Have you been able to confirm the time difference? I’m not trying to take their side of things, but if it’s minutes off, I wouldn’t doubt that’s possible. SSO is highly secure, right? A time difference might be enough to throw it off?
Here’s reference: https://support.pingidentity.com/s/article/Accounting-for-Time-Drift-Between-SAML-Endpoints50907 From: cisco-voip <cisco-voip-boun...@puck.nether.net> On Behalf Of Jonathan Charles Sent: Thursday, September 16, 2021 6:23 PM To: Benjamin Turner <benmtur...@hotmail.com> Cc: cisco-voip@puck.nether.net Subject: Re: [cisco-voip] Error Processing SAML Response CAUTION: This email originated from outside of the University of Guelph. Do not click links or open attachments unless you recognize the sender and know the content is safe. If in doubt, forward suspicious emails to ith...@uoguelph.ca<mailto:ith...@uoguelph.ca> No... TBH, I have never heard of it... TAC is hyper-asserting that the issue is time mismatch between CUCM/CUC and ADFS... Jonathan On Thu, Sep 16, 2021 at 4:08 PM Benjamin Turner <benmtur...@hotmail.com<mailto:benmtur...@hotmail.com>> wrote: Have you tried to run a SAML Tracer? Sincerely, Benjamin M. Turner ________________________________ From: cisco-voip <cisco-voip-boun...@puck.nether.net<mailto:cisco-voip-boun...@puck.nether.net>> on behalf of Jonathan Charles <jonv...@gmail.com<mailto:jonv...@gmail.com>> Sent: Thursday, September 16, 2021 4:56:48 PM To: cisco-voip@puck.nether.net<mailto:cisco-voip@puck.nether.net> <cisco-voip@puck.nether.net<mailto:cisco-voip@puck.nether.net>> Subject: [cisco-voip] Error Processing SAML Response So, users are randomly getting the above error when logging into CUCM UCMUser or CUC Inbox... we are also getting it using AD credentials into admin pages for CUCM/CUC/etc. For a user, it will work find repeatedly, then you will get the error, close your browser, and reopen, still get the error for a few minutes. Then later it will work. When a user is affected, other users work fine. TAC is saying it is an NTP issue, however, NTP between CUCM 12.5 and IdP (ADFS 2.0) is fine. Pings are around 1ms between servers. Any ideas? Jonathan
_______________________________________________ cisco-voip mailing list cisco-voip@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-voip