https://bz.apache.org/bugzilla/show_bug.cgi?id=66120
--- Comment #3 from Mark Thomas <ma...@apache.org> --- My current thinking is that make this behaviour optional depending on the setting of the "persistAuthentication" attribute of the Manager. If we do this that way, the change to the session serialization format can be handled in a backwards compatible manner. If there are no objections, I intend to implement this in time for the August release round. -- You are receiving this mail because: You are the assignee for the bug. --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org