Ok great. I just submitted a pull request for 4.1. Thanks Misagh for all your help!
--- Abhijit Gaikwad Applications Programmer | [email protected]<mailto:[email protected]> From: [email protected] [mailto:[email protected]] On Behalf Of Misagh Moayyed Sent: Tuesday, December 01, 2015 5:50 PM To: [email protected] Subject: Re: [cas-user] CAS 4.1.1 Google Apps SAML issue For starters yes. The ISOStandardDateFormat class basically gets you the current date/time in this format: yyyy-MM-dd’T'HH:mm:ss'Z' What might be happening is, the parse() call right after that does not respect the timezone that is returned. Thus your issue. If you can come up with unit tests that confirm that theory, great. Otherwise, we’ll look into it but go ahead and submit a PR please to the 4.1 branch. - Misagh On Dec 1, 2015, at 3:42 PM, Abhijit Gaikwad <[email protected]<mailto:[email protected]>> wrote: Misagh, Just to confirm since I don’t know the code base very well and I don’t know what the ISOStandardDateFormat class is actually supposed to do, I am not very sure if the issue is with the code or if I am doing something wrong to get the incorrect dates. My fix works for me though. But did you wanted me to submit a PR to replace that line with just the new DateTime line as below? Original line: final DateTime currentDateTime = DateTime.parse(new ISOStandardDateFormat().getCurrentDateAndTime()); New line: final DateTime currentDateTime = new DateTime(); --- Abhijit Gaikwad Applications Programmer | T 321-674-8208 | [email protected]<mailto:[email protected]> From: [email protected]<mailto:[email protected]> [mailto:[email protected]] On Behalf Of Misagh Moayyed Sent: Tuesday, December 01, 2015 5:36 PM To: [email protected]<mailto:[email protected]> Subject: Re: [cas-user] CAS 4.1.1 Google Apps SAML issue OK that’s an easy one. Go ahead and submit a PR if you would please: http://jasig.github.io/cas/developer/Contributor-Guidelines.html - Misagh On Dec 1, 2015, at 2:07 PM, Abhijit Gaikwad <[email protected]<mailto:[email protected]>> wrote: Hey Misagh, Thanks for pushing the fix for the issue. In addition to the skew I am also having an issue with the dates themselves, specifically the time zones. I have been testing with the custom code as you suggested and the below statement creates problems for me. final DateTime currentDateTime = DateTime.parse(new ISOStandardDateFormat().getCurrentDateAndTime()); https://github.com/Jasig/cas/blob/4.1.x/cas-server-support-saml/src/main/java/org/jasig/cas/support/saml/authentication/principal/GoogleAccountsService.java#L171 >From what I can tell it creates a date and uses my local time (EST) but >creates a date object that is Zulu time (If I am understanding it correctly). >So no matter what the skew (unless it is > 5 hours as zulu time is about +5 >hours eastern standard time) my authentication always expires. If I change the above line in the code to just final DateTime currentDateTime = new DateTime(); It creates a time that is close to UTC which works fine. I have ensured that my centos7 box has timezone and locale set to EST as seen below. Is there something else I should be looking at in terms of timezones? What am I missing? #timedatectl Local time: Tue 2015-12-01 15:48:32 EST Universal time: Tue 2015-12-01 20:48:32 UTC RTC time: Tue 2015-12-01 20:48:32 Timezone: America/New_York (EST, -0500) NTP enabled: yes NTP synchronized: yes RTC in local TZ: no DST active: no Last DST change: DST ended at Sun 2015-11-01 01:59:59 EDT Sun 2015-11-01 01:00:00 EST Next DST change: DST begins (the clock jumps one hour forward) at Sun 2016-03-13 01:59:59 EST Sun 2016-03-13 03:00:00 EDT # locale LANG=en_US.UTF-8 LC_CTYPE="en_US.UTF-8" LC_NUMERIC="en_US.UTF-8" LC_TIME="en_US.UTF-8" LC_COLLATE="en_US.UTF-8" LC_MONETARY="en_US.UTF-8" LC_MESSAGES="en_US.UTF-8" LC_PAPER="en_US.UTF-8" LC_NAME="en_US.UTF-8" LC_ADDRESS="en_US.UTF-8" LC_TELEPHONE="en_US.UTF-8" LC_MEASUREMENT="en_US.UTF-8" LC_IDENTIFICATION="en_US.UTF-8" LC_ALL= Thanks, --- Abhijit Gaikwad Applications Programmer | T 321-674-8208 | [email protected]<mailto:[email protected]> From: [email protected]<mailto:[email protected]> [mailto:[email protected]] On Behalf Of Abhijit Gaikwad Sent: Monday, November 30, 2015 12:45 PM To: Misagh Moayyed; [email protected]<mailto:[email protected]> Subject: RE: [cas-user] CAS 4.1.1 Google Apps SAML issue I’m curious to know what the use case would be where one would want to subtract a skew value. I’ll go ahead and create an issue for update the other NotOnOrAfter value. Thanks, --- Abhijit Gaikwad Applications Programmer | [email protected]<mailto:[email protected]> From: [email protected]<mailto:[email protected]> [mailto:[email protected]] On Behalf Of Misagh Moayyed Sent: Monday, November 30, 2015 10:08 AM To: [email protected]<mailto:[email protected]> Subject: Re: [cas-user] CAS 4.1.1 Google Apps SAML issue Yes, we can skew both. Please do create an issue. - Misagh On Nov 30, 2015, at 6:41 AM, Abhijit Gaikwad <[email protected]<mailto:[email protected]>> wrote: From: Abhijit Gaikwad Sent: Tuesday, November 24, 2015 4:39 PM To: [email protected]<mailto:[email protected]> Subject: RE: [cas-user] CAS 4.1.1 Google Apps SAML issue Hello, I saw the release of CAS 4.1.2 and tried using the skew allowance but it still doesn’t work for me. I still get the your credentials have expired. I noticed two things: 1. Only one of the two NotOnOrAfter values get skewed. The other one is still set to the current time. On our production setup CAS 3.5.1 both values get increased by a year. I suspect that is the issue and may be you guys could skew both? <samlp:Status> <samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/> </samlp:Status> <Assertion ID="<<skdjfskjsdfslkjlksjdlfjskd>>" IssueInstant="2003-04-17T00:46:02.000Z" Version="2.0"> <Issuer>https://www.opensaml.org/IDP</Issuer<https://www.opensaml.org/IDP%3c/Issuer>> <Subject> <NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"><<personDetails>></NameID> <SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"> <SubjectConfirmationData InResponseTo="<<somerandomstringlksjdlfkjsflksdjflks>>" NotOnOrAfter="2015-11-24T15:39:00.000Z" Recipient="https://www.google.com/a/<<mydomain>>/acs<https://www.google.com/a/%3c%3cmydomain%3e%3e/acs>"/> </SubjectConfirmation> </Subject> <Conditions NotBefore="2003-04-17T00:46:02.000Z" NotOnOrAfter="2015-11-24T15:41:00.000Z"> <AudienceRestriction> <Audience>https://www.google.com/a/<<mydomain>>/acs</Audience<https://www.google.com/a/%3c%3cmydomain%3e%3e/acs%3c/Audience>> </AudienceRestriction> </Conditions> <AuthnStatement AuthnInstant="2015-11-24T15:39:00.000Z"> <AuthnContext> <AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:Password</AuthnContextClassRef> </AuthnContext> </AuthnStatement> </Assertion> </samlp:Response> 2. The skew value is being subtracted from the current time. So instead of adding say 2 seconds, 2 seconds get subtracted from current time. I am not sure if that was the intended purpose, I got around that by adding a negative skep in test (-120) Help will be greatly appreciated. Thanks, -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]<mailto:[email protected]>. Visit this group at http://groups.google.com/a/apereo.org/group/cas-user/. -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]<mailto:[email protected]>. Visit this group at http://groups.google.com/a/apereo.org/group/cas-user/. -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]<mailto:[email protected]>. Visit this group at http://groups.google.com/a/apereo.org/group/cas-user/. -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]<mailto:[email protected]>. Visit this group at http://groups.google.com/a/apereo.org/group/cas-user/. -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]<mailto:[email protected]>. Visit this group at http://groups.google.com/a/apereo.org/group/cas-user/. -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]<mailto:[email protected]>. Visit this group at http://groups.google.com/a/apereo.org/group/cas-user/. -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. Visit this group at http://groups.google.com/a/apereo.org/group/cas-user/.
