The "problem" is known - see here - and boils down to improper clock synchronization between the service provider and the identity provider.
They are probably now within 60 seconds, so from time to time they drop out of the synchronization boundary.
You can fix this:
- (best) synchronization of both systems with the same known time base via ntpd.
- submission to one of the two hours of the system to the other.
There are also more creative options, for example:
These two “solutions” are subject to errors and “missed” problems (that is, the clock does not carefully move from WRONG_TIME to CORRECT_TIME, they are directly set to the “correct” value). It may also have other unpleasant effects depending on other conditions / software.
Finally, you can modify the /saml/lib/Message.php modules and increase the time delta, even if it’s “documenting the problem”, assuming that there is some process that can hold both systems for no more than 60 "(there are some schemes for creating time schemes, not ntpd based that could do this).
LSerni
source share