Hi all, I want to protect my site using Basic Authentication. I have a form log in that goes to log in servlet, achecks credentials against ldap, if valid, creates a session, and lets the user in. In this situation, I was wondering if there is way that I can then tell Apache this guy has authenticated so don't respond with a www.authenticate header when he tries to access a protected page. Any thoughts or ideas would be appreciated. Regards, Jake the Snake -- ---------------------------------------------------------- To subscribe: [EMAIL PROTECTED] To unsubscribe: [EMAIL PROTECTED] Archives and Other: <http://java.apache.org/main/mail.html> Problems?: [EMAIL PROTECTED]