Hi, Gene.
Not sure what your actual issue is. If I got you right, commenting out the `UsernamePassword` handler resolved this for you, i.e. now your user won't be redirected to Shib's own login page even in case SP or Asimba will use `urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport` auth classref. Is it correct?
This login handler will be soon removed completely, I guess, I remeber there was another github report created by Michael, instructing dev team to do so.
Best regards,
Alex.