I think I see how that would work for standard security - the part of the problem that I am struggling with is that we are doing 2-way SSL.
I have clientauth="true" in the connector configuration in Tomcat's server.xml. Basically, that has made it so that everyone who connects to the site has to present a certificate. What I need is for a few directories to not require the client certificate. For the record, I am running JBoss 4.0.2 with Josso, in case that clears anything up for anyone. Sorry if I left out some details or was a little hazy about them the first time around. Thanks again, Jeremy View the original post : http://www.jboss.com/index.html?module=bb&op=viewtopic&p=3955864#3955864 Reply to the post : http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&p=3955864 Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job easier Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642 _______________________________________________ JBoss-user mailing list JBoss-user@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/jboss-user