> I am using CAS for the RemoteUser authn. I looked back at my V2 configs > and listserv historical traffic and found the answer. It was to delegate > all WebSSO to CAS, by disabling sessions entirely in the IdP. This can > now be done (in V3) in idp.properties with idp.session.enabled = false. That wouldn't fix what you reported. -- Scott