Re: SSL FAQ and question

2002-11-21 Thread Norbert Kuhnert
ave to try that out. Did you need to configure a second for the secure site? Or is that only necessary if you want a separate domain secure.site.com instead of regular.site.com. -Original Message----- From: Norbert Kuhnert [mailto:[EMAIL PROTECTED]] Sent: Thursday, November 21, 2002 11:49

Re: SSL FAQ and question

2002-11-21 Thread Norbert Kuhnert
Jay, I've had success with using the webapp deployment descriptor "transport-guarantee" user-data-contraint as follows: myPayroll /payrollServlet GET CONFIDENTIAL If your Tomcat server's connector is properly setup to specify the "redirect

Re: Session Tracking based on the Client's IP

2002-11-20 Thread Norbert Kuhnert
Jose, Unfortunately, this approach would be somewhat unreliable, depending on the sites accessing Tomcat. Most corporate networks are protected by a firewall and many of the do "Dynamic Network Address Translation". Dynamic NAT is used to hide the real IP address of clients connected from the int