When you mention valid roles.

The role has to be in LDAP as well as enumerated in a security-role list?

I am not sure where how the connection should be working here. Is there a way to authenticate the user without requiring a specific role?

Thanks,
Dan

Caldarale, Charles R wrote:
From: Daniel Curran [mailto:[EMAIL PROTECTED] Subject: Re: SingleSignOn Valve Not Challenging

I have added an auth constraint

<auth-constraint>
    <role-name>*</role-name>
</auth-constraint>

To quote from the servlet spec:

'The special role name "*" is a shorthand for all role names defined in
the deployment descriptor.'

You still need to enumerate the valid roles with <security-role>
elements.

 - Chuck


THIS COMMUNICATION MAY CONTAIN CONFIDENTIAL AND/OR OTHERWISE PROPRIETARY
MATERIAL and is thus for use only by the intended recipient. If you
received this in error, please contact the sender and delete the e-mail
and its attachments from all computers.

---------------------------------------------------------------------
To start a new topic, e-mail: users@tomcat.apache.org
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



---------------------------------------------------------------------
To start a new topic, e-mail: users@tomcat.apache.org
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to