Hi Sham,Thank you for explanation, as I am not using the encryption, so sp2 will not fix my problem.So here is a question: when user click logout link, AEM does clears the cookie first right? if it is so, I can't do the real sign out if IDP doesn't clears related cookies, right? That required cookie...