Okta Access Gateway Displays an Assertion Valid in the Future Error
Last Updated:
Overview
A time gap or clock skew in Okta Access Gateway (OAG) causes an assertion validation error, preventing users from authenticating. Resolve this issue by checking the Network Time Protocol (NTP) status and synchronizing the system time in the Management Console. When the Okta Access Gateway clock skew exceeds the allowed limit, the application generates one of the following errors:
Caused by: SimpleSAML\Error\Exception: Received an Assertion that Is Valid in the Future. Check Clock Synchronization on IdP and SP
Caused by: SimpleSAML\Error\Exception: Error validating SubjectConfirmation in Assertion: NotOnOrAfter in SubjectConfirmationData is in the past
Applies To
- Okta Classic Engine
- Okta Identity Engine (OIE)
- Okta Access Gateway (OAG)
Cause
The Okta Access Gateway clock skew exceeds the three-to-five-minute limit, preventing successful user authentication.
Solution
How is the system time synchronized in Okta Access Gateway?
Synchronize the system time and verify the Network Time Protocol (NTP) service status using the Management Console by following these steps.
- Access the Okta Access Gateway Management Console via Secure Shell (SSH).
- Select 2 for Services, select 3 for NTP, and select 5 to Check status.
- Perform one of the following actions based on the status output:
- If the current date and time are incorrect, select 6 to Set system time.
- If the service fails to run, select 2 to Start chronyd.
- If the polling shows zero, the server lacks a response from the Network Time Protocol (NTP) server. Contact the internal networking team to resolve the connection issue.
NOTE: The NTP service adjusts the clock in very small increments. If a significant time difference exists, manually update the time in the Management Console or restart the service.
- To manually set the time, select 2 for Services, select 3 for NTP, and select 6 to Set System Time.
- To restart the service, select 2 for Services, select 3 for NTP, and select 4 to Restart chronyd.
