Description
There're properties in org.apache.cxf.ws.security.trust.STSClient:
sendRenewing, allowRenewing
Unfortunately they don't prevent the renewal from being issued.
p.s. We have a real usecase where thirdparty use STS service but don't support the renewal
Affected version: 2.7.1