The SAML2CommonLoginModule assumes that most of the heavy lifting of the authentication process is going to happen in the SP valve. If the SP valve is not installed by the web app, then the web app can fallback to form (if configured to use FORM authentication) where _any_ user can login by using the "EMPTY_STR" password. deleteme
|