Index: trunk/BNC/src/PPP/pppSatObs.cpp
===================================================================
--- trunk/BNC/src/PPP/pppSatObs.cpp	(revision 11041)
+++ trunk/BNC/src/PPP/pppSatObs.cpp	(revision 11042)
@@ -409,7 +409,21 @@
 // provider is relied on to keep DF+010 synchronized with DF+069 across all
 // systems for this to work.
-////////////////////////////////////////////////////////////////////////////
-static bool ssrSatAntennaTrusted(const t_satAntenna* satAntenna) {
+//
+// Separately, providers only guarantee SatelliteAntennaIOD uniqueness within
+// a rolling 64-day window (it wraps/repeats after that), so a client that
+// has been without a fresh Antenna message for that system for 64 days or
+// more must treat any cached data as unverifiable and stop using it, even
+// if the IOD/Metadata check above would otherwise pass - the same IOD value
+// could by then legitimately mean something else. epoTime is the current
+// processing epoch, compared against t_satAntenna::_time (when this data
+// was actually decoded, not a wire epoch - the message carries none).
+////////////////////////////////////////////////////////////////////////////
+static bool ssrSatAntennaTrusted(const t_satAntenna* satAntenna, const bncTime& epoTime) {
+  const double MAX_AGE_SEC = 64.0 * 86400.0;
   if (!satAntenna || satAntenna->_satelliteAntennaIOD == 0) {
+    return false;
+  }
+  if (epoTime.valid() && satAntenna->_time.valid() &&
+      epoTime - satAntenna->_time >= MAX_AGE_SEC) {
     return false;
   }
@@ -543,5 +557,5 @@
   if (PPP_CLIENT->antex()) {
     const t_satAntenna* satAntenna = PPP_CLIENT->obsPool()->satAntenna(_prn);
-    if (!ssrSatAntennaTrusted(satAntenna)) {
+    if (!ssrSatAntennaTrusted(satAntenna, _time)) {
       satAntenna = 0; // untrusted (IOD zero, or not confirmed via Metadata) - fall back to ANTEX
     }
