Re: SSL FAQ and question

2002-11-21 Thread Norbert Kuhnert
Jay, I've had success with using the webapp deployment descriptor transport-guarantee user-data-contraint as follows: security-constraint web-resource-collection web-resource-namemyPayroll/web-resource-name url-pattern/payrollServlet/url-pattern http-methodGET/http-method

Re: SSL FAQ and question

2002-11-21 Thread Norbert Kuhnert
. Did you need to configure a second Host for the secure site? Or is that only necessary if you want a separate domain secure.site.com instead of regular.site.com. -Original Message- From: Norbert Kuhnert [mailto:[EMAIL PROTECTED]] Sent: Thursday, November 21, 2002 11:49 AM To: Tomcat

Re: Session Tracking based on the Client's IP

2002-11-20 Thread Norbert Kuhnert
Jose, Unfortunately, this approach would be somewhat unreliable, depending on the sites accessing Tomcat. Most corporate networks are protected by a firewall and many of the do Dynamic Network Address Translation. Dynamic NAT is used to hide the real IP address of clients connected from the