-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 24/09/2012 17:51, Christopher Schultz wrote: > I'm curious how you will "check DIGEST first" and then apply > BASIC. Are you expecting some clients to simply send DIGEST > credentials without first contacting the server? I don't think > that's possible.
RFC2616 allows multiple authentication challenges to be sent so both DIGEST and BASIC could be sent in a single response. It would then be up to the client how to respond. Mark -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (MingW32) Comment: Using GnuPG with Mozilla - http://www.enigmail.net/ iQIcBAEBAgAGBQJQYJ1FAAoJEBDAHFovYFnnt5AP/jtel9ZjB5NbKePywWKjnxj7 X7n9tGfIXYSgycGxo0EXCwD2hjViVr/j3+tkqv3wTXCa0pqajOOem1mA0AVHXP/0 fkVgFSK+hcFQoxhHCYYC0a/aQnAeNs5azBR++pfIsHkXYQKAXo1hMLezwbhev2KA 86lrRWpBjGPsEWezx4A/N3W0x9Ct5AqtYSBYHSDBhlbYLwl7Id7wv7NDi30gdR6D W/gT6jilEqCHKlmy8QmTYogwFUQ1+LMbEIKmVgmk+9QuLyJaf2xmwV8Vt5dETdGt xwT+8mPq4ZLv/JICjrrAkS1KQfb31KBlwM+YHERrSI2x6AzVxT2xWp9mCnigRdZl jJdcbyoZ1UrJeJrDHJEDuIkF3SR8Cixl3Ibsadu/EYtOYA+VPUj2U79Qahe/0HYg pCPstXF0o+1NfVJ9Lz8wQ2HIKdQ7aVKHjVmxQ7jsMRLBbqGxS/8ddkQ+yKf0H35h T/eNZ5YEnaae8dPYrDZUAG893Xas0pRcadrU7xrDuYRi+0KMTwEfmgxTPahKXXb+ eNmR1W4CZimnCEdxkDQALgs1fsip566/9DWbZUax+wKRlmU9qckww5RsCsL0liBX WQwVOrzmrpohqFe9MF4MsIMNz4gfntpqf7Bmye/A12N1PNZ4MgtDXBBEHbNGf/32 dohVMz9MfgkSdOsQ3Kdv =d9uL -----END PGP SIGNATURE----- --------------------------------------------------------------------- To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org For additional commands, e-mail: users-h...@tomcat.apache.org