----- Original Message ----- From: "Bill Davidson" <[EMAIL PROTECTED]>
To: "Tomcat Users List" <users@tomcat.apache.org>
Sent: Tuesday, June 10, 2008 3:43 AM
Subject: Re: Session lost when switching from https to http after upgrade to Tomcat 6


Johnny Kewl wrote:
maybe moving from HTTPs to HTTP is just a bad idea.
No doubt.  However, I didn't design this app and it's not up to me.
BTW, it's an old app.  It's running on Tomcat 3.2.4 in production to
give you an idea of its age.  We want to move to a newer server
first and then work on modernizing the app itself.

... its more just the thought that as soon as FORM auth, is used, theres other issues that kick in.
+ You for example have the HTTPs to HTTP issue
But another query somewhere here had a similar issue where the guy was authenticating against tomcat, and then again for static content against apache on JK, and the FORM auth was making life difficult there as well.

Thats what I'm thinking... and it always seems to be a tricky problem when it does show itself. Those little sec dialogs that browsers pop up, actually take a whole lot of potential issues out of the equation.
No critique, I'm just beginning to think pretty forms come at a cost ;)
I think I'm a DIGEST kinda guy ;)

---------------------------------------------------------------------------
HARBOR : http://www.kewlstuff.co.za/index.htm
The most powerful application server on earth.
The only real POJO Application Server.
See it in Action : http://www.kewlstuff.co.za/cd_tut_swf/whatisejb1.htm
---------------------------------------------------------------------------

---------------------------------------------------------------------
To start a new topic, e-mail: users@tomcat.apache.org
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to