<div dir="ltr"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div lang="EN-US" link="#0563C1" vlink="#954F72"><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">The following is an excerpt from the idp-process.log in DEBUG, as requested.  I restarted our Jetty server, then I did a single SAML2 authentication using our
 testing SP (WTS-Staging1).  I then logged out and browse to our sample CAS protected URL.  The login page branding I am presented with is the UIInfo from the WTS-Staging1 SP.</span></p></div></blockquote><div>The logs show what I'd expect other than the existence of an RelyingPartyUIContext, which simply doesn't get populated by the CAS protocol flow. While the CAS login flow does set up a SAMLMetadataContext, which is a precondition of SetRPUIInformation, none of the fields are set that are needed to build the RPUICtx in the authn/password flow.</div><div><br></div><div>Do you have a test environment where you can configure the standard authn/password flow and repeat your test sequence againt that? If you still see that behavior in a "default" case, then it would be stronger evidence that it's not some custom code causing the problem.</div><div><br></div><div>M</div><div><br></div></div></div>