-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 24/09/2012 17:51, Christopher Schultz wrote:
> I'm curious how you will "check DIGEST first" and then apply
> BASIC. Are you expecting some clients to simply send DIGEST
> credentials without first contacting the server? I don't think
> that's possible.

RFC2616 allows multiple authentication challenges to be sent so both
DIGEST and BASIC could be sent in a single response. It would then be
up to the client how to respond.

Mark
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)
Comment: Using GnuPG with Mozilla - http://www.enigmail.net/

iQIcBAEBAgAGBQJQYJ1FAAoJEBDAHFovYFnnt5AP/jtel9ZjB5NbKePywWKjnxj7
X7n9tGfIXYSgycGxo0EXCwD2hjViVr/j3+tkqv3wTXCa0pqajOOem1mA0AVHXP/0
fkVgFSK+hcFQoxhHCYYC0a/aQnAeNs5azBR++pfIsHkXYQKAXo1hMLezwbhev2KA
86lrRWpBjGPsEWezx4A/N3W0x9Ct5AqtYSBYHSDBhlbYLwl7Id7wv7NDi30gdR6D
W/gT6jilEqCHKlmy8QmTYogwFUQ1+LMbEIKmVgmk+9QuLyJaf2xmwV8Vt5dETdGt
xwT+8mPq4ZLv/JICjrrAkS1KQfb31KBlwM+YHERrSI2x6AzVxT2xWp9mCnigRdZl
jJdcbyoZ1UrJeJrDHJEDuIkF3SR8Cixl3Ibsadu/EYtOYA+VPUj2U79Qahe/0HYg
pCPstXF0o+1NfVJ9Lz8wQ2HIKdQ7aVKHjVmxQ7jsMRLBbqGxS/8ddkQ+yKf0H35h
T/eNZ5YEnaae8dPYrDZUAG893Xas0pRcadrU7xrDuYRi+0KMTwEfmgxTPahKXXb+
eNmR1W4CZimnCEdxkDQALgs1fsip566/9DWbZUax+wKRlmU9qckww5RsCsL0liBX
WQwVOrzmrpohqFe9MF4MsIMNz4gfntpqf7Bmye/A12N1PNZ4MgtDXBBEHbNGf/32
dohVMz9MfgkSdOsQ3Kdv
=d9uL
-----END PGP SIGNATURE-----

---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org
For additional commands, e-mail: users-h...@tomcat.apache.org

Reply via email to