https://issues.apache.org/bugzilla/show_bug.cgi?id=48208

Ralf Hauser <hau...@acm.org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
            Summary|allow client certificate    |allow to configure a
                   |with any issuer: server.xml |customm client certificate
                   |connector attribute         |Trust Manager in server.xml
                   |"acceptAllCerts"            |per connector attribute
                   |                            |"trustManagerClassName"

--- Comment #7 from Ralf Hauser <hau...@acm.org> 2011-01-31 19:27:22 EST ---
Hi Chris, we do need authentication and "want" is not good enough since the
user can opt out not to use client cert auth altogether AFAICR.

To avoid misunderstandings, I have updated the Summary.

Luciana's patch attachment (id=26581) for tomcat 6 svn revision 1065625 exactly
tries to implement what Mark suggested as "acceptable approach" in comment 3

-- 
Configure bugmail: https://issues.apache.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org

Reply via email to