>> Yes, but I don't see what that buys you unless your goal is to
>> deploy all those certs and then not protect your applications with
>> them.
>Getting around the HTTP POST from SSL (IdP) to non-SSL (SP) security
>warning in the user agent, IIRC,

I get that part, but if you've done the work to make SSL on the vhost
possible, why turn it off for the app? 10 years ago, yes, for performance,
but today?

-- Scott

