I was able to get the re:Solution SSOSAML plugin to work with our ADFS, an AWS ELB [Elastic Load Balancer], and Jira [Jira, Confluence, and Jira Service Desk].
However, when we introduced the WAP reverse proxy for extra security, SSOSAML no longer worked. No log files or debug sessions showed the reason.
One way around it was to disable HTTP/2.0 on the WAP.
Another was to disable HTTP/2.0 on the ELB.
I tried changing the application server's server.xml file from HTTP/1.1 to 2.0 but it wouldn't work.
I would have thought that if HTTP/2.0 didn't work, the handshake would down-select to 1.1 but that was obviously not happening.
I hope this helps someone who runs into this in the future; I spent about a month tearing my hair out before the WAP guy suggested looking at HTTP [I noticed that some logs mentioned 1.1 and others mentioned 2.0 but I didn't follow-up on that observation].