Question 1
A collaboration engineer is configuring SAML SSO between a Cisco Unified Communications Manager cluster (v12.5) and a third-party Identity Provider (IdP). After exchanging metadata, users report that upon successful authentication at the IdP, they are redirected to the CUCM user web page but are met with an 'SSO Login Failed' error. A review of the CUCM's IdP configuration reveals that the 'Attribute for User ID' is correctly set to 'uid'. Which of the following is the most probable cause for this authentication failure?
Answer and explanation
Correct answer: B
SAML assertions have a validity period defined by 'NotBefore' and 'NotOnOrAfter' timestamps. To prevent replay attacks, Cisco collaboration applications enforce a strict time synchronization requirement. If the clock skew between the Service Provider (CUCM) and the Identity Provider (IdP) is greater than a configured tolerance (typically 2-3 minutes), the assertion will be considered invalid, leading to a login failure even if all other parameters are correct. While unsigned assertions, incorrect user attributes, or certificate issues are also potential causes, clock skew is a very common and often overlooked reason for this specific symptom.