<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Wed, Feb 10, 2016 at 10:23 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex"><span class="">> Yes, that does look simpler, and the already-notified cookie is very nice. My<br>
> head hurts trying to parse AD pwdLastSet but it works with a contrived static<br>
> YYMMdd attribute.<br>
<br>
</span>I was a little surprised joda-time didn't have a parser built in for that, I think we'll have to eventually add something to the predicate class.<br><span class=""><font color="#888888"><br>
-- Scott</font></span></blockquote><div><br></div><div>I ended up making it with scripted attribute resolution to obtain a suitable passwordExpiration string, with help of <span style="font-size:12.8px">FileTimeValueTranscoder.</span></div><div><span style="font-size:12.8px">Thank you all.</span></div><div><span style="font-size:12.8px"><br></span></div><div><span style="font-size:12.8px">By the way, if this method will be the way to go in 3.3.0, will the original condition/expiring-password subflow kept in the future release?</span></div><div><br></div></div></div></div>