Return-Path: Delivered-To: apmail-jakarta-tomcat-user-archive@apache.org Received: (qmail 25822 invoked from network); 30 Jun 2002 01:00:49 -0000 Received: from unknown (HELO nagoya.betaversion.org) (192.18.49.131) by 209.66.108.5 with SMTP; 30 Jun 2002 01:00:49 -0000 Received: (qmail 7848 invoked by uid 97); 30 Jun 2002 01:00:47 -0000 Delivered-To: qmlist-jakarta-archive-tomcat-user@jakarta.apache.org Received: (qmail 7832 invoked by uid 97); 30 Jun 2002 01:00:47 -0000 Mailing-List: contact tomcat-user-help@jakarta.apache.org; run by ezmlm Precedence: bulk List-Unsubscribe: List-Subscribe: List-Help: List-Post: List-Id: "Tomcat Users List" Reply-To: "Tomcat Users List" Delivered-To: mailing list tomcat-user@jakarta.apache.org Received: (qmail 7820 invoked by uid 98); 30 Jun 2002 01:00:46 -0000 X-Antivirus: nagoya (v4198 created Apr 24 2002) Message-ID: <20020630010036.28038.qmail@web20710.mail.yahoo.com> Date: Sat, 29 Jun 2002 18:00:36 -0700 (PDT) From: "Dmitry ..." Subject: Re: SSL and Authentication To: Tomcat Users List In-Reply-To: <20020629155530.2262.qmail@web20702.mail.yahoo.com> MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="0-870858234-1025398836=:28012" X-Spam-Rating: 209.66.108.5 1.6.2 0/1000/N X-Spam-Rating: 209.66.108.5 1.6.2 0/1000/N --0-870858234-1025398836=:28012 Content-Type: text/plain; charset=us-ascii I figured out that I'll need to refactor my directory structure and use seperate s. I'm curious, is there a standard or preferred way to do this? My next step is to integrate Tomcat with Apache, and then an EJB server (perhaps JBoss?)... --Dmitry "Dmitry ..." wrote: Hello everyone. I have a security-contstraint set up with /* and JDBCRealm, and I have SSL configured in server.xml. Both the JDBCRealm and SSL are working, just not quite as I'd like. Currently, when the user first enters my site (/mysite/index.html), he is asked to authenticate himself. When the user requests a page through SSL (.../location=https:8443/mysite/../Registration.jsp), he is again asked to authenticate himself. What I want is: 1) The user to be able to access index.html (and a few other pages) withought authentication. I'd rather not have to enter every page individually under . *2) The user to not have to re-authenticate himself when he selects to go to Registration.jsp via SSL. Thank you in advance, Dmitry --------------------------------- Do You Yahoo!? Sign-up for Video Highlights of 2002 FIFA World Cup --------------------------------- Do You Yahoo!? Sign-up for Video Highlights of 2002 FIFA World Cup --0-870858234-1025398836=:28012--