Thanks Michael...
Agreed, but right now, based on your install script/RPM/DEB packages for the community edition, oxTrust is being exposed through the same Apache HTTPD configuration/ reverse proxy as the identity app.
I'd suggest you guys split up the packaging and/or configure the install script to provide two different virtual hosts out of the box on different ports maybe??? (That way, one virtual host can have the header directive set and the other not?)