SOLVED.<br><br><div>The problem had nothing to do with which OpenSAML configuration bean we used or the configured algorithms. It turns out that a CAS client component was overwriting the OpenSAML security settings via a call to DefaultBootstrap.bootstrap(). I filed an issue with the Java CAS client project if anyone is interested in the details:</div><div><br></div><div><a href="https://issues.jasig.org/browse/CASC-237">https://issues.jasig.org/browse/CASC-237</a><br></div><div><br></div><div>Anyone that&#39;s using the Java CAS client libraries (e.g. shib-cas-authenticator folks) on the IdP and setting custom OpenSAML security settings may want to confirm whether they are affected by this issue. I&#39;m fairly certain that one would have to be using the Saml11AuthenticationFilter component to be affected, so it&#39;s doubtful shib-cas-authenticator deployers would be affected. For those folks like us doing Shib-CAS integration via REMOTE_USER, I would think it&#39;s more likely.</div><div><br></div><div>M</div><div><br></div><div class="gmail_quote"></div>