If it's rewritten internally only, the IdP's cookie probably has an /idp path set that blocks it from subsequent use and would have ot be adjusted. If the client sees the rewrite that shouldn't be the case. -- Scott