Bug ID 520610: BIG-IP as SP ignores "SubjectConfirmationData NotOnOrAfter" timestamp.

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
11.6.0, 11.6.1, 11.6.2, 11.6.3,,,,, 11.6.4, 11.6.5,,,, 12.0.0, 12.0.0 HF1, 12.1.0 HF1, 12.0.0 HF2, 12.1.0 HF2, 12.0.0 HF3, 12.0.0 HF4, 12.1.1 HF1, 12.1.1 HF2, 12.1.2 HF1, 12.1.2 HF2

Fixed In:

Opened: Apr 29, 2015

Severity: 3-Major


Assertions that are passed from a SAML Identity Provider (IdP) to a SAML Service Provider (SP) contain a number of timestamps to prevent replay attacks. When assertions are processed by BIG-IP as SP, most of these timestamps are verified, except for SubjectConfirmationData NotOnOrAfter.


As a result, BIG-IP as SP can accept an assertion with an expired SubjectConfirmationData NotOnOrAfter timestamp.


This happens when the SubjectConfirmationData NotOnOrAfter timestamp is expired by the time that the BIG-IP as SP processes the assertion.


There is no workaround at this time.

Fix Information


Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips