the saml:AuthnStatement/AuthnInstance is not
>> updated. In the version 5.3.X the date is updated even if it is with the
>> same TGT, so the client does not display error messages.
>>
>>
>> Do you know which parameter in cas 6.6.X that update the *AuthnInstance*
>> when used with the same TGT but not the same ST?
>>
>> Thank you.
>>
>>
>>
>> Best Regards,
>>
>> Le jeudi 23 novembre 2023 à 06:38:55 UTC+1, Mohamed Amdouni a écrit :
>>
>>> Hello,
>>>
>>> I’m testing a saml client after cas migration from 5.3 to 6.6.
>>>
>>> The saml authentication is processed successfully ( using spnego &
>>> Kerberos): no login details are entered, the spnego token is sent and
>>> validated .After a long idle period, if I refresh the page I got an error
>>> on the wall client saying that « Authentication statement is too long »
>>> which is not the cas in the old version 5.
>>> No error are generated in the cas server.
>>>
>>> I would like to know if there are some default values that are not used
>>> any more in the new version of cas that could be related to this issue.
>>>
>>>
>>> I also detected that the time zone is no more sent in the assertions.
>>>
>>> It seems that the locale are no more detected automatically ? No value
>>> are specified in the old version but the time zone is returned in the
>>> assertions.
>>>
>>> In debug mode some locale error are detected about messages but the
>>> langage is correct when cas displays some screens ( I don’t have any custom
>>> translation)
>>>
>>> Thank you.
>>>
>>>
>>>
>>> --
> - Website: https://apereo.github.io/cas
> - Gitter Chatroom: https://gitter.im/apereo/cas
> - List Guidelines: https://goo.gl/1VRrw7
> - Contributions: https://goo.gl/mh7qDG
> ---
> You received this message because you are subscribed to the Google Groups
> "CAS Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> To view this discussion on the web visit
> https://groups.google.com/a/apereo.org/d/msgid/cas-user/CALmwvcZfkWhiYx2OV2ZzXPAwrDNDt420Ms96p%3DVP8-KRPJMQLQ%40mail.gmail.com
> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/CALmwvcZfkWhiYx2OV2ZzXPAwrDNDt420Ms96p%3DVP8-KRPJMQLQ%40mail.gmail.com?utm_medium=email&utm_source=footer>
> .
>

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAE5VfR1SqywkBLSr5fEeX%3DHeXjK5MVL5n2A31wE%3DAz1zUF87-w%40mail.gmail.com.

Reply via email to