Hi,

I have CAS 6.2 configured to authenticate against Azure AD, I have some 
users that are getting an error:

org.pac4j.saml.exceptions.SAMLAuthnInstantException: Authentication issue 
instant is too old or in the future

It seems to be browser/PC dependent, if they try a different PC it is OK, 
the assertion seems to be very old in some cases (months old). It only 
seems to affect CAS based SAML logins though, authenticating against Azure 
AD directly for O365 for example works as expected.

I know I can workaround this by increasing the setting but does anyone know 
why I would need to (I already have it set for about 3 months and need to 
increase it further and I am guessing would have to do this again in the 
future if I cannot find the cause.

Thanks

Sean

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to cas-user+unsubscr...@apereo.org.
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/60e4cb0e-9f3d-4bfd-acae-5144020f745cn%40apereo.org.

Reply via email to