I'm guessing this is relevant for IdP's that utilize TLS-based authentication for back-channel queries with containers fronted by Apache. Just sent as a heads up. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4979