(Sorry if this is a bit off topic) I am using Tomcat 3.1 with Apache - Stronghold. I am new to SSL / Digital certificates, and was wondering if any one can point me to any example code / url or even a book title which has an example of how to read a client digital certificate and grant access to users based on that. Firstly is this supported in Tomcat 3.1 with Apache as the web server ? Also is there any way that I can dispense certificates off my web server rather than ask the users to get a certificate from a CA. Thanks Shahed.