When you mention valid roles.
The role has to be in LDAP as well as enumerated in a security-role list?
I am not sure where how the connection should be working here. Is there
a way to authenticate the user without requiring a specific role?
Thanks,
Dan
Caldarale, Charles R wrote:
From: Daniel Curran [mailto:[EMAIL PROTECTED]
Subject: Re: SingleSignOn Valve Not Challenging
I have added an auth constraint
<auth-constraint>
<role-name>*</role-name>
</auth-constraint>
To quote from the servlet spec:
'The special role name "*" is a shorthand for all role names defined in
the deployment descriptor.'
You still need to enumerate the valid roles with <security-role>
elements.
- Chuck
THIS COMMUNICATION MAY CONTAIN CONFIDENTIAL AND/OR OTHERWISE PROPRIETARY
MATERIAL and is thus for use only by the intended recipient. If you
received this in error, please contact the sender and delete the e-mail
and its attachments from all computers.
---------------------------------------------------------------------
To start a new topic, e-mail: users@tomcat.apache.org
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]
---------------------------------------------------------------------
To start a new topic, e-mail: users@tomcat.apache.org
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]