<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Arial, sans-serif;">
<div>Hi</div>
<div><br>
</div>
<div>This is my first post to this list so apologize if topic has been adressed before.</div>
<div><br>
</div>
<div>I have a misbehaving SP who refuses to apply time skew. After big drama I got them to implement the option to simply ignore notBefore since it is optional according to spec.</div>
<div><br>
</div>
<div>I upgraded from 2.x to 2.4.0 because i found out about the options to ignore &#8221;notBefore&#8221; by adding includeConditionsNotBefore=false to profiles in ProfileConfiguration but my IdP doesn&#8217;t even start properly because of the additional includeConditionsNotBefore.&nbsp;</div>
<div><br>
</div>
<div>The log says:</div>
<div><br>
</div>
<div>5:50:54.655 - ERROR [edu.internet2.middleware.shibboleth.common.config.BaseService:187] - Configuration was not loaded for shibboleth.RelyingPartyConfigurationManager service, error creating components. &nbsp;The root cause of this error was: org.xml.sax.SAXParseException:
 cvc-complex-type.3.2.2: Attribute 'includeConditionsNotBefore' is not allowed to appear in element 'ProfileConfiguration&#8217;.</div>
<div><br>
</div>
<div>So, I upgraded again from 2.4.0 to 2.4.3,.. Same thing :-(</div>
<div><br>
</div>
<div>I have tried on DefaultRelyingParty and custom RelyingParty.</div>
<div><br>
</div>
<div>What is the correct approach to have IdP ignore sending notBefore in response to SP?</div>
<div>Any ideas?</div>
<div><br>
</div>
<div>
<div>
<div>-------------------------------------</div>
<div>Pablo Millet</div>
<div>IT-Department</div>
<div>University of Gothenburg</div>
</div>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div>&nbsp;</div>
<div><br>
</div>
<div><br>
</div>
<pre><br></pre>
</body>
</html>