Hi James,
> So this confirms what you are saying (see below). Without haproxy in a > non-LB environment this works so apparently tomcat on the target openAM > server is more lenient. You can disable those strict RFC checks by configuring [1]: option accept-invalid-http-request However, by doing so you are only masking the problem and it could lead to more serious problems eventually. Lukas [1] http://cbonte.github.io/haproxy-dconv/configuration-1.4.html#4-option%20accept-invalid-http-request

