OK that’s an easy one. Go ahead and submit a PR if you would please:
http://jasig.github.io/cas/developer/Contributor-Guidelines.html 
<http://jasig.github.io/cas/developer/Contributor-Guidelines.html>


- Misagh

> On Dec 1, 2015, at 2:07 PM, Abhijit Gaikwad <[email protected]> wrote:
> 
> Hey Misagh,
>  Thanks for pushing the fix for the issue. In addition to the skew I am also 
> having an issue with the dates themselves, specifically the time zones. I 
> have been testing with the custom code as you suggested and the below 
> statement creates problems for me.
>  
> final DateTime currentDateTime = DateTime.parse(new 
> ISOStandardDateFormat().getCurrentDateAndTime());
> https://github.com/Jasig/cas/blob/4.1.x/cas-server-support-saml/src/main/java/org/jasig/cas/support/saml/authentication/principal/GoogleAccountsService.java#L171
>  
> <https://github.com/Jasig/cas/blob/4.1.x/cas-server-support-saml/src/main/java/org/jasig/cas/support/saml/authentication/principal/GoogleAccountsService.java#L171>
>  
> From what I can tell it creates a date and uses my local time (EST) but 
> creates a date object that is Zulu time (If I am understanding it correctly). 
> So no matter what the skew (unless it is > 5 hours as zulu time is about +5 
> hours eastern standard time) my authentication always expires.
>  
> If I change the above line in the code to just
> final DateTime currentDateTime = new DateTime();
>  
> It creates a time that is close to UTC  which works fine.
>  
> I have ensured that my centos7 box has timezone and locale set to EST as seen 
> below. Is there something else I should be looking at in terms of timezones? 
> What am I missing?
>  
> #timedatectl
>       Local time: Tue 2015-12-01 15:48:32 EST
>   Universal time: Tue 2015-12-01 20:48:32 UTC
>         RTC time: Tue 2015-12-01 20:48:32
>         Timezone: America/New_York (EST, -0500)
>      NTP enabled: yes
> NTP synchronized: yes
> RTC in local TZ: no
>       DST active: no
> Last DST change: DST ended at
>                   Sun 2015-11-01 01:59:59 EDT
>                   Sun 2015-11-01 01:00:00 EST
> Next DST change: DST begins (the clock jumps one hour forward) at
>                   Sun 2016-03-13 01:59:59 EST
>                   Sun 2016-03-13 03:00:00 EDT
>  
> # locale
> LANG=en_US.UTF-8
> LC_CTYPE="en_US.UTF-8"
> LC_NUMERIC="en_US.UTF-8"
> LC_TIME="en_US.UTF-8"
> LC_COLLATE="en_US.UTF-8"
> LC_MONETARY="en_US.UTF-8"
> LC_MESSAGES="en_US.UTF-8"
> LC_PAPER="en_US.UTF-8"
> LC_NAME="en_US.UTF-8"
> LC_ADDRESS="en_US.UTF-8"
> LC_TELEPHONE="en_US.UTF-8"
> LC_MEASUREMENT="en_US.UTF-8"
> LC_IDENTIFICATION="en_US.UTF-8"
> LC_ALL=
>  
> Thanks,
> ---
> Abhijit Gaikwad
> Applications Programmer | T 321-674-8208 | [email protected] 
> <mailto:[email protected]>
>  
> From: [email protected] [mailto:[email protected]] On Behalf Of Abhijit 
> Gaikwad
> Sent: Monday, November 30, 2015 12:45 PM
> To: Misagh Moayyed; [email protected]
> Subject: RE: [cas-user] CAS 4.1.1 Google Apps SAML issue
>  
> I’m curious to know what the use case would be where one would want to 
> subtract a skew value. I’ll go ahead and create an issue for update the other 
> NotOnOrAfter value.
>  
> Thanks,
> ---
> Abhijit Gaikwad
> Applications Programmer | [email protected] <mailto:[email protected]>
>  
> From: [email protected] <mailto:[email protected]> 
> [mailto:[email protected] <mailto:[email protected]>] On Behalf Of Misagh 
> Moayyed
> Sent: Monday, November 30, 2015 10:08 AM
> To: [email protected] <mailto:[email protected]>
> Subject: Re: [cas-user] CAS 4.1.1 Google Apps SAML issue
>  
> Yes, we can skew both. Please do create an issue. 
>  
> - Misagh 
>  
> On Nov 30, 2015, at 6:41 AM, Abhijit Gaikwad <[email protected] 
> <mailto:[email protected]>> wrote:
>  
>  
> From: Abhijit Gaikwad 
> Sent: Tuesday, November 24, 2015 4:39 PM
> To: [email protected] <mailto:[email protected]>
> Subject: RE: [cas-user] CAS 4.1.1 Google Apps SAML issue
>  
> Hello,
> I saw the release of CAS 4.1.2 and tried using the skew allowance but it 
> still doesn’t work for me. I still get the your credentials have expired. I 
> noticed two things:
> 1.       Only one of the two NotOnOrAfter values get skewed. The other one is 
> still set to the current time. On our production setup CAS 3.5.1 both values 
> get increased by a year. I suspect that is the issue and may be you guys 
> could skew both?
> <samlp:Status>
> <samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
> </samlp:Status>
> <Assertion ID="<<skdjfskjsdfslkjlksjdlfjskd>>" 
> IssueInstant="2003-04-17T00:46:02.000Z" Version="2.0">
> <Issuer>https://www.opensaml.org/IDP</Issuer 
> <https://www.opensaml.org/IDP%3c/Issuer>>
> <Subject>
> <NameID 
> Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"><<personDetails>></NameID>
> <SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
> <SubjectConfirmationData 
> InResponseTo="<<somerandomstringlksjdlfkjsflksdjflks>>" 
> NotOnOrAfter="2015-11-24T15:39:00.000Z" 
> Recipient="https://www.google.com/a/<<mydomain>>/acs 
> <https://www.google.com/a/%3c%3cmydomain%3e%3e/acs>"/>
> </SubjectConfirmation>
> </Subject>
> <Conditions NotBefore="2003-04-17T00:46:02.000Z" 
> NotOnOrAfter="2015-11-24T15:41:00.000Z">
> <AudienceRestriction>
> <Audience>https://www.google.com/a/<<mydomain>>/acs</Audience 
> <https://www.google.com/a/%3c%3cmydomain%3e%3e/acs%3c/Audience>>
> </AudienceRestriction>
> </Conditions>
> <AuthnStatement AuthnInstant="2015-11-24T15:39:00.000Z">
> <AuthnContext>
> <AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:Password</AuthnContextClassRef>
> </AuthnContext>
> </AuthnStatement>
> </Assertion>
> </samlp:Response>
> 2.       The skew value is being subtracted from the current time. So instead 
> of adding say 2 seconds, 2 seconds get subtracted from current time. I am not 
> sure if that was the intended purpose, I got around that by adding a negative 
> skep in test (-120)
>  
> Help will be greatly appreciated.
>  
> Thanks,
>  
> -- 
> You received this message because you are subscribed to the Google Groups 
> "CAS Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to [email protected] 
> <mailto:[email protected]>.
> Visit this group at http://groups.google.com/a/apereo.org/group/cas-user/ 
> <http://groups.google.com/a/apereo.org/group/cas-user/>.
> -- 
> You received this message because you are subscribed to the Google Groups 
> "CAS Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to [email protected] 
> <mailto:[email protected]>.
> Visit this group at http://groups.google.com/a/apereo.org/group/cas-user/ 
> <http://groups.google.com/a/apereo.org/group/cas-user/>.
> 
> -- 
> You received this message because you are subscribed to the Google Groups 
> "CAS Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to [email protected] 
> <mailto:[email protected]>.
> Visit this group at http://groups.google.com/a/apereo.org/group/cas-user/ 
> <http://groups.google.com/a/apereo.org/group/cas-user/>.

-- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
Visit this group at http://groups.google.com/a/apereo.org/group/cas-user/.

Reply via email to