Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
1.6.4
-
None
-
None
Description
The SAML NotOnOrAfter Conditions is not set correctly in certain circumstances, when creating SAML 1.1 and SAML 2 Assertions. This happens when the user adds a "ConditionsBean" in the CallbackHandler to create the SAML Token, but does not specify either notBefore, notAfter or tokenPeriodMinutes. In this case, a Conditions element is created in which the NotOnOrAfter time is the exact same as the NotBefore time.