<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;" dir="ltr">
<p style="margin-top:0;margin-bottom:0">Hi,</p>
<p style="margin-top:0;margin-bottom:0"><br>
</p>
<p style="margin-top:0;margin-bottom:0">Is it possible to disable a security rule (or use a different TrustEngine) for a specific relying party? I've got an ADFS instance with a SAML2 SSO redirect that the browser is replaying to our IdP due to the cache headers
 ADFS is sending. A user would sporadically see this as a 404.</p>
<p style="margin-top:0;margin-bottom:0"><br>
</p>
<p style="margin-top:0;margin-bottom:0">Ideally ADFS would send better cache headers but am looking into this in case that's not possible, since its AuthnRequest isn't signed so I don't think there's any danger in allowing a replayed request.</p>
<p style="margin-top:0;margin-bottom:0"><br>
</p>
<p style="margin-top:0;margin-bottom:0">Nick</p>
</div>
</body>
</html>