Thank you Paul for your idea, I have also switched to metadata-driven configuration, set forceAuthn=true and got it working. Paul -- Sent from: https://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html