-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Tim,
Tim Funk wrote: > What you'll really want is to ditch the transport guarantee clause in > web.xml and create a filter which will be smart enough to force/unforce > you from SSL. Why do this when the <security-constraint> already allows you to protect only certain URL patterns? It seems to me that maintaining less code in your application is a good thing. - -chris -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFGhUa89CaO5/Lv0PARAjw5AJ0fHGpgedo24rGajP2FxckHE0BXLgCgpWGf RX8dEwP4l+a/4xVemr5+ULg= =qWWc -----END PGP SIGNATURE----- --------------------------------------------------------------------- To start a new topic, e-mail: users@tomcat.apache.org To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]