Re: Realm Tag in webappnamecontext.xml

2006-06-02 Thread Mark Thomas
Marc Farrow wrote:
  auth-contraint/

And there is the problem. An empty auth-constraint allows
unauthenticated access as per SRV.12.8.1

An empty auth-constraint is not the same as an auth-constraint
that specifies no roles and therefore denies access to all as per
SRV.12.8.1.


Mark

-
To start a new topic, e-mail: users@tomcat.apache.org
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: Realm Tag in webappnamecontext.xml

2006-06-02 Thread Marc Farrow

Thanks Mark.  I did figure out my configuration problem!

On 6/2/06, Mark Thomas [EMAIL PROTECTED] wrote:


Marc Farrow wrote:
  auth-contraint/

And there is the problem. An empty auth-constraint allows
unauthenticated access as per SRV.12.8.1

An empty auth-constraint is not the same as an auth-constraint
that specifies no roles and therefore denies access to all as per
SRV.12.8.1.


Mark

-
To start a new topic, e-mail: users@tomcat.apache.org
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]





--
Marc Farrow