https://bz.apache.org/bugzilla/show_bug.cgi?id=57865
--- Comment #5 from Alessandro Trolli <alessandro.tro...@gmail.com> --- I'm actually not able to reproduce using a simple webapp (please find in attachements war and config files) but even with complete webapp result is not deterministic. The thing I've observed during first debug session is that Principal was available after logout (calling session.invalidate and issuing a client redirect to root context) without being redirect to authentication form by SingleSignOn valve -- You are receiving this mail because: You are the assignee for the bug. --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org