There's no reason anybody should ever sign a SAML AuthnRequest. The signRequests profile option on the SAML.SSO profile bean is what controls it. You should not do it, that's wasted CPU time for all concerned. -- Scott