Author: markt
Date: Sun Dec 14 12:37:14 2014
New Revision: 1645450
URL: http://svn.apache.org/r1645450
Log:
CTR Docs update
Fix https://issues.apache.org/bugzilla/show_bug.cgi?id=57348
Remove references to DIGEST auth config attributes from BASIC auth docs.
Modified:
tomcat/tc6.0.x/trunk/webapps/docs/config/valve.xml
Modified: tomcat/tc6.0.x/trunk/webapps/docs/config/valve.xml
URL:
http://svn.apache.org/viewvc/tomcat/tc6.0.x/trunk/webapps/docs/config/valve.xml?rev=1645450&r1=1645449&r2=1645450&view=diff
==============================================================================
--- tomcat/tc6.0.x/trunk/webapps/docs/config/valve.xml (original)
+++ tomcat/tc6.0.x/trunk/webapps/docs/config/valve.xml Sun Dec 14 12:37:14 2014
@@ -527,12 +527,6 @@
used.</p>
</attribute>
- <attribute name="cnonceCacheSize" required="false">
- <p>To protect against replay attacks, the DIGEST authenticator tracks
- client nonce and nonce count values. This attribute controls the size
- of that cache. If not specified, the default value of 1000 is used.</p>
- </attribute>
-
<attribute name="disableProxyCaching" required="false">
<p>Controls the caching of pages that are protected by security
constraints. Setting this to <code>false</code> may help work around
@@ -543,26 +537,6 @@
<code>true</code> will be used.</p>
</attribute>
- <attribute name="key" required="false">
- <p>The secret key used by digest authentication. If not set, a secure
- random value is generated. This should normally only be set when it is
- necessary to keep key values constant either across server restarts
- and/or across a cluster.</p>
- </attribute>
-
- <attribute name="nonceValidity" required="false">
- <p>The time, in milliseconds, that a server generated nonce will be
- considered valid for use in authentication. If not specified, the
- default value of 300000 (5 minutes) will be used.</p>
- </attribute>
-
- <attribute name="opaque" required="false">
- <p>The opaque server string used by digest authentication. If not set,
a
- random value is generated. This should normally only be set when it is
- necessary to keep opaque values constant either across server restarts
- and/or across a cluster.</p>
- </attribute>
-
<attribute name="securePagesWithPragma" required="false">
<p>Controls the caching of pages that are protected by security
constraints. Setting this to <code>false</code> may help work around
@@ -572,14 +546,6 @@
If not set, the default value of <code>true</code> will be used.</p>
</attribute>
- <attribute name="validateUri" required="false">
- <p>Should the URI be validated as required by RFC2617? If not
specified,
- the default value of <code>true</code> will be used. This should
- normally only be set when Tomcat is located behind a reverse proxy and
- the proxy is modifying the URI passed to Tomcat such that DIGEST
- authentication always fails.</p>
- </attribute>
-
</attributes>
</subsection>
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]