---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Minimize SAML notBefore or notOnOrAfter constraint duration \[Updated in Security Center 1.3 and 1.5\]

# Minimize SAML notBefore or notOnOrAfter constraint duration \[Updated in Security Center 1.3 and 1.5\] {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Configure this property to add a grace period in which SAML requests and responses are considered valid.
This property adds a grace period during which SAML requests and responses are considered valid. The property value represents the number of seconds to add to the NotBefore and NotOnOrAfter
constraints to account for time differences between the Identity Provider (IdP) clock, and Service Provider (SP) clock. These constraints defend against replay attacks by denying requests that aren't made within the specified time
frame. If the IdP and SP clocks are significantly different, then the network latency may result in the SAML request being unauthorized.

## More information {#sc-saml-notbefore-or-notonorafter-constraint__section_qhx_1b1_xwb}

{#sc-saml-notbefore-or-notonorafter-constraint__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.authenticate.sso.saml2.clockskew |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | string |
| Recommended value | less than 60 |
| Default value | 180 |
| Category | [Authentication](https://servicenow-prod.fluidtopics.net/faHnGPrE5YkSR8Xq~3OW5g "The authentication category covers the main elements of modern authentication to confirm an entity and its claims are authentic and correct, resistant to impersonation and prevent interception of passwords.") |
| Security risk | * Severity score: 7.5 * CVSS score: High * Security risk details: Setting the property to a value of 60 or higher may prevent the constraints from defending against replay attacks. {#sc-saml-notbefore-or-notonorafter-constraint__ul_g1g_3sf_xwb} |
| Dependencies and prerequisites | None |
[ ]

{#sc-saml-notbefore-or-notonorafter-constraint__table_ajc_b43_3kb}

