We won't have identities for private key passwords, but we do for EAP identities and they might get reused if redirected.