djoos / EscapeWSSEAuthenticationBundle

Symfony bundle to implement WSSE authentication
http://symfony.com/doc/current/cookbook/security/custom_authentication_provider.html
137 stars 59 forks source link

New Feature: Clockskew #84

Open hostage-nl opened 8 years ago

hostage-nl commented 8 years ago

Hi,

I experience problems with clients with a slight clock skew, even though their time is synced (the default microsoft way). The time is a tiny bit in the future so WSSE authentication always fails. The server is properly synced with ntp.

With clock skew configuration parameter i added, i've introduced a margin within which clock skew is allowed.

I would appreciate if you could merge this pull request.

Thanks!

martijn.

sagikazarmark commented 8 years ago

+10000000000000000000 with the following comments:

  1. AFAIK this feature is called time tolerance or something, not sure if it is "offical" term.
  2. I don't think it makes sense to modify the lifetime as well. It is perfectly fine to modify the configuration instead.
hostage-nl commented 8 years ago
  1. I found the term clock skew in someone else's code while researching the problem. I agree that something like time tolerance sounds better and is more self explanatory.
  2. Not sure what you mean, i think i didn't change anything lifetime related.
  3. I fixed the failing test.
sagikazarmark commented 8 years ago

Any news? I would really love to see this merged.

hostage-nl commented 8 years ago

Same here, is there anything i need to do to get this one merged?

Once upon a 19 Aug 2016, Márk Sági-Kazár hit keys in the following order:

Any news? I would really love to see this merged.

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHub, or mute the thread.*

Hostage Kleine Gartmanplantsoen 21 1017 RP Amsterdam tel: +31 (0)20 4632 303 https://www.hostage.nl