-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Tim,

Tim Funk wrote:
> What you'll really want is to ditch the transport guarantee clause in
> web.xml and create a filter which will be smart enough to force/unforce
> you from SSL.

Why do this when the <security-constraint> already allows you to protect
only certain URL patterns? It seems to me that maintaining less code in
your application is a good thing.

- -chris
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFGhUa89CaO5/Lv0PARAjw5AJ0fHGpgedo24rGajP2FxckHE0BXLgCgpWGf
RX8dEwP4l+a/4xVemr5+ULg=
=qWWc
-----END PGP SIGNATURE-----

---------------------------------------------------------------------
To start a new topic, e-mail: users@tomcat.apache.org
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to