<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">Hey Scott,<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Just a quick revisit…<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">>> If I do an intercept( and I think you have actually provided an example config
<br>
>> for this, conf/intercept/expiring-password-intercept-config.xml), the caveat <br>
>> is I will likely have to define password policy at the IdP with calendar-math,
<br>
>> instead of utilizing the account-state indicator from the LDAP bind <br>
>> response(where we believe password policy should be applied)...  or can I <br>
>> access the bind response and the AccountState object within, from the <br>
>> interceptor flow?  I'll have to poke around for that option first.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">> No, but you could maybe poke something into the tree with a pretty minimal expression in webflow and just > signal proceed, and defer the rest until an interceptor checks for the thing in the tree.
<br>
<br>
FWIW, if the AuthenticationContext is populated by an LDAP bind attempt during the password-authn-flow, then in fact, the LDAPResponseContext is a sub-context of the AC, and that context class does provide methods for access to the AccountState object, which
 in turn has getters for any errors or warnings(codes) being responded by the LDAP directory.  All that to say no additional tree tampering is necessary, as long as the AC is in the context tree at any post-authn flow.
<br>
<br>
Thanks again for the assist on this.  We have our expiring-password flow working again, in a clean state.
<br>
<br>
-Josh<o:p></o:p></p>
</div>
</body>
</html>