If you create WWW-Authenticate as in example 8.2 of Jason's Servlet book, is there a way in JSP or servlet to invalidate this authentication? =========================================================================== To unsubscribe: mailto [EMAIL PROTECTED] with body: "signoff JSP-INTEREST". FAQs on JSP can be found at: http://java.sun.com/products/jsp/faq.html http://www.esperanto.org.nz/jsp/jspfaq.html