This is a valid bug. The CAS SecuredURLPattern needs to filter /sec from its list.
This fix should be available in the next release. Until then, you can override the getSecuredURLPatterns method on the Valve with this filtering Thanks View the original post : http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4193773#4193773 Reply to the post : http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&p=4193773 _______________________________________________ jboss-user mailing list jboss-user@lists.jboss.org https://lists.jboss.org/mailman/listinfo/jboss-user