<div dir="ltr">Prior to upgrading from Shib 3, we had shibboleth set up to handle user authentication via LDAP, and we retrieved the user expiration date via an attribute (this attribute was a call to a database, which allowed us to set the format of the date returned, as well as modify the expiration based on business rules, and allowed us to treat administratively reset users as 'expired').  The attribute was named 'passwordExpiration' -- and that's the limit of my notes. Perhaps once I got that attribute populated, it was simply just used and things just worked.<br><br>This was working just fine. I believe we tested this after upgrading to 4.1 and I believe it was working then, but I cannot be 100% sure.<div><br></div><div>Now that we are on 4.2, users that *should* be considered expired based on the date, but know the value of the expired password, are allowed in without being redirected to the password reset page. <br><br>I see some discussion on the mailing list (<a href="http://shibboleth.net/pipermail/users/2023-January/053346.html">http://shibboleth.net/pipermail/users/2023-January/053346.html</a>) that references files we don't have. I have tried changing the format of the expiration to yyyyMMdd based on that email exchange, but no luck. </div><div><br></div><div>I can't seem to find documentation for Shib 4.3 for how to set up expiring passwords -- any ideas what I seem to be missing?<br clear="all"><div><br></div><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><pre cols="72">Jeff Chapin,</pre>Panther eSports Adviser            <br>Systems/Applications Administrator<br>ITS-IS, University of Northern Iowa<br>Phone: 319-273-3162 Email: <a href="mailto:Jeff.Chapin@uni.edu" target="_blank">Jeff.Chapin@uni.edu</a> </div></div></div></div></div></div>