[ https://issues.apache.org/jira/browse/CXF-5692?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13971378#comment-13971378 ]
Colm O hEigeartaigh commented on CXF-5692: ------------------------------------------ It's validated when the token is received as part of the SAML SSO protocol. Otherwise, only the Conditions NotOnOrAfter expiry is validated. Do you have a particular use-case that NotOnOrAfter can't be used instead? Colm. > CXF doesn't verify SessionNotOnOrAfter of AuthenticationStatement > ----------------------------------------------------------------- > > Key: CXF-5692 > URL: https://issues.apache.org/jira/browse/CXF-5692 > Project: CXF > Issue Type: Bug > Components: JAX-WS Runtime > Affects Versions: 2.7.10 > Reporter: Tony Clarke > Assignee: Colm O hEigeartaigh > -- This message was sent by Atlassian JIRA (v6.2#6252)