> I decided simply to extend my idp, writing my own LoginHandler to handle > the 2 onknown types of authContextClassReference... > It would be just like the standard usernamePassword login handler, but it > handles the new authContextClassReference type. You don't need to do that, the IdP already supports that. -- Scott