Does this mean that your browser can cache the signed cert and log in to websites automatically without needing to even contact the provider again?
I'm guessing there's some sort of timestamp there, to prevent someone from just stealing the cert and logging in to whatever they want as that user.