Handling Replay Attacks and Validating Timestamps in SAML Assertions with Okta
Last Updated:
Overview
This article discusses whether the Okta service has mechanisms to protect against replay attacks and avoid interception and replay of Secure Assertion Markup Language (SAML) assertions. Moreover, it clarifies if the service validates timestamps to expire assertions after use to comply with the SAML specification.
Applies To
- Information security
- SAML Assertions Management
Solution
Okta implements several measures to ensure SAML assertions are secure:
- SAML assertions in Okta are valid for 5 minutes (300 seconds) before and 5 minutes (300 seconds) after the issuance time.
- Okta includes NotBefore and NotOnorAfter properties as part of the SAML Assertion Response to specify the period during which the assertion is valid.
- While Okta does not support OneTimeUse, it does have a replay cache. This cache stores the assertion ID to prevent replay of assertions.
- The replay cache is valid for a duration of 20 minutes.
By implementing these measures, Okta provides robust protection against replay attacks and proper validation of timestamps in SAML assertions.
