We have a federation with a vendor which is working well for about 8000 employees. However I daily receive one or two clients which receive the below alert in their browser from the vendor and their access is refused.
Details: <vendor> and client timestamp are not matching.
Information : NotBefore: 1/16/2015 6:35:05 AM, NotOnOrAfter: 1/16/2015 7:35:05 AM
<vendor) Server time : 1/16/2015 6:34:50 AM
I checked all my ADFS servers and proxies and they are correctly sync'd with tock.usno.navy.mil. The vendor also checked the time on their servers and they are correctly sync'd with NIST time servers.
What else could I check? Could the 15 second time delta be coming from the user's desktop?
Thanks
LRL