OMElement assertionOMElement = tk.getToken();
SAMLAssertion samlAssertion = null;
try {
samlAssertion = new SAMLAssertion((Element) assertionOMElement);
samlAssertion.unsign();
samlAssertion.setNotBefore(creationTime);
samlAssertion.setNotOnOrAfter(expirationTime);
// sign the assertion
X509Certificate[] issuerCerts = crypto