I do not necessarily disagree that my clients / service providers are over reacting
to unintended recovery of sessions.  The fact remains that key services decline
or back out of Shibb-based central authN, and their absence slows general awareness
of and acceptance of our Shibboleth services; that in turn reduces the value proposition
for SSO if a few heavily used services are not part of it.  It even contributes to the
continued conflation (in my local experience) of SSO with single set of credentials,
thereby implicitly legitimizing credential relay (again, in the minds of my clients /
service providers even if not objectively so).

It may be that I and other in this situation should just "wait out" these skeptics,
but I hope to offer a response to this particular concern, even recognizing that
an effective response to this concern may spur a new objection, based on 
underlying unexpressed concerns (say, their discomfort with lack of total control
implicit in trusted third party central authN).

David Bantz

