> But be that as it may, assuming you're using RemoteUser, it's documented, > authMethodHeader. Correction: authnMethodHeader. And of course you would have to set the shibboleth.authn.RemoteUser.addDefaultPrincipals bean to FALSE or it's just going to circumvent it. -- Scott