Some servers are configured with multiple authentication groups. OpenConnect request just authentication entries that are valid for specific group (process_auth_form method). So, authentication group have to setup first, and new form have to be requested then. Some authentication groups may require secondary password. For example one-time password from Google Authenticator app. Lukas