Return-Path: Mailing-List: contact tomcat-dev-help@jakarta.apache.org; run by ezmlm Delivered-To: mailing list tomcat-dev@jakarta.apache.org Received: (qmail 23447 invoked from network); 1 Mar 2001 23:28:08 -0000 Received: from unknown (HELO mailin1.bigpond.com) (139.134.6.21) by h31.sny.collab.net with SMTP; 1 Mar 2001 23:28:08 -0000 Received: from bigpond.net.au ([139.134.4.54]) by mailin1.bigpond.com (Netscape Messaging Server 4.15) with SMTP id G9JL1001.9KH for ; Fri, 2 Mar 2001 09:24:36 +1000 Received: from CPE-61-9-164-185.vic.bigpond.net.au ([61.9.164.185]) by mail6.bigpond.com (Claudes-Energetic-MailRouter V2.9c 11/5272897); 02 Mar 2001 09:19:39 Message-ID: <3A9EE9FB.8060602@bigpond.net.au> Date: Fri, 02 Mar 2001 11:31:55 +1100 From: Jason Harrop User-Agent: Mozilla/5.0 (X11; U; Linux 2.2.13 i686; en-US; 0.7) Gecko/20010119 X-Accept-Language: en MIME-Version: 1.0 To: tomcat-dev@jakarta.apache.org Subject: Re: [TC4] SingleSignOnSupport broken? References: <3A9E54D6.3000109@bigpond.net.au> <3A9E7A21.97C237D2@eng.sun.com> Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit X-Spam-Rating: h31.sny.collab.net 1.6.2 0/1000/N Craig R. McClanahan wrote: > There is an (undocumented) restriction in the current implementation when using > BASIC or DIGEST authentication with single sign on support -- the value you > specify for in the security constraints needs to be the same for all of > the webapps that are participating in the single sign on environment. This is > probably a bug (most of my development work was on using form-based login with > this), but it should work if you use the same realm string. > Craig, I did try it with identical in each web.xml file, before trying it with different ones. If the realm names are identical, and i just use http basic authentication (which i do), what role would single sign on support play? I don't understand why it is needed at all - shouldn't the browser just send the authentication information to TC after receiving the 401 with a WWW-Authenticate header? thanks Jason