In addition to what Peter said, my canonical answer to this is that you should move all your "local" login processes behind a SAML IdP and simply use SSO for everybody. That answer is independent of Shibboleth. -- Scott