> Hence my question: can the web server (Apache, in my case) distinguish > unauthentified requests, and drop them, before them being processed by > mod_shib ? That isn't sufficient, you'd have to know the difference between unauthenticated and unauthenticated by the polling script. I see no obvious way, but I'm no Apache expert. -- Scott