<div dir="ltr">Hi,<div><br></div><div>The documentation for v2.x at</div><div><br></div><div><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPAuthRemoteUser">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPAuthRemoteUser</a><br></div><div><br></div><div>includes "This login handler does not support the SAML 2 forced re-authentication or passive authentication feature."</div><div><br></div><div>Do you happen to recall if "does not support" meant that the IdP would send the SP a SAML error if the SP included isPassive in the authnRequest?</div><div><br></div><div>Sorry to ask about old functionality. If you do not recall I can dig out an old deployment and actually do the experiment...</div><div><br></div><div>Thanks,</div><div><br></div><div>Scott K</div></div>