https://issues.apache.org/bugzilla/show_bug.cgi?id=54503
--- Comment #3 from Mark Thomas <ma...@apache.org> --- That is a big patch. I have one immediate concern with the proposed patch with is the unknown licensing of the new JAR file. Looking more broadly, I think it would be worth (re-)considering adding JASPIC to Tomcat. Most of the code should be available in TomEE. That would then provide a standard mechanism to plug-in additional authentication mechanisms such as SAML2. At the moment, I'd be happier with SAML2 as an optional extra rather than as a core component. -- You are receiving this mail because: You are the assignee for the bug. --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org