> > I think I already answered this in the original mail. > > We are *not* committing to do anything other than kill off the IdP session. > For sites that use REMOTE USER authn could you redirect the user to the real authenticating site after killing the idp's session? Jim