I use Apache's authentication with mod_ntlm.
http://members.ozemail.com.au/~timcostello/mod_ntlm/
Just use <Location> tags to protect your webapp rather than messing with any of the
Tomcat stuff.
I went round and round trying to do this with IIS4. It's incredible that Apache has
cleaner support for NTLM than MS's own product.
HTH
***********************************************************
Brett Knights 250-338-3509 work
[EMAIL PROTECTED] 250-334-8309 home
***********************************************************