Glen,

This was on the list a while ago. It is by design that this happens. It is
for security reasons as I understand it. It is considered safe to move from
http to https but not the other direction.

Doug
www.parsonstechnical.com


----- Original Message ----- 
From: "Drinkwater, GJ (Glen)" <[EMAIL PROTECTED]>
To: "'Tomcat Users List'" <[EMAIL PROTECTED]>
Sent: Wednesday, April 21, 2004 8:15 AM
Subject: SSL and sessions


> Hi
>
> I am using tomcat with ssl for the initial log into my application over
ssl,
> the problem is that if i send the application back to http (normal) the
> session that i first created under ssl is different from the session that
is
> created going back to http.  Is there any configuration that allows the
same
> session to go to and from https and http with the same session id.
>
> Cheers Glen
>
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [EMAIL PROTECTED]
> For additional commands, e-mail: [EMAIL PROTECTED]
>
>



---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to