On Fri, 10 Jan 2003, Costin Manolache wrote:

> I find it amazing that 2 people reported beeing hit by meteors (duplicate
> session ids ) in the same week.

Make that 3; I've seen this as well; I suspect this is becauce tomcat
saves the sessions across restarts; and then happens to re-generate them
in the same way on the second startup.

> You're right - a counter is better than time. It'll duplicate the counter
> if tomcat is restarted - so probably the initial value of the counter
> should be random or derived from time.

Well counter + time-of-tomcatstart + ip + port is very unique provided
the ip is in the public space.

Dw.


--
To unsubscribe, e-mail:   <mailto:[EMAIL PROTECTED]>
For additional commands, e-mail: <mailto:[EMAIL PROTECTED]>

Reply via email to