Can we get support for setting the `SessionNotOnOrAfter` in the `AuthnStatement` element for SAML2? Details: http://stackoverflow.com/questions/29508906/notonorafter-in-subjectconfirmationdata-and-conditions-and-sessionnotonorafter