<div dir="ltr"><div>I notice that (unless I've corrupted my core config somehow), the default SAML2.SSO doesn't set p:maximumSPSessionLifetime, so AuthnStatement is missing a SessionNotOnOrAfter attribute; shouldn't this be populated by default from idp.session.timeout?<br><br></div><div>Phil<br></div></div>