Hi,
I'm using Tomcat 5.5.23 with SSO enabled. I also implemented a customer Realm (extending RealmBase). It's been working great but just recently I've noticed that some session mix-up happening under high load. I am at loss to find where/why this happened. I looked at my own Realm implementation, but authenticate() method is called only once when user first authenticates himself. Subsequent calls does not invoke authenticate() method in my customer Realm, so it must be handled somewhere else in Tomcat code. Can anybody point me to a right direction, please? <http://www.google.com/reader/shared/16849249410805339619> Timothy Wonil Lee Java Developer <http://www.koorong.com/> Koorong Books email: <mailto:[EMAIL PROTECTED]> [EMAIL PROTECTED] direct ph: (+612) 9857 4448 direct fax: (+612) 9857 6648