<div dir="ltr"><br><div class="gmail_quote"><div dir="ltr"><div>I notice that (unless I've corrupted my core config somehow), the default SAML2.SSO doesn't set p:maximumSPSessionLifetime, so AuthnStatement is missing a SessionNotOnOrAfter attribute; shouldn't this be populated by default from idp.session.timeout?<span class="HOEnZb"><font color="#888888"><br><br></font></span></div><span class="HOEnZb"><font color="#888888"><div>Phil<br></div></font></span></div>
</div><br></div>