On 11/14/19, 10:53 AM, "users on behalf of Wessel, Keith" <users-bounces at shibboleth.net on behalf of kwessel at illinois.edu> wrote: > But I assume that the two shibboleth2.xml settings (handlerSSL="false" and cookieProps="http" still need to be set? Nope. It *is* SSL if the server tells it that it is. -- Scott